Reverse Engineering Flash EEPROM Memories Using Scanning Electron Microscopy

نویسندگان

  • Franck Courbon
  • Sergei Skorobogatov
  • Christopher Woods
چکیده

In this article, a methodology to extract Flash EEPROM memory contents is presented. Samples are first backside prepared to expose the tunnel oxide of floating gate transistors. Then, a Scanning Electron Microscope (SEM) in the so called Passive Voltage Contrast (PVC) mode allows distinguishing ‘0’ and ‘1’ bit values stored in individual memory cell. Using SEM operator-free acquisition and standard image processing technique we demonstrate the possible automating of such technique over a full memory. The presented fast, efficient and low cost technique is successfully implemented on 0.35μm technology node microcontrollers and on a 0.21μm smart card type integrated circuit. The technique is at least two orders of magnitude faster than state-of-the-art Scanning Probe Microscopy (SPM) methods. Without adequate protection an adversary could obtain the full memory array content within minutes. The technique is a first step for reverse engineering secure embedded systems.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Direct charge measurement in Floating Gate transistors of Flash EEPROM using Scanning Electron Microscopy

We present a characterization methodology for fast direct measurement of the charge accumulated on Floating Gate (FG) transistors of Flash EEPROM cells. Using a Scanning Electron Microscope (SEM) in Passive Voltage Contrast (PVC) mode we were able to distinguish between '0' and '1' bit values stored in each memory cell. Moreover, it was possible to characterize the remaining charge on the FG; t...

متن کامل

Reliability Issues of Flash Memory Cells

The reliability issues of Flash electrically erasable programmable read-only memory (Flash EEPROM) are reviewed in this paper. The reduction of the memory cell size and improvement in the reliability have been realized by several breakthroughs in the device technology; in particular, the reliability of the ETOX and NAND structure EEPROM will be discussed in detail. Flash EEPROM is expected to b...

متن کامل

High Voltage Generation for Low Power Large VDD Range Non Volatile Memories

The design of embedded non volatile memories, such as EEPROM or Flash, working under a wide VDD range depending on the battery (typically 1.8V-3.3V), needs specific techniques. Optimization of the charge pump circuitry and of the current consumption during the write operation are treated in this paper.

متن کامل

Flash Memory Technology - a Review

Since the first flash memory patent issued on October 6, 1987, flash memory’s multiple useful characteristics, including nonvolatility, in-circuit reprogrammability, low power consumption, and high density, have led it to become the fastest growing memory segment in recent years. Mobile computing and communication have driven the demand for flash memories. Nascent applications, such as digital ...

متن کامل

Ni-Based SAS Process on Source and Drain for High Performance of Polysilicon TFT Low-Voltage Flash Memory Cell

We report the fabrication process, material and electrical characterizations of ultra thin body (UTB) thin film transistors (TFTs) by using nickel (Ni)-based self-aligned silicidation (SAS) process. The resulting polysilicon film, after a chemical mechanical process (CMP), is about 13 nm thick with approximately 1019 cm-3 body doping. Root mean square (RMS) surface roughness below 1 nm is achie...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016