Hardware Exploitation 12 min read • June 2023 (IOActive Labs)

Applying Fault Injection to the Firmware Update Process of a Drone

Bypassing digital signature verification routines during in-field drone firmware upgrade via precise timing and voltage glitch pulses.

Gabriel González García
Gabriel González García
Embedded Security Researcher & Author

Originally published at IOActive Labs, this research explores how physical hardware fault injection (voltage glitching) can be utilized to subvert secure boot and firmware validation mechanisms in commercial unmanned aerial vehicles (drones).

The Attack Surface: Firmware Upgrade Pipelines

Commercial drone platforms enforce digital signature verification using public-key cryptography (such as RSA-2048 or ECDSA) before allowing new firmware binaries to be written to flash memory. However, signature checking algorithms ultimately execute on microcontrollers that are vulnerable to electrical transients.

By injecting a precision negative voltage pulse onto the microcontroller's core power rail ({DD}$) during the exact clock cycle where the return value of verify_signature() is evaluated, an attacker can flip condition branch flags.

"A single nanosecond glitch can convert a failed cryptographic verification from 0x00 (DENIED) to 0x01 (SUCCESS), causing the device to happily flash unauthorized, modified firmware."

Trigger Synchronization & Oscilloscope Traces

The primary challenge in fault injection is trigger repeatability. By monitoring GPIO activity or power consumption spikes during hash calculations, we generate a deterministic trigger signal using an FPGA or fast microcontroller.

Target Verification Routine (ARM Cortex-M Disassembly)
; Cryptographic signature check routine
BL      crypto_rsa_verify        ; Return 0 if invalid, 1 if valid in R0
CMP     R0, #0                   ; Check result
BEQ     error_invalid_signature  ; <-- TARGET GLITCH POINT: Force branch to fall through
BL      flash_write_firmware     ; Firmware update proceeds!

Mitigations for Hardware Engineers

← Back to All Research Share on LinkedIn

Get New Research & U-Boot Lab Resources

Subscribe to receive notifications when new embedded security papers, reverse engineering tools, and U-Boot VM updates are released.