A little old, but still a good read. "This paper discusses the hardware foundations of the cryptosystem employed
by the XboxTM video game console from Microsoft. A secret boot block overlay
is buried within a system ASIC. This secret boot block decrypts and verifies
portions of an external FLASH-type ROM. The presence of the secret boot block
is camouflaged by a decoy boot block in the external ROM. The code contained
within the secret boot block is transferred to the CPU in the clear over a set of
high-speed busses where it can be extracted using simple custom hardware. The
paper concludes with recommendations for improving the Xbox security system.
One lesson of this study is that the use of a high-performance bus alone is not a
sufficient security measure, given the advent of inexpensive, fast rapid prototyping
services and high-performance FPGAs."
|