backside:start
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
backside:start [2018/02/20 21:25] – mcmaster | backside:start [2018/02/20 21:55] (current) – removed mcmaster | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | Backside analysis can include: | ||
- | * Imaging transistor layout without delayering | ||
- | * Imaging transistor activity using PMT, camera, etc for side channnel analysis | ||
- | * Laser fault injection, bypassing security meshes and other things usually in the way | ||
- | |||
- | Fabs often thin wafers and perform backside analysis to get at the transistors without going through metal. | ||
- | |||
- | [[http:// | ||
- | |||
- | ====== Camera ====== | ||
- | |||
- | ===== Sample commercial unit ===== | ||
- | |||
- | With IR imaging and laser fault injection | ||
- | |||
- | Camera: | ||
- | * uEeye Cockpit | ||
- | * ueye IDS camera | ||
- | * U124xSE-NIR | ||
- | * Or maybe: UI24xSE-NIR | ||
- | * think its standard camera they removed IR filter | ||
- | * https:// | ||
- | |||
- | |||
- | ====== Optical fault injection ====== | ||
- | |||
- | In its simplest form, a CSP can be strobed with a camera flash | ||
- | |||
- | You need to excite the silicon with a photo of wavelength no more than 1.1 um (reference: " | ||
- | |||
- | [[https:// | ||
- | |||
- | [[https:// | ||
- | |||
- | Solutions include: | ||
- | * [[http:// | ||
- | * [[https:// | ||
- | * ChipWispherer has voltage glitching. Could probably rig something similar up for optical glitching | ||
backside/start.1519161913.txt.gz · Last modified: 2018/02/20 21:25 by mcmaster