In this paper, we demonstrate the first successful extraction of the encryption key from the hardware AES accelerator in the nRF52832 Bluetooth Low Energy system-on-chip operating in Counter with CBC-MAC (CCM) mode using side-channel information recovered from RF signals. This attack marks a significant milestone, as previous attempts to break this accelerator were unsuccessful. Our results provide a critical insight into the proprietary hardware AES-CCM accelerator in the nRF52832, paving the way for future enhancements to its resistance to side-channel attacks. All the related data are made available to the research community to promote further analysis.
Part of ISBN 979-8-3503-5684-7; 979-8-3503-5683-0
QC 20260327