The tamper controller peripheral handles input from internal and external physical attack detectors and controls the device response.
The following figure shows an overview of the TAMPC detectors, input, and output.
- Detection of external tampering attacks
- Detector supporting an active driven shield mounted on a PCB that is on top of a device
- Detection of fault injection attacks (voltage glitching, electromagnetic fault injection, etc.)
- Signal protector to guard critical configuration signals
- Glitch detectors to protect internal logic
- Built-in self-check for correctness inside the CRACEN
The tamper detectors are divided into two categories: external and internal. The external detectors rely on external stimuli through dedicated GPIO pins, and the internal detectors rely on internal signals not exposed outside the device package.
External tamper detectors
A tamper attack detected by any of the external tamper detectors indicates that a break-in attack is ongoing. This could include breaking the product encapsulation. This is detected through the external active shield detectors.
Internal tamper detectors
A tamper attack detected by an internal tamper detector indicates that the device's internal logic could be affected by the attack, the system state could be compromised, and thus not to be trusted. Recommended operation is to utilize the TAMPC automatic system wide reset feature, see PROTECT.INTRESETEN.CTRL. This ensures the device is operating in a safe and known state after an attack has been detected. The automatic reset from TAMPC triggers SECTAMPER to be set in the reset reason register. The device should on the following reset check for SECTAMPER in the reset reason register and take necessary action.