FPGA et extraction de firmware - Siddique Vally-Adam

FPGA et extraction de firmware - Siddique Vally-Adam

🎙 Siddique Vally-Adam 👥 12K 📅 April 13, 2026 ⏱ 50 min 👁 41 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

FPGAfirmwareUARTglitchhardware hacking

Summary

In this keynote from Bsides Réunion, Siddique Vally-Adam presents a practical introduction to using FPGAs for firmware extraction from embedded systems. He begins by explaining the basics of FPGAs, contrasting them with microcontrollers like Arduino, and covers fundamental logic gates, flip-flops, and multiplexers. He then demonstrates how to design a simple UART communication module using Verilog in AMD Vivado, emphasizing the importance of clock synchronization. The core of the talk focuses on fault injection techniques, specifically voltage or clock glitching, to bypass firmware read protections. He outlines a methodology involving a Python script to automate timing variations and a custom FPGA-based glitch generator. He also mentions using logic analyzers and oscilloscopes for signal analysis. The talk concludes with a brief discussion of countermeasures and the need for further research.

129 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable practical insights into FPGA-based firmware extraction, a niche area with limited accessible resources. The speaker’s hands-on experience is evident, and he effectively explains complex concepts like FSM and UART in an accessible manner. The argumentation is coherent, progressing from basic FPGA principles to a concrete attack methodology. However, the presentation is somewhat informal and lacks depth in certain areas, such as the specifics of glitch timing and countermeasures.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references tools like Vivado and mentions a training by Dmitry Nedospasov, but does not provide formal citations or sources. The title accurately reflects the content. The talk is based on the speaker’s expertise and practical experience rather than peer-reviewed literature, which limits its scientific rigor but enhances its practical relevance.

139 words

Title / Content Match

The title accurately reflects the content, which focuses on using FPGAs for firmware extraction.

Quality & Reliability

7/10

The speaker demonstrates practical expertise in FPGA-based firmware extraction, with a hands-on approach and references to real tools and techniques. However, the presentation is informal, lacks detailed citations, and some technical explanations are simplified.

Key Moments

Cited Sources

  • AMD Vivado — Mentioned as the primary FPGA design tool used in the demonstration.
  • Dmitry Nedospasov's training — Referenced as a source of the methodology for hardware hacking.

Concurring Sources

  • FPGA-based glitch attacks — The speaker's methodology aligns with known research on FPGA-based glitch attacks.

Dissenting Sources

  • Countermeasures to fault injection — The talk briefly mentions countermeasures but does not provide a comprehensive analysis, which could be seen as a limitation.

Contribution & Novelties

The talk provides a practical, hands-on perspective on FPGA-based firmware extraction, bridging the gap between theoretical knowledge and real-world application. It emphasizes the use of FPGAs for precise timing control in glitch attacks, a technique not widely covered in accessible formats.

Pour aller plus loin :

92 words

Radar Profile

The radar profile shows a balanced distribution across all dimensions, with slightly higher scores in information quantity and technical level, reflecting the practical nature of the talk. The lower reliability score indicates a lack of formal citations and reliance on personal experience.

Reliability 6/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être identifiée.