arXiv論文メモ
新着一覧
cs.CR / cs.AR · 査読状況未確認

入力専用のアナログ端子から情報が漏れる条件

Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs

Ramana Ranganatham, Chirag Adiga, Michael Zuzak, Tejasvi Das

この論文をやさしく読む

ひとことで言うと

入力専用とされる端子でも、回路内部の変動が外へ伝わり、情報の出口になり得ることを試作チップで示した研究です。

何に役立つ?

アナログ回路のセキュリティ審査や試験で、端子の名目上の役割だけで情報の流れる向きを決めつけないための知見です。

この研究の面白いところ

通常の出力信号の品質への影響が小さくても情報流出が成立し得る点を、回路モデルとシリコン測定の両方から示しています。

どこまで分かった?

結果は提示された回路条件と55nmのPPG用AFE事例でのものです。最大10kbpsや誤りなしという結果を、すべてのアナログ入力端子や動作条件へ一般化することはできません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

ミックスドシグナルSoCは、公称上は入力専用のアナログ端子を使ってチップ外の信号を取得する。しかし、こうしたインターフェースの方向性は一般に機能上の性質として扱われ、セキュリティ特性として明示的に検証されない。本研究では、データに依存する回路オフセットの変調によって、公称入力専用端子が外向きの情報チャネルになる、方向性に基づくアナログ・ミックスドシグナル(AMS)情報流出攻撃の一類型を特定し、実験で示す。攻撃の仕組みを解析的にモデル化し、成立を可能にする三つのホスト側条件、すなわち閉ループ増幅器、外部に露出した増幅器入力、その端子の十分に高いインピーダンスを特定する。 この攻撃類型を、市販の55nm CMOSプロセスで製造した光電式容積脈波(PPG)アナログフロントエンド(AFE)の代表的なシリコン事例で検証する。ペイロードの面積増分は、典型的な生体計測AFEに対して0.001%未満である。評価条件の下では、ペイロードを有効にしても、フィルター処理後のPPG出力のSNR低下はわずか0.03dBだった。また、ハードウェアトロイ(HT)が引き起こす最大摂動はPPG振幅の5.9%であり、プロセスと温度にわたって露出したセンサー入力端子に生じる正常な変動34.3%の範囲内に収まった。 未処理の流出信号のSINRは−20dB未満だが、対象に合わせたフィルタリングによって14dBを超え、信号を復元できる。シリコン測定では、入力端子を通じた最大10kbpsのデータ流出と、PRBSメッセージの誤りのない復元を実証した。これらの結果は、従来のテストの観測可能性に抜けがあることを明らかにし、アナログ端子の方向性を、公称の信号の流れから推測するのではなく、明示的な検証、テスト範囲、対策を必要とするAMSセキュリティ特性として位置付ける。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-16(UTC)
最新改訂
2026-09-16 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Mixed-signal SoCs rely on nominally input-only analog pins to acquire off-chip signals, but the directionality of these interfaces is generally treated as a functional property rather than explicitly verified as a security property. This work identifies and experimentally demonstrates a directionality-based class of analog and mixed-signal (AMS) exfiltration attacks in which data-dependent circuit-offset modulation converts a nominally input-only pin into an outbound information channel. We analytically model the attack mechanism and identify three enabling host conditions: a closed-loop amplifier, an exposed amplifier input, and sufficiently high impedance at that pin. This attack class is validated through a representative silicon case study using a photoplethysmography (PPG) analog front-end (AFE) fabricated in a commercial 55-nm CMOS process. The payload incurs $<$0.001\% area overhead relative to typical biosensing AFEs. Under the evaluated conditions, payload activation reduces the filtered PPG-output SNR by only 0.03~dB, while the maximum HT-induced perturbation of 5.9\% of the PPG amplitude remains within the 34.3\% benign variation at the exposed sensor-input pin across process and temperature. The raw exfiltration SINR remains below -20~dB, while targeted filtering increases it above 14~dB and enables signal recovery. Silicon measurements demonstrate data exfiltration through the input pin at bit rates up to 10~kbps and error-free recovery of a PRBS message. These results expose a conventional test-observability gap and establish analog pin directionality as an AMS security property requiring explicit verification, test coverage, and defense rather than being inferred from nominal signal flow.

著者のコメント

Submitted to IEEE Transactions on Information Forensics and Security (TIFS)

arXiv ID: 2609.19111 / 要約の誤りについて