Glossary

Threat model

Beginner

A list of what an attacker might want from the chip, who they might be, and how they could try to get it.

Novice

A document that names what must be protected (secret keys, software, user data), who might attack (remotely, with the chip in hand, or from inside the supply chain) and where they could get in. Security requirements are written from it.

Expert

Covers logical attacks; physical attacks such as side-channel analysis (reading secrets from power use or timing) and fault injection (glitching voltage or clock to make the chip misbehave); and test and debug ports as a way in. It must exist before architecture, because countermeasures change the block diagram and the test design.

Explained in Specification (Design Flow).

See also: side-channel attack.

All 896 terms →