
so the world jot WS a lot yeah on I work which is a small kind of research and covers pretty much all the mobile syst and stuff like that but yeah that's pretty much my background I do a lot of system stuff [Music] reg so kind of runs on today a primer conductors are put together how we can unput them together what is engineering of a hob so let's jump it why would be one of R engineer it seems a bit excessive right kind one the big on is attack surfes that we traditionally looked at research perspective small smaller they are these are on the vendor side so it's dep increasing on that there's a lot of
[Music] solutions so get anymore that does make difficult forens security research uh of the other big frustration these days is could using ke that are ined in Silicon there not a whole lot you can do with that unless so another one of those chicken again if you're what do you need it that's a still issue and kind of another big one is traditionally where we would like toct from a hard target you go injection analysis Tye in vors significant invest in this this past 10 years so that's increasing the past for the most prodcts as well and yeah the other good thing about s is for a single rision of a GU is kind of a fixed cost investment you do it
once all of the that fix cost is quite High ini and yeah I mean is the gr it has to be there you can Rel and make life more difficult but itly implemented on [Music] that and the most important re it's pretty quick so uh so and semiconductors we got to before we can stuff yeah so semiconduct design of the modern processes so you have language synthesis likeing Fring Trey all synthis for us hearing perspective and the most important ones are how are on the and general floor planning so yeah the final form is a format called pdsi kind of format it's been around for the longest time these you see botom that's individual transition trans
for you stage yeah that's kind [Music] traditionaly so this synthesization process like that we have an HL language PHL very anything of the sort similar the next step is mapping that so okay so process development this is what semiconductor will give you as a customer goes effectively in this case prob see that butross se cell [Music] is and the [Music] poity yeah thiser the single standard stand cell is effectively a cell CH across many many it's B building box the final chip made up with many many many standard give you an idea that's a very minimal chip on the right side single solo so just IDE in reality like your interships any other it's on
this [Music] so so [Music] GS process takies they do the process packing theing packaging interesting proc Eng again the itself so it has to be attached to something electronically so this say which has that's [Music] see so yeah kind of couple different styles tradition kind of chips and stuff like that you see old style [Music] stuffs more yeah kind of unfortunately for us as R Engineers these processes are kind of one way it's quite UND them some pretty nasty methods so looking at these bonding anding Tech dep this kind SL so again the traditional style you have middle [Music] yeah machine this [Music] [Music] isun uh so looking at what the looks like crosssection this is coming
make of have a bunch of interc which is effectively you knowes same
[Music] for so vertical connection [Music] give you an idea [Music]
sowhere [Music] small uh so yeah that's why together we don't really care about that so much we care about getting the D back on so how do we do process system uh we'll do this one briefly uh because there's a bunch of laws in UK which kind of suck do this stuff so just this but methods for actually deure the7 a lot of these meod very [Music] prise specific level [Music] but uh and then some tech [Music] to chips actually EAS [Music] just so those [Music] arees the D from the epoxy setting but because the D has a bunch of metal layers typically interested in transistors of body the actual logic which means all these on top of this is
separate process [Music] foray pretty [Music] here that's not best you can also do some more aot [Music] money you get times so this is the most Lev way you have a lot [Music] machine in Aion the issue with [Music] is [Music] Advan it's very high removal rate and again using [Music] so of the the topic SC El be what so yeah kind of one thing is why you need first part first place because traditional mics for icse engineering like 90s and80s limited by this called the wavelength of light limits the thetical maximum resoltion us the most modern sizes but micos using El instead so the is much and get much higher yeah that's that's pretty boring
uh a lot of about that so what does it look like in reality this is kind ofle this so we have particular gsmc process here that may or may not be involved soon that's nor opal of Interest left of the and this is the resol we can so you can kind seeu but it's a bit of a blow not to we jump up elect mic this is kind of the scene region theol is much higher can actually see so the structures we'll talk that later but yeah for us as RSE Engineers this use mod there's yet again sort further to
yeah if you need [Music] use resol andle unless process so the systems the you have the tradition University or research is much the same you have chamber [Music] El [Music] otherwi gender and that's kind of what does for so quite important uh for electronic sces it's not quite as simple it's just Prett under like an microscope a bit of an invol sequence for theing CH that like the chamber s on Sample holder putting the whole thing back on and have to pump the high vacuum it's B of the process spting on like Fingerprints of high problems basically are not so work the whole process traditional otherwise lower resol [Music] it'ses like this [Music] you that makes a lot
[Music] dist uh so yeah top itself as this elect assembly you basically have at top which [Music] electrons [Music] lenses [Music] important so what doing is if you know how sequence picture [Music] being uh the other one was talk reverse is different sources [Music] ELR uh these are fine uh if you want to do more advanced noes more recent stuff you kind of struggle with one of these uh you really want to switch up to as a fission so see here the difference in [Music] those so if you want to do [Music] so yeah this is kind of the other big one um for reverse engineering we kind of use this in a couple of ways so the
the way that the electron being actually interact is quite important it a bunch of things when the electron F the sample secondary electrons surface level so the top of the sample is what weing with this um yeah p and it's really high resolution well what we can do as well is electrons from quite low which means versus reverse engineer so you can leave on the top and [Music] ELR but also being able to [Music] and yeah as it says it's quite useful for cheating [Music] andar yeah so the other interesting thing about electrons is their intensity is kind of directly proportional to the theom interacting with the set number so different elements different intensities which is the same for semiconductors you
have different in [Music] Al as well so you kind of use that to [Music] figure reverse [Music] engering kind of interesting one as as the elergy a that us these number so that we canally identify material [Music] so that a lot of words what does this actually look like issue this is what Ty [Music] second difference so you see that it's a lot more Elemental Focus you can see these [Music] quite so that's different aspects and [Music] to the one the we tell that [Music] these [Music] composition so elements [Music] so that's of the produces an image what do we need to do scale samples in there sample preparation for S is a bit more involved
so yeah uh for most SS they need to be completely dry which is a bit more especially at some point to so we have put through some kind of CRI Point dryer up in yeah specific s can handle these things but really like for the [Music] traditional buy you really [Music] wanty pretty Sol yeah I mean again about hydrocarbons not friend of be pretty clean so TR pretty much the standard uh and yeah the thing about or is a Sol half the BR so you need to something for some get away with it for others not so much and this is a process something very [Music]
yeah [Music] coil so SS bit at times is of into such as signation like this to correct this pretty often especially chevels think cring it's quite easy to see C object sh in both directions as [Music] change B is so again if you're see this not good kind of the [Music]
we need conc here is primarily current and then current quite accelerating voltage it's not good for the but it's pretty much the ideal semiconduct setup so secondary [Music] a [Music] bu um so what kind of possibilities that this open up rever engineering once you configured everything you sample one the big ones is CS so for us it's very unlikely that we'll know what what process and all these different prop using the so you have to go through like this C you ever Eder anything like that it's quite similar to setting up type Library struct this different stand cells you [Music] not yeah these are kind ofing box so you understand these can engine the ship in entirety and a
lot of times we have cust standard cellers which Implement BLS and security so these are quite important [Music] going um there is sort of limited options foring a reconstruction so this is effectively if you cells and you can image each effec you can reconstr enlas in some cas so instead of engineer small segs of ship enti it these are like six figer investment Tye tools so verying however they exist and it is [Music] option so outside ofk C for us as Engineers something quite important is structures [Music] and enables you to one time program Z One typically or abuse I guess inors to store configurations such as super or also sub foration so if you can sensitive matter
you get effectively uh these from but TMC is a to focus on one is a standard TSC and these [Music] particular by pass
access uh a couple of other methods um for like bigger Siz [Music] line [Music] midle yeah so if you want to take an array ofes can have to follow this process probably and Stitch all these individual image together andic say a lot of just
like very simple this the other one is how these are accessed so if you have noes each column and each each row actually access L right or is a scram man you need to go back reversing and the kind ni thing do is if you understand these address we can just wred get and yeah some pretty spicy things so
so FES quite another interesting thing is Ms so this is basically W so firm some but it's all pretty low level so it be the initial up or something like that which is quite for usability Eng um it's quite quite a similar process to how we look at FS so you have the IND indiv a couple way that they do that however again we just understand the number of coding you can see you get so that often pretty easy process on
pretty variable that's kind of the things that we can do with scan microscope which quite as a kind of the next big thing is outside of you have purps which are very similar machines except instead of using electrons they use ions to bombard something so yeah yeah not too similar using ions traditionally they used to be their own units but cross units that have so you can image and use different types of vibs so you got PBS ands um which as a reverse we're not really using those for anything fan day and REM material much quicker so yeah the prim of the f is use ions to from the surface Tet so we actually use that to expose particular
price sh so one but also a prry gas you deposit to so if you want to deposit platinum or or something else on [Music] the um yeah so the pr gas is system for the gas inection system is with just a bunch of nozes quite small and direct where you need something surface so you can use this to accelerate the action which prober but again you can also use you can or use Plum line across in in our case engineering the prim use Cas for this is doing something build a f circuit which meally edit the functionality on the
ship yeah
differents yeah there are some artifacts in
[Music] they're quite expensive again but pretty much everything withs andit so and yeah so the big one as well [Music] iside increased exponentially particular quite for [Music] us yeah I mean it's selectively like this here she's quite a bit higher than normal kind of what you're trying to optimize here is how much time you need
R uh yeah so I mentioned circul thisly before kind that looks like in reality OB see you have all the functionality is implemented level but with we can just change it so if they have a condition that says should be disabl line that says no should be enabled that does a lot of to get level so pretty much the cheap code for uh um that like quite a bad thing what you do to this happening so measures couple things you have the at a very basic level usually so left right up down bit Lin lines but some some somewhere thought what if you scramble so it change the order happens it's kind of like okay that's the thing you can do
but it's another 15 minutes figure so again this F but they do do it I guess prevent some very low effort attacks you can even D the power stor and just peration so you get so there was an effort and something else that they tried of thises on the very top layer ofip you have a bunch of these Lin TPM and stuff that sh bits is Bunch lines so get right back of the chip one of those SE monitor chip from or so that's Prett an kind of is micro you have needle the ship so it's basic very small [Music] again just all of these lines figure out they go back to uh so all figure out where they
going so yeah I mean again another vation but one of the best it uses one of the aspects of process which is called an ede effect so typically when age the mechanical means laughing at and [Music] withes material gradually however the abiv gather at the edges of the DI so each of the leing edges will have a little bit more on and this leads to the edges of the so that's quite bad you lose a lot of information on um some genius one of the figed this so they started to all those structures such as ctivities and anything bring [Music] up is quite [Music]
annoying again this one's actually pretty good meure quite pretty usually
sucessful sacrificial slice a bit of another ey off the same place it on the Le Edge and B
[Music] protect so I think three for three mitigations are pretty useless it does kind of increase the much Techni use but at the end of the day still do couple other things like as are three big ones [Music] pretty so all these some expensive right like Baseline one will be 16,000 p as three pressure gases how you do this [Music] hobbyist uh you be surprise and eBay your friends your local ones t on there's a Lotus University laboratory I think TK has so it range anywhere from like 2 to [Music] 3K always want to keep an eye on some and yeah I mean some go through period so the end actually pretty good so somebody some ones can cheap um
again size of are like 300 kg as they want them you can ridiculous values yeah recy another pretty good
part yeah near so like theys but in reality this is aiss improperly so it's going to require like weeks to so you can use that to your advantage the reality is these guys own these they just into a big lot of so again that's the key [Music] um and yeah so the other big Advantage for us is is no legitimate business is purchasing a second you're buying like the model that you can afford from the vendor R associated with from what's been loaded in there before it's something horribly video active or some horrible chemical does it even work what put into will the provider service contract so I don't really know
what the other good thing to do is buch of Stu there hundred webites all these but yeah [Music] got so the big one is do not contact vendors because you have bu three weeks and so that's always fun always trying to meetings I don't know about you guys but I don't [Music] have so yeah bit of Wast of time for everyone involved and best way is meeting up with people compes so quite a b one years for MC uh a lot of V there but also a lot of service people they are pretty forthcoming with UHA and service so right people those kind of conferences you get a bunch of Japanese that across that's the key what say
people uh that sounds good however some associated with electron ownership uh yeah it's pretty awful idea all in all some pretty difficult PRS involved also systems you don't know how these how to rec these machine thees electron UPS itself they don't like being dropped the second hand have been dropped on the side so that's not a good good aspect the maintenance is pretty
BR and putting them all together in one thing wor [Music] um yeah it's pretty [Music] to and the detectors have important aspect so you of
these there are some case studies bunch of buch Trends people in the industry who do have these so here y That's G in there as you do it can be done but it's a lifelong sort of activity collecting these things uh Peter inlands got a bunch of also Dan Dan Revolution machine these things s like lition so that's not an ideal set up for your however pretty good nonetheless uh yeah spirit app I believe he's like close to exceeding the floors Kg on the edge of what's actually suitable for thatment coup others a lot of these people want to remain anonymous the have been from universities think these have been disposed all the med so lot of that lot
of people that know someone that know has access so quite really and yeah me I this years ago so got a bunch of stuff in the apartment I think I'm up to on these are little desktop ones so they're lot lot more usable however they did a lot of reps so not not great unless you,
uh so yeah I mean conclusions pretty awesome things if you get your hands on one it does open up and you will reverse engineering and ability research they're not cheap try and get involved good way to get to in your local University you can rent it some in Te use it um need bring sensitive IP to use B they may not appreciate that however in most cases they're willing to help so do try and get involved machines if you have any questions on own business send message or something so that's pretty much everything [Applause]
[Music] various points yes um I getting close toig as well newes yeah is is s market second you can that yeah so you're kindy to get away that the open [Music]
[Music]
so with with the with the you make so you effectively have tunnel on your own interested in bottom layer kind a tricky with smaller sizes kind of the other thing I didn't really mention which is quite poent here is secure processes so I Stu CPM and they're not going to chips like these are much bigger 130m so it's a more expect yeah processes yeah exactly you said yeah do you have any ideas hard um and if I did I wouldn't really give them up however s cffs are quite a good one but they do increase the amount of so you'll [Music]
see yeah uh so I mean that's that's kind of a one trip you'll run into that so I think the their goal is to increase if you [Applause] chips be will to invest [Music]
[Music]
dotion the lower acceler voles you don't cause enough damage actually through P um the thing things like the you'll see of damage which doing but just as the end especially voltages you won [Music] any yeah what we talking uh yeah I mean usually like somewh 4K up 16k very much depends on the different application but the Size Doesn't really affect much like it's the same process for the address coding noted but it's the whole same process once you figure out how that address happens how the storage already matter
[Music]