Hacker News front page13 min readadvanced
Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug
Summary
Researchers used photon‑emission microscopy to locate the DEBUGEN register on a decapsulated RP2350, then applied focused laser pulses to flip its bits, re‑enabling Secure debug and extracting a secret stored in OTP memory. The attack needs physical access and a $250 k lab setup, showing that the chip’s permanent debug‑disable can be overridden.
- Photon‑emission microscopy can map activity of individual register bits on a decapsulated MCU by comparing emission stacks of toggled bit patterns.
- Targeted 980 nm laser pulses (~1.2 W, 100 ns) can set DEBUGEN bits, re‑enabling Mem‑AP and granting Secure debug despite permanent debug‑disable.
- After restoring Secure debug and performing a rescue reset, the OTP‑protected secret can be read before the runtime lock is applied.
- The attack requires destructive chip preparation and expensive equipment (~$250 k), but demonstrates a practical bypass of RP2350’s debug‑disable mechanism.
Hardware security engineers and MCU vendors should care because it shows that permanent debug‑disable can be bypassed with targeted laser faults, undermining trust in on‑chip protection mechanisms.
7/10




