product catelog


High Precision EM Probe
The High Precision HP EM Probe is a very sensitive probe used for Side Channel Analysis (SCA). It picks up electromagnetic emissions from semiconductor circuits. T
he probe has changeable tips with a directed coil and the probe has adjustable gain. The probe can pick up EM fields with frequencies up to 4.5 GHz and converts these into an AC signal.

Huracán Security Analysis Edition
Electromagnetic Fault Injection (EMFI) allows the user to introduce a fault in a targeted chip of the target system in the hope of bypassing security features. Comparing to laser FI and power FI, performing EMFI requires almost no modification to the target printed circuit board (PCB), making it very efficient in setup preparation. Figure 1 shows a high-level block diagram of an EMFI setup using Huracán and other Riscure equipment. The target can be any device with active CAN interface.
Huracán plays several roles in this EMFI setup. It supplies +12V to the system, communicates with the target chip directly or indirectly via CAN protocol, generates a trigger signal to Spider at the beginning or the end of a CAN frame transmission that kick starts a certain operation. The Spider will then control the EMFI transient probe to fire an EM pulse at the specified moment by the user.


Current Probe
The Current Probe is a passive, high frequency pick-up device for electric currents. It is used in Side Channel Analysis (SCA) to measure the power consumption of a target with great sensivity.


Glitch Amplifier
The Glitch Amplifier is device to power embedded targets, for example, FPGA’s of SOC’s. The Glitch Amplifier is capable of inserting high-speed glitches in the supply voltage while handling supply current. A pulse generator like Riscure VC-Glitcher or Spider can generate the signal for glitching


Laser Station 2
The Laser Station 2 is a workbench for optical Fault Injection (FI) attacks on semiconductors using a laser.
The workbench consists of a microscope on a stand with an XY-stage. The laser unit is mounted next to the microscope and laser light is inserted into the optical path of the microscope. Laser light is aimed and guided through a spot size reducer and an optical revolver to a spot area on the target. The optical revolver has space for five switchable objectives. Objectives for 5x, 20x, and 50x magnification can be purchased separately.
The microscope has a top camera for visual confirmation of the laser spot on the target. An external light source provides additional illumination for the top camera view.

Multi-Mode Diode Lasers
The Multi-Mode Diode Laser is a source of light produced by laser diodes with energy levels up to 20W power. Multi-Mode Diode Lasers are designed to operate in pulsed mode.
The Multi-Mode Diode Laser is normally attached to the Diode Laser Station and operated for optical Fault Injection (FI) attacks on semiconductors.

The Piñata board is a development board based on an ARM Cortex-M4F core working at a 168MHz clock speed. The board has been physically modified and programmed in order to be a training target for passive Side Channel Analysis (SCA) attacks such as Differential Power Analysis (DPA) or active Fault Injection attacks such as Differential Fault Analysis (DFA). Additionally, the source code and IDE is provided in order to allow users to extend the functionality of the board and use it as a development/prototyping board. The main features of the STM32F407IG/STM32F417IG CPU in the board are the following: - 1Mbyte internal FLASH memory, 196 Kbytes internal SRAM. Firmware updateable. - Floating point unit for single-precision arithmetic - I/O interfaces: 6x UART, 3x SPI, 3x I2C, 2x CAN, serial over USB, Ethernet, 140x GPIO pins - External memory controller for NAND/NOR FLASH, SRAM, PSRAM, CF - True Random Number Generator (TRNG) - Hardware crypto engine for DES, TDES, AES, hashing (MD5, SHA1) and HMAC. This option is only available in the hardware-crypto enabled model of the board.

Spider
The Spider is a generic, high-performance workbench to interact with embedded hardware. Such a workbench has many applications in side-channel analysis (SCA) and fault injection (FI) attacks. The Spider can read and respond to signals associated with protocols like JTAG, I2C and SPI, and thus provides an information channel to the internal processing state of targeted hardware.


Probe Station 5
The Probe Station 5 is a high precision probing workbench used in security evaluations. It is capable of moving an EM Probe, EM-FI Transient Probe or Compact Laser Microscope over the encapsulation of semiconductors chips and smart cards. The Probe Station is used with the EM Probe, EM-FI Transient Probe or Compact Laser Station to detect and perturb cryptography related hotspots in a target

icWaves offers a solution for this. This FPGA-based device generates a trigger pulse after real-time detection of a pattern in the power or EM signal of a chip. icWaves has a special narrow band-pass filter built in to enable the detection of a pattern even in noisy signals. The latter is important because side channel signals are typically noisy and detecting a predefined pattern is therefore not always feasible without a tuneable filtering mechanism. Besides triggering a fault, icWaves is also used to prevent a smart card from shutting down after detecting a fault injection attack. By detecting the wave pattern that indicates the shutdown of the card, icWaves generates a trigger to stop the shutdown process.

CleanWave (无接触模式13.56M,过滤模拟信号)

When testing for side channel leakage in a contactless solution, the 13.56 MHz carrier wave of the reader introduces significant noise in the measurements. The CleanWave consist of analog filters that reduce the RF signal while preserving the leakage signal from the contactless smart card. As a result, the input voltage range of the digital oscilloscope can be reduced which leads to a reduction of the quantization error and consequently to a better signal to noise ratio. While the CleanWave is designed to be used in combination with the Inspector EM probe for EMA-RF or Micropross MP300 TCL2 RF antenna for RFA, the filter can be used with any side channel test system.
Dual-function analog device for RFA and EMA-RF measurements.
Significant reduction of quantization error.
Integrated power supply for Riscure EM Probe.

Side Channel Analysis Ultimate
Ultimate performance for side channel analysis! Riscures state of the art side channel analysis functionality scalable on your server(s). Embedded devices can be tested against side channel resistance with the devices that are part of this bundle and analyzed with advanced methods like Deep Learning and Template attacks. Next to devices for accurate power and EM measurements, this setup also include devices for advanced patern based triggering and Riscures Transceiver to enable optimal hardware signal filtering. The setup is completed with a workstation fit for purpose and the complete Inspector installation with the most advanced analysis modules like Deep Learning and Template analysis. Extended warranty on the devices in this setup is included with a calibration device that enables you to test the quality of your devices whenever you like. To get you up to speed as fast as possible, we will install all equipment on-site and train your staff so that they can get started immediatly.
Includes:
- Current Probe
- EM Capacitor Probe Set
- EM Probe Station
- High precision EM probe
- icWaves
- Transceiver
- Spider
- LeCroy Waverunner 9404M Oscilloscope
- Pinata H
- Inspector subscription Acquisition professional - 3 years
- Inspector subscription Analysis professional - 3 years
- Inspector subscription Analysis premium - 3 years
- License:
- 1x - Inspector subscription seat(s) with dongle - included
- 2x - Additional subscription seat with dongle
- Total of 3x licenses included
- Workstation for Inspector
- 4 trainees Essential SCA Training - 3 days
- 4 trainees Advanced SCA Training - 2 days
- 2 trips for 1 trainer included
- 1 day installation

Fault Injection Ultimate
The complete range of devices offering all fault injection capabilitites Riscure has available. Embedded devices can be tested against fault injection resistance with the devices that are part of this bundle. High percision laser attacks can be executed efficiently because of the easy to use laser station in combination with a variety of laser sources. Even double laser attacks can be done with the same level of easy that your staff will get used to fast when working with Riscure laser devices. Apart from laser fault injection attacks, this bundle also consists of devices used for EM and voltage glitching attacks. The hart of all these setups will be formed by our Spider, which is able to communicate over lots of protocols to all your targets and is capable of clock glitching too. Next to those, this setup also include devices for advanced patern based triggering and Riscures Transceiver to enable optimal hardware signal filtering. The setup is completed with a workstation fit for purpose and the complete Inspector FI installation with both a Java framework of a Python framework for you to use. Extended warranty on the devices in this setup is included with a calibration device that enables you to test the quality of your devices whenever you like. To get you up to speed as fast as possible, we will install all equipment on-site and train your staff so that they can get started immediatly.
Includes:
- Laser station 2 high precision XYZ stage & Safety Box
- Twin Scan LS2 Upgrade
- 1064nm NIR Diode Laser (20W, 25MHz, multimode)
- 445nm Blue Diode Laser (3W, 25 MHz, multimode)
- 808nm Deep Red Diode Laser (14W, 25MHz, multimode)
- DPSS Laser 1064nm
- DPSS Laser 532nm
- Riscure/Alphanov PDM2+HP 980nm
- Riscure/Alphanov PDM2+HP 1064nm
- Microscope objective, 5X Objective M-Plan NIR
- Microscope objective, 20X Objective M-Plan NIR
- Microscope objective, 50X Objective M-Plan NIR
- Microscope objective, 100X Objective M-Plan NIR
- Infrared lightning for Microscope
- XYZ precision stage
- EM-FI Transient Coils (High precision)
- EM-FI Transient Probe
- BBI Probe Set
- Glitch Amplifier
- High Power Glitch Amplifier
- icWaves
- 2x Spider
- Transceiver
- 2x PicoScope 3206D Oscilloscope
- Pinata H training target
- Inspector subscription FI professional - 3 years
- 1x Inspector subscription seat(s) with dongle included
- Additional 1x Inspector Subscription seat with dongle
- 2x Workstation for Inspector
- 4 trainees Essential FI Training - 2 days
- 4 trainees Advanced FI Training - 2 days
- 2 trip for 1 trainer included
- 2 days installation
