SRAM Has No Chill: Exploiting Power Domain Separation to Steal On-Chip Secrets.

The widespread use of embedded systems and smart devices has heightened the threat of physical memory attacks, such as cold boot attacks that exploit DRAM’s temporary data retention at low temperatures. Although storing secrets in on-chip SRAM typically protects against these attacks due to its isol...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 68; no. 8; pp. 82 - 91
Autores principales: Mahmod, Jubayer, Hicks, Matthew
Formato: Artículo
Publicado: Association for Computing Machinery Aug2025
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The widespread use of embedded systems and smart devices has heightened the threat of physical memory attacks, such as cold boot attacks that exploit DRAM’s temporary data retention at low temperatures. Although storing secrets in on-chip SRAM typically protects against these attacks due to its isolation and minimal capacitance, this protection is not foolproof. This paper introduces Volt Boot, an attack that bypasses traditional defenses by exploiting uneven power states in system-on-chip architectures to retain data in volatile SRAM across reboots. Tested on modern ARM Cortex-A devices, Volt Boot reliably extracts sensitive information from caches, registers, and internal RAM with perfect accuracy and no need for low temperatures or complex processing.