Skip to content

Clock Glitching

Clock glitching is a fault injection technique that exploits timing vulnerabilities in embedded systems by introducing deliberate disruptions to the clock signal. By manipulating the clock's timing, attackers can induce transient errors in the execution of critical operations, such as cryptographic key scheduling or authentication checks. This section details the implementation of clock glitching attacks, including hardware setup, timing manipulation, and exploitation strategies.


Hardware Setup for Clock Glitching

To perform clock glitching, an attacker typically needs access to the target device's clock signal. Common approaches include:
1. Direct Clock Manipulation: Using a hardware tool (e.g., JTAG, UART, or a dedicated glitch generator) to interface with the target's clock source (e.g., a crystal oscillator or PLL).
2. Oscilloscope/Signal Generator: Injecting glitches via a signal generator connected to the clock line, often using a logic analyzer to synchronize the attack.
3. Power Supply Glitching: Inducing timing errors by modulating the power supply voltage, though this is less precise than direct clock manipulation.

Example Setup:
A typical setup involves a glitch generator (e.g., ChipWhisperer) connected to the target's clock line. The attacker configures the generator to produce short, high-frequency pulses that disrupt the clock signal.

# Example command to configure a glitch generator (hypothetical tool)
chipwhisperer-cli --glitch-type pulse --duration 100ns --frequency 1MHz

Timing Manipulation and Glitch Parameters

The success of a clock glitching attack depends on precise control over the following parameters:
- Glitch Duration: Short pulses (e.g., 10–100 ns) are often used to disrupt critical timing windows.
- Glitch Frequency: Adjusting the frequency to match the target's clock cycle (e.g., 100 MHz) ensures the glitch aligns with the device's operational rhythm.
- Duty Cycle: Varying the proportion of time the clock is disrupted (e.g., 10% duty cycle) to test different attack vectors.

Example:
An attacker might use a timing analyzer to measure the target's clock period and then inject a glitch at the midpoint of the cycle to induce a timing error.

# Hypothetical Python script to generate a glitch pulse
import time
glitch_duration = 0.1e-6  # 100 ns
glitch_frequency = 1e6    # 1 MHz
while True:
    # Apply glitch
    apply_glitch(glitch_duration)
    time.sleep(1/glitch_frequency)  # Wait for next cycle

Exploitation of Timing Vulnerabilities

Clock glitching exploits vulnerabilities in systems that rely on precise timing for security-critical operations. Common targets include:
1. Cryptographic Algorithms: Glitching during key scheduling or round operations can cause the device to leak intermediate values.
2. Secure Elements: Disrupting authentication sequences may bypass secure boot checks.
3. State Machines: Timing errors can force the device into unintended states (e.g., skipping validation steps).

Example:
In a AES implementation, a glitch during the SubBytes step might cause the device to use incorrect S-box values, revealing the key through differential analysis.


Key Takeaways

  • Hardware Access: Clock glitching requires physical access to the target's clock signal or power supply.
  • Precision Timing: Success depends on precise control over glitch duration, frequency, and alignment with the target's clock cycle.
  • Exploitation Focus: Attackers target timing-critical operations in cryptographic or authentication logic to extract secrets or bypass security checks.
  • Mitigations: Shielding clock lines, using error-checking mechanisms, or implementing clock domain crossing (CDC) safeguards can reduce vulnerability.