Laser Fault Injection Breaks RP2350 Secure Debug Protections

Original: Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

Why This Matters

Demonstrates that even revised, hardened microcontrollers remain vulnerable to well-resourced physical attackers—relevant to hardware wallet and embedded security threat modeling.

Ledger's Donjon security team used photon-emission microscopy and laser fault injection to restore Secure debug access on a Raspberry Pi RP2350 A4 chip, bypassing permanently disabled debug settings and recovering a secret from OTP memory. The attack requires roughly $250,000 in lab equipment and destructive physical access.

Ledger's Donjon research team published a detailed attack against the Raspberry Pi RP2350 A4 microcontroller, the revised chip released after the original RP2350 Hacking Challenge closed in December 2024. The attack chains two advanced techniques: differential photon-emission microscopy to locate the debug-enable register, followed by precisely targeted laser fault injection to flip the two bits needed to restore Secure debug access via the SWD interface.

The RP2350's permanent CRIT1.DEBUG_DISABLE flag is designed to drive enable signals for both cores' memory access ports (Mem-APs) to zero, cutting off debugger bus access entirely. Donjon researchers used photon-emission analysis to isolate activity in that register, dramatically narrowing the laser target area before executing the injection.

Once Secure debug was restored, the team performed a rescue reset that halted the chip before firmware could apply its runtime OTP page lock—a soft lock that tightens page permissions but resets with each OTP reset cycle. That timing window left a target OTP page Secure-readable, allowing secret recovery.

The RP2350 uses triple-redundant majority voting on OTP lock bits and three-of-eight voting on security flags, per Raspberry Pi's own datasheet. Despite those hardening measures, the laser injection succeeded by targeting the runtime register state rather than the OTP bits themselves.

The researchers emphasize the steep barrier to entry: the attack demands physical access, destructive sample preparation (likely decapsulation), and approximately $250,000 worth of laboratory equipment.

Source

donjon.ledger.com — Read original →