Tempest

Public

@jameswill-winsock

Share Tempest

Check access before sharing the link.

Who can open this board

Anyone can open this board. No sign-in is required.

This link opens the latest version. Copying it does not grant additional access.

Loading…

README

Tempest : Open Hardware EM Side-Channel Analysis Platform

Important:

if you are here looking for review, firmware, gerber and pcb have been updated. There is no step models or 3d models for this project. Firmware is a fork of the SIPEED RV Debugger Plus, ported from the BL507 to the RP2040. All pcb files and gerbers have been uploaded for the carrier board for the primer. All pcbs are done.

latest readme for progress on the attack target available here.

Status

Early build. Built for Stardance @ Hack Club.

Current progress

Done:

  • Shrike-Lite ML-KEM accelerator is functionally complete (currently fighting Renesas place-and-route to get the final bitstream out).
  • Finished designing the Tang Primer 20K carrier board.
  • Finished designing the H Field Probe

In progress:

Demo video. Give me a while. Renesas Go Configure is quite the software, and the place-and-route tool keeps blowing up violently in my face.

Description

Tempest is an open hardware electromagnetic side-channel analysis platform built around a collection of custom-designed PCBs, analog front-end hardware, FPGA development boards, and open-source software for evaluating cryptographic implementations.

Or, in simpler English: Every chip leaks tiny electromagnetic signals while it's running. Those signals aren't supposed to contain useful information... but sometimes they do. Tempest tries to measure those leaks and figure out whether they reveal anything about the cryptographic algorithm running inside. The project is built around Shrike-Lite, my ML-KEM (Kyber) hardware accelerator running on a hilariously tiny Renesas SLG47910 FPGA. Shrike answers one question: "Can modern post-quantum cryptography fit on ridiculously small hardware?" Tempest answers the obvious follow-up: "Cool. Now how badly does it leak? ". Rather than buying a commercial side-channel lab, the goal is to design as much of the measurement hardware as possible from scratch so anyone can build the same setup themselves.

Why EM instead of power analysis?

Power analysis is the classic approach. The problem is... it usually means taking a knife to your PCB. You know, cut traces, insert shunt resistors, resolder stuff. That's perfectly fine on a $2 dev board. I ain't sure as hell doing allat to a motherboard I actually want to keep using afterwards. EM analysis measures the exact same switching currents, except instead of touching the power rail, you simply hold a small magnetic loop probe near the chip and measure the field it radiates. It's completely non-invasive, portable, and lets me move between different targets without modifying the hardware.

Project Architecture

Tempest is really two projects that work together.

Shrike
(Resource-constrained ML-KEM accelerator)

            ↓

Produces real electromagnetic leakage

            ↓

Tempest
(Open hardware instrumentation platform)

            ↓

Measures leakage

            ↓

Correlation analysis

            ↓

Can we recover useful information?

The long-term hardware stack looks like this:

Target FPGA / TPM
        │
        ▼
Shielded EM Probe
        │
        ▼
Active Probe + LNA
        │
        ▼
Filter / Analog Front-End
        │
        ▼
Capture Hardware
        │
        ▼
Python Analysis Pipeline

Hardware Designed For This Project

HardwareStatus
Shrike-Lite ML-KEM AcceleratorComplete (bitstream generation pending)
Tang Primer 20K Carrier BoardComplete
Shielded PCB EM ProbeComplete
Probe Calibration BoardComplete

Roadmap

  • Finish Shrike-Lite bring-up.
  • Build and validate a passive EM probe.
  • Build a calibration board to characterize probe performance.
  • Validate the analog front-end on a deliberately leaky AES implementation before touching Kyber.
  • Build the trigger/synchronization pipeline.
  • Perform correlation EM analysis against Shrike-Lite.
  • Scale to the Tang Primer 20K as a larger TPM stand-in.
  • Eventually move to a real motherboard TPM once the entire workflow is validated.

Original Hardware Contributions

Unlike the initial revision of this project, Tempest now focuses on designing the measurement hardware itself rather than simply integrating commercial equipment. Current hardware work includes:

  • Tang Primer 20K carrier board
  • Shielded PCB EM probe
  • Probe calibration fixture

Bill of Materials

ItemEst. Price (USD)SourceWhy
Tang Nano 20k$40RobuMain FPGA for ADC, SDR, trigger generation, timing/synchronization, counters, buffering/FIFOs, and control logic
Tang Primer 20K Carrier PCB~$20Self-designedCarrier for the Primer module (I already own the core board)
Passive Probe PCB~$15Self-designedShielded PCB H-field probe, source IEC 61967-6
Probe Calibration PCB~$15Self-designedRepeatable EM reference source, source IEC 61967-6 Appendix A
SPF5189Z RF Low Noise Amplifier$15REE52To boost passive probe signal
SMA Connectors, RG178, Adapters, Attenuators$30–60Pasternack, Amphenol, Mini-CircuitsRF interconnects
PCB fabrication & assembly~$50JLCPCBManufacturing the custom boards

Grand total: approx 215$ (down from last times 400$ yipee) The oscilloscope, precision positioning stage, and laboratory power supply have been removed from the grant request. The initial revision of Tempest is designed to be developed using low-cost hardware and custom-designed PCBs, with higher-end laboratory equipment treated as optional future upgrades rather than project requirements. BOM Revision 2: The Tang Mega 138K, Thorlabs positioning equipment, and benchtop power supply have been removed due to cost. They have been replaced with lower-cost alternatives where necessary. A second, lower-cost FPGA is still required for SDR, ADC, high-speed deterministic logic, trigger generation, timing/synchronization, buffering, and real-time control, which cannot be reliably handled by the host computer or RTL-SDR alone. BOM Revision 3: More stuff removed, I have discovered that I can offload a lot more stuff to the FPGA like ADC and SDR onto it via a research paper and other stuff as well. Cost has been bought down. Final cost is around approx 230$.

Repository Layout

  • rtl: Shrike-Lite accelerator, Future hardware targets

  • hardware: KiCad projects, Carrier board, Probe board

  • analysis: Capture software, CPA/CEMA pipeline

  • docs: Research notes, Measurements, Design reviews

Why this matters

Most public EM side-channel work either targets toy AES implementations or uses lab-grade near-field scanning rigs that cost tens of thousands of dollars. There's a real gap in documented, reproducible, low-cost EM side-channel analysis against post-quantum crypto specifically; ML-KEM side-channel resistance is an active research area (and a pretty hot one too - there's a hell lot of researchers taking a crack at it) and having a from-scratch hardware+software stack to poke at it is worth more to me than a paper result I can't independently reproduce.

If it works, you'll be able to:

  • build the hardware,
  • reproduce the measurements,
  • attack real cryptographic implementations,
  • and improve your own hardware designs by seeing exactly where they leak.

Besides... The math behind modern cryptography is ridiculously strong. Turns out the easiest way to break it is often just listening to the chip while it does the math. It's cool, isn't it? The math can't be cracked, but we sure as hell can crack the data anyways because of bad engineering decisions. :)

License

GNU GPLv3

Comments

No comments yet. Be the first to ask about this board.

Ask about this board

Sign in to BoardRepo

New here? Signing in creates your account; there is no separate sign-up.