ChipWhisperer Capture Rev2 The first capture hardware designed specifically for the needs of the embedded hardware security expert. Amplified analog input for power analysis. Device clock synchronization with external PLL for filtering. Voltagetranslators with high-speed IO & bidirectional support. Spartan 6 LX25 FPGA with high-speed USB connection for configuration and data transfer. Target programming & Control. Blinking lights. Travel-sized aluminum case. The hardware and software is entirely Open-Source, making this the perfect platform for your own experiments. Single-Channel Analog Input: 0-55 db gain, software adjustable 105 MSPS sample rate, synchronous to DUT 120 MHz analog bandwidth Clock Inputs: LVDS/CMOS input to PLL chip Front-Panel SMA (3.3V CMOS) Rear-panel clock input on TargetIO Connector Computer Connection: High-Speed USB 2.0 for FPGA configuration, data connection, power Full-Speed USB 2.0 for AVR programmer, optional power supply input TargetIO Connection: 20-Pin connector for target Voltage-translators for control of device via UART Clock input (from target) and output
Multi-Target Victim Board XMega Device ChipWhisperer Rev2 Connection 7.37 MHz, 3.579 MHz Oscillators Built-in Low Noise Amplifiers up to 40 db gain VCC/GND Shunts AtMega328P Device with Serial Connection The multi-target victim board provides a reference platform for side-channel attacks. Use the provided Mega328P as your first attack. You can then move on to more advanced attacks implemented in the XMega device. If you re interested in using the SASEBO-W with your ChipWhisperer, you can use the feed-through adapter (pictured left). Can use the AVR programmer built into the ChipWhisperer Capture Rev2 to download new programs to AVR or XMega device. The included breakout board (picture right) simplifies connection of external targets to the rear panel IO connector.
Probes Differential Probe Reduce noise by eliminating common-mode noise. Adjustable offset voltage, powered from ChipWhisperer Rev2 hardware or bench power supply for stand-alone use. Low Noise Amplifier Low Noise Amplifier. Use with included magnetic field probe, or just to amplify a small signal. Power provided by ChipWhisperer Rev2, or supply your own 3V source. +20dB gain, 0.5-1000 MHz bandwidth. Included H-Field probe (pictured right) can be connected directly to LNA input.
Software & Firmware The underlying technology is part of the Open-Source ChipWhisperer project. This means you are free to modify every aspect of the hardware or software, ideal for the academic research or the teaching environment. The Python-based ChipWhisperer- Capture software runs on Windows & Linux computers. Interfaces to a wide range of possible targets include the example AVR target, SASEBO- GII, and SAKURA-G. Adding new targets is simple due to the simple Python-based code base. Traces are stored to several different formats, and can be exported for analysis in 3rd party software. ChipWhisperer-Analyzer software gives you a starting place for learning about side-channel attacks. Implementation of Correlation Power Analysis (CPA) for AES-128 algorithms can be expanded for a wide range of other targets. Functions for plotting results are provided, and results such as Partial Guessing Entropy (PGE) can be plotted or exported to other popular analysis software.
Specifications FPGA Type Available FPGAs (Not Officially Supported) Power Source Target Clock Inputs Target Clock Outputs Target Communication Lines Target Programming ADC Channels ADC Max Conversion Rate ADC Gain Range (LNA Input) ADC Maximum Input Volage (LNA Input) ADC Sample Clock ADC Sample Buffer Size Trigger Source Trigger Event Trigger Out Additional Trigger Features Spartan 6 LX25 using ZTEX Module LX45, LX75, LX150 Bus-powered via USB-Mini, or use USB-A for external 5V supply Front Panel SMA: 3.3V CMOS direct to FPGA Front Panel SMA: 3.3V CMOS via PLL chip to FPGA Front Panel Header: LVDS via PLL chjp to FPGA TargetIO Connector: 3.3V-5V CMOS to FPGA TargetIO Connector: 3.3V-5V CMOS from FPGA TargetIO Connector: 3.3V-5V buffered IO, 4 lines AVR-ISP MK-II compatible programmer provided 1 (2nd channel available as add-on in future) 105 MSPS -5 to 55 dbm -1.8 dbm / 0.635 Vp-p Synchronous or asynchronous to target, with adjustable phase delay and adjustable frequency multiplication 24K Samples, board provides DDR memory which can expand buffer to 32M Samples (not yet supported) Front-Panel, any of 4 TargetIO communication Line Rising/Falling edge, Digital or Analog Pattern Match Front-Panel Connector Programmable offset to capture Programmable pre-capture level
Ordering Information More Information: newae.com/sidechannel Online Store: store.newae.com Looking for the complete set? Purchase the CWREV2-KIT which includes everything you need for learning about side-channel analysis, and moving towards making your embedded products truly secure! Includes following parts: ChipWhisperer Rev2 Capture Hardware Multi-Target Adapter with AtMega328P Mounter in socket SASEBO-W Adapter Board Differential Probe Low Noise Amplifier H-Field Probe Breakout Board USB A-B Cable, 1 meter, with Ferrite USB A-B Mini Cable, 1 meter, with Ferrite SMA Cable, 12 6-pin, 8-pin, 20-pin IDC Cable Water-Tight Storage Case Includes padded storage case Disclaimer: The information in this document is provided in connection with NewAE Technology s products. No license, express or implied, by estoppel or otherwise, to any intellectual property right is granted by this document or in connection with the sale of NewAE Technology s products. NEWAE TECHNOLOGY ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR STATU- TORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL NEWAE TECHNOLOGY BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAM- AGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS AND PROFITS, BUSINESS INTERRUPTION, OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF NEWAE TECHNOL- OGY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. NewAE Technology makes no representations or warranties with respect to the accuracy or completeness of the contents of this document and reserves the right to make changes to specifications and product descriptions at any time without notice. NewAE Technology does not make any commitment to update the information contained herein. NewAE Technology products are not suitable for, and shall not be used in, automotive applications. NewAE Technology products are not intended, authorized, or warranted for use as components in applications intended to support or sustain life. NewAE Technology products are designed solely for teaching purposes.