Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs

By Ramana Ranganatham 1, Chirag Adiga 1, Michael Zuzak 2, Tejasvi Das 1
1 RAMLab, the Department of Electrical and Microelectronic Engineering, Rochester Institute of Technology.
2 Department of Computer Engineering, Rochester Institute of Technology, Rochester, NY, 14623

Abstract

Mixed-signal SoCs rely on nominally input-only analog pins to acquire off-chip signals, but the directionality of these interfaces is generally treated as a functional property rather than explicitly verified as a security property. This work identifies and experimentally demonstrates a directionality-based class of analog and mixed-signal (AMS) exfiltration attacks in which data-dependent circuit-offset modulation converts a nominally input-only pin into an outbound information channel. We analytically model the attack mechanism and identify three enabling host conditions: a closed-loop amplifier, an exposed amplifier input, and sufficiently high impedance at that pin. This attack class is validated through a representative silicon case study using a photoplethysmography (PPG) analog front-end (AFE) fabricated in a commercial 55-nm CMOS process. The payload incurs <0.001% area overhead relative to typical biosensing AFEs. Under the evaluated conditions, payload activation reduces the filtered PPG-output SNR by only 0.03~dB, while the maximum HT-induced perturbation of 5.9% of the PPG amplitude remains within the 34.3% benign variation at the exposed sensor-input pin across process and temperature. The raw exfiltration SINR remains below -20~dB, while targeted filtering increases it above 14~dB and enables signal recovery. Silicon measurements demonstrate data exfiltration through the input pin at bit rates up to 10~kbps and error-free recovery of a PRBS message. These results expose a conventional test-observability gap and establish analog pin directionality as an AMS security property requiring explicit verification, test coverage, and defense rather than being inferred from nominal signal flow.

Index Terms — Analog security, hardware security, hardware trojan (HT), exfiltration, analog front end (AFE), input-referred offset, analog pin directionality

To read the full article, click here

×
Semiconductor IP