Design Advisory for Zynq-7000: FSBL Authentication Attack

https://support.xilinx.com/s/article/76974?language=en_US

<article class="content" data-aura-rendered-by="89:118;a" style="box-sizing: border-box; display: block; padding: 0px;">

DESCRIPTION

In this physical attack, an attacker might potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn could further allow the attacker to perform additional attacks such as using the device as a decryption oracle.

The 7 Series families, including the Zynq-7000 SoCs, were not designed to be resistant to physical attacks. In the case where physical access and physical modification of the board are required to perform this attack, then the overall security profile of the Zynq-7000 does not change.

The below figure is a high-level summary that can be used to determine whether an existing system is impacted.

SOLUTION

A patch to the Zynq-7000 SoC FSBL will be included in the 2022.1 release that mitigates this specific issue.

©著作权归作者所有,转载或内容合作请联系作者
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

推荐阅读更多精彩内容

  • 字符串 1.什么是字符串 使用单引号或者双引号括起来的字符集就是字符串。 引号中单独的符号、数字、字母等叫字符。 ...
    mango_2e17阅读 12,179评论 1 7
  • 《闭上眼睛才能看清楚自己》这本书是香海禅寺主持贤宗法师的人生体悟,修行心得及讲学录,此书从六个章节讲述了禅修是什么...
    宜均阅读 13,420评论 1 25
  • 前言 Google Play应用市场对于应用的targetSdkVersion有了更为严格的要求。从 2018 年...
    申国骏阅读 64,885评论 15 98
  • 第七章:理性的投资观 字数: 1.投资要围绕目的进行 投资的目的是为了挣钱。投资的除了金钱还有时间和精力也是一种投...
    幸福萍宝阅读 8,668评论 1 2
  • 本文转载自微信公众号“电子搬砖师”,原文链接 这篇文章会以特别形象通俗的方式讲讲什么是PID。 很多人看到网上写的...
    这个飞宏不太冷阅读 11,846评论 2 15