[Cryptech Tech] Tamper detection

Fredrik Thulin fredrik at thulin.net
Tue Jul 19 16:36:23 UTC 2016


On tisdag 19 juli 2016 kl. 17:24:37 CEST Leif Johansson wrote:
> Skickat från min iPhone
> 
> 
> > 19 juli 2016 kl. 17:02 skrev Jakob Schlyter <jakob at kirei.se>:
> > 
> > On 2016-07-19 at 16:49, Basil Dolmatov wrote:
> > 
> > 
> >>> Stated differently, the tamper daughterboard could feed the VBAT on the
> >>> Alpha instead of being fed by the VBAT on the Alpha.
> >>> 
> >>> Any downsides to that?
> >> 
> >> Daughter board can be absent, this should not lead to unusable tamper
> >> processor.
> 
> > 
> > But without tamper sensors, what should the tamper processors do?
>
> Handle the panic button

If the tamper processor is operating with the panic button as the only tamper 
input "sensor", I think a jumper from VCCO_3V3 to VBAT is adequate to power 
it. If you want to use a battery instead, by all means wire a single cell 
CR2032 battery to the VBAT header that is on the rev03 already.

The discussion with Rick led us to thinking that unless we have a true 10-year 
battery solution, it might be better to have the actual battery outside the 
tamper protection where it might be replaced (envisioning a meshed tamper bag 
here, among other things).

This of course means there should be enough power to wipe keys _inside_ the 
tamper boundary too - in form of one or more of these super-caps presumably.

/Fredrik



More information about the Tech mailing list