%PDF-1.5
%
1 0 obj
<<
/Type /Catalog
/Pages 2 0 R
/Outlines 3 0 R
/Names 4 0 R
/PageMode /UseOutlines
/Lang (en)
/Metadata 5 0 R
/PageLabels <<
/Nums [0 6 0 R]
>>
/OpenAction 7 0 R
>>
endobj
8 0 obj
<<
/Producer (pdfTeX-1.40.20)
/Author ( S.L. Thomas, J.V.d. Herrewegen, G. Vasilakis, Z. Chen, M. Ordean and F.D. Garcia )
/Title (Cutting Through the Complexity of Reverse Engineering Embedded Devices)
/Subject (IACR Transactions on Cryptographic Hardware and Embedded Systems, DOI:10.46586/tches.v2021.i3.360-389)
/Creator (LaTeX with hyperref)
/Keywords (Reverse engineering, Embedded device firmware, Hardware-based execution tracing)
/CreationDate (D:20210705214230+02'00')
/ModDate (D:20210705214230+02'00')
/Trapped /False
/PTEX.Fullbanner (This is pdfTeX, Version 3.14159265-2.6-1.40.20 \(TeX Live 2019/Debian\) kpathsea version 6.3.1)
>>
endobj
2 0 obj
<<
/Type /Pages
/Count 31
/Kids [9 0 R 10 0 R 11 0 R 12 0 R 13 0 R]
>>
endobj
3 0 obj
<<
/Type /Outlines
/First 14 0 R
/Last 15 0 R
/Count 10
>>
endobj
4 0 obj
<<
/Dests 16 0 R
>>
endobj
5 0 obj
<<
/Length 14872
/Type /Metadata
/Subtype /XML
>>
stream
XMP Media Management Schema
xmpMM
http://ns.adobe.com/xap/1.0/mm/
DocumentID
URI
internal
UUID based identifier for all versions and renditions of a document
InstanceID
URI
internal
UUID based identifier for specific incarnation of a document
VersionID
Text
internal
Document version identifier
PRISM Basic Metadata
prism
http://prismstandard.org/namespaces/basic/2.1/
complianceProfile
Text
internal
PRISM specification compliance profile to which this document adheres
publicationName
Text
external
Publication name
aggregationType
Text
external
Publication type
bookEdition
Text
external
Edition of the book in which the document was published
volume
Text
external
Publication volume number
number
Text
external
Publication issue number within a volume
pageRange
Text
external
Page range for the document within the print version of its publication
issn
Text
external
ISSN for the printed publication in which the document was published
eIssn
Text
external
ISSN for the electronic publication in which the document was published
isbn
Text
external
ISBN for the publication in which the document was published
doi
Text
external
Digital Object Identifier for the document
url
URL
external
URL at which the document can be found
byteCount
Integer
internal
Approximate file size in octets
pageCount
Integer
internal
Number of pages in the print version of the document
subtitle
Text
external
Document's subtitle
Reverse engineering, Embedded device firmware, Hardware-based execution tracing
1.5
True
http://creativecommons.org/licenses/by/4.0/
application/pdf
Cutting Through the Complexity of Reverse Engineering Embedded Devices
Cutting Through the Complexity of Reverse Engineering Embedded Devices
IACR Transactions on Cryptographic Hardware and Embedded Systems, DOI:10.46586/tches.v2021.i3.360-389
IACR Transactions on Cryptographic Hardware and Embedded Systems, DOI:10.46586/tches.v2021.i3.360-389
Licensed under Creative Commons License CC-BY 4.0.
Licensed under Creative Commons License CC-BY 4.0.
2021-07-05T21:42:30+02:00
en
Text
S.L. Thomas
J.V.d. Herrewegen
G. Vasilakis
Z. Chen
M. Ordean and F.D. Garcia
Reverse engineering
Embedded device firmware
Hardware-based execution tracing
36-tches.tex
2021-07-05T21:42:30+02:00
2021-07-05T21:42:30+02:00
2021-07-05T21:42:30+02:00
LaTeX with hyperref
uuid:c9590aea-e4ce-4aef-ba33-3390a39054ce
uuid:18820595-900a-4efd-b59b-675f7a88d7a8
three
IACR Transactions on Cryptographic Hardware and Embedded Systems
journal
2021
3
360-389
2569-2925
10.46586/tches.v2021.i3.360-389
endstream
endobj
6 0 obj
<<
/S /D
/St 360
>>
endobj
7 0 obj
<<
/S /GoTo
/D [17 0 R /Fit]
>>
endobj
9 0 obj
<<
/Type /Pages
/Count 7
/Parent 2 0 R
/Kids [18 0 R 17 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R]
>>
endobj
10 0 obj
<<
/Type /Pages
/Count 6
/Parent 2 0 R
/Kids [24 0 R 25 0 R 26 0 R 27 0 R 28 0 R 29 0 R]
>>
endobj
11 0 obj
<<
/Type /Pages
/Count 6
/Parent 2 0 R
/Kids [30 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R]
>>
endobj
12 0 obj
<<
/Type /Pages
/Count 6
/Parent 2 0 R
/Kids [36 0 R 37 0 R 38 0 R 39 0 R 40 0 R 41 0 R]
>>
endobj
13 0 obj
<<
/Type /Pages
/Count 6
/Parent 2 0 R
/Kids [42 0 R 43 0 R 44 0 R 45 0 R 46 0 R 47 0 R]
>>
endobj
14 0 obj
<<
/Title (Introduction)
/A 48 0 R
/Parent 3 0 R
/Next 49 0 R
/First 50 0 R
/Last 50 0 R
/Count -1
>>
endobj
15 0 obj
<<
/Title (Analyzing the Huawei R216h Baseband with Incision)
/A 51 0 R
/Parent 3 0 R
/Prev 52 0 R
>>
endobj
16 0 obj
<<
/Kids [53 0 R 54 0 R]
/Limits [(AlgoLine.1.1) (table.2)]
>>
endobj
17 0 obj
<<
/Type /Page
/Contents 55 0 R
/Resources 56 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 9 0 R
/Annots [57 0 R 58 0 R 59 0 R 60 0 R 61 0 R 62 0 R 63 0 R 64 0 R 65 0 R 66 0 R
67 0 R]
>>
endobj
18 0 obj
<<
/Contents 68 0 R
/Type /Page
/Resources <<
/Font <<
/F1 69 0 R
/F2 70 0 R
/F3 71 0 R
/F4 72 0 R
>>
/XObject <<
/Xf1 73 0 R
>>
>>
/Annots [74 0 R 75 0 R 76 0 R]
/Parent 9 0 R
/MediaBox [0 0 595 842]
>>
endobj
19 0 obj
<<
/Type /Page
/Contents 77 0 R
/Resources 78 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 9 0 R
/Annots [79 0 R 80 0 R 81 0 R 82 0 R 83 0 R 84 0 R 85 0 R 86 0 R 87 0 R 88 0 R
89 0 R 90 0 R 91 0 R 92 0 R 93 0 R]
>>
endobj
20 0 obj
<<
/Type /Page
/Contents 94 0 R
/Resources 95 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 9 0 R
/Annots [96 0 R]
>>
endobj
21 0 obj
<<
/Type /Page
/Contents 97 0 R
/Resources 98 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 9 0 R
/Annots [99 0 R 100 0 R 101 0 R 102 0 R 103 0 R]
>>
endobj
22 0 obj
<<
/Type /Page
/Contents 104 0 R
/Resources 105 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 9 0 R
/Annots [106 0 R 107 0 R]
>>
endobj
23 0 obj
<<
/Type /Page
/Contents 108 0 R
/Resources 109 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 9 0 R
/Group 110 0 R
/Annots [111 0 R 112 0 R]
>>
endobj
24 0 obj
<<
/Type /Page
/Contents 113 0 R
/Resources 114 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 10 0 R
/Annots [115 0 R 116 0 R 117 0 R]
>>
endobj
25 0 obj
<<
/Type /Page
/Contents 118 0 R
/Resources 119 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 10 0 R
/Group 120 0 R
/Annots [121 0 R 122 0 R 123 0 R 124 0 R]
>>
endobj
26 0 obj
<<
/Type /Page
/Contents 125 0 R
/Resources 126 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 10 0 R
/Annots [127 0 R 128 0 R 129 0 R 130 0 R 131 0 R 132 0 R 133 0 R]
>>
endobj
27 0 obj
<<
/Type /Page
/Contents 134 0 R
/Resources 135 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 10 0 R
/Group 136 0 R
/Annots [137 0 R 138 0 R 139 0 R 140 0 R]
>>
endobj
28 0 obj
<<
/Type /Page
/Contents 141 0 R
/Resources 142 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 10 0 R
/Annots [143 0 R 144 0 R 145 0 R 146 0 R 147 0 R]
>>
endobj
29 0 obj
<<
/Type /Page
/Contents 148 0 R
/Resources 149 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 10 0 R
/Annots [150 0 R 151 0 R]
>>
endobj
30 0 obj
<<
/Type /Page
/Contents 152 0 R
/Resources 153 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 11 0 R
/Group 154 0 R
/Annots [155 0 R 156 0 R 157 0 R 158 0 R 159 0 R]
>>
endobj
31 0 obj
<<
/Type /Page
/Contents 160 0 R
/Resources 161 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 11 0 R
/Group 162 0 R
/Annots [163 0 R 164 0 R 165 0 R 166 0 R 167 0 R 168 0 R]
>>
endobj
32 0 obj
<<
/Type /Page
/Contents 169 0 R
/Resources 170 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 11 0 R
/Group 171 0 R
/Annots [172 0 R 173 0 R]
>>
endobj
33 0 obj
<<
/Type /Page
/Contents 174 0 R
/Resources 175 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 11 0 R
/Annots [176 0 R 177 0 R 178 0 R 179 0 R 180 0 R 181 0 R]
>>
endobj
34 0 obj
<<
/Type /Page
/Contents 182 0 R
/Resources 183 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 11 0 R
/Group 184 0 R
/Annots [185 0 R 186 0 R 187 0 R]
>>
endobj
35 0 obj
<<
/Type /Page
/Contents 188 0 R
/Resources 189 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 11 0 R
/Group 190 0 R
/Annots [191 0 R 192 0 R]
>>
endobj
36 0 obj
<<
/Type /Page
/Contents 193 0 R
/Resources 194 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 12 0 R
/Annots [195 0 R 196 0 R 197 0 R 198 0 R 199 0 R 200 0 R 201 0 R 202 0 R 203 0 R 204 0 R
205 0 R 206 0 R 207 0 R 208 0 R 209 0 R 210 0 R 211 0 R 212 0 R 213 0 R 214 0 R
215 0 R 216 0 R]
>>
endobj
37 0 obj
<<
/Type /Page
/Contents 217 0 R
/Resources 218 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 12 0 R
/Annots [219 0 R 220 0 R 221 0 R 222 0 R 223 0 R 224 0 R 225 0 R 226 0 R 227 0 R 228 0 R
229 0 R 230 0 R]
>>
endobj
38 0 obj
<<
/Type /Page
/Contents 231 0 R
/Resources 232 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 12 0 R
/Annots [233 0 R 234 0 R 235 0 R 236 0 R 237 0 R 238 0 R 239 0 R]
>>
endobj
39 0 obj
<<
/Type /Page
/Contents 240 0 R
/Resources 241 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 12 0 R
/Annots [242 0 R 243 0 R 244 0 R 245 0 R]
>>
endobj
40 0 obj
<<
/Type /Page
/Contents 246 0 R
/Resources 247 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 12 0 R
/Annots [248 0 R 249 0 R 250 0 R 251 0 R 252 0 R]
>>
endobj
41 0 obj
<<
/Type /Page
/Contents 253 0 R
/Resources 254 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 12 0 R
/Annots [255 0 R 256 0 R 257 0 R 258 0 R]
>>
endobj
42 0 obj
<<
/Type /Page
/Contents 259 0 R
/Resources 260 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 13 0 R
>>
endobj
43 0 obj
<<
/Type /Page
/Contents 261 0 R
/Resources 262 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 13 0 R
>>
endobj
44 0 obj
<<
/Type /Page
/Contents 263 0 R
/Resources 264 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 13 0 R
>>
endobj
45 0 obj
<<
/Type /Page
/Contents 265 0 R
/Resources 266 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 13 0 R
>>
endobj
46 0 obj
<<
/Type /Page
/Contents 267 0 R
/Resources 268 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 13 0 R
/Group 269 0 R
/Annots [270 0 R 271 0 R 272 0 R 273 0 R 274 0 R 275 0 R 276 0 R 277 0 R 278 0 R 279 0 R]
>>
endobj
47 0 obj
<<
/Type /Page
/Contents 280 0 R
/Resources 281 0 R
/MediaBox [0 0 595.276 841.89]
/Parent 13 0 R
/Group 282 0 R
/Annots [283 0 R 284 0 R]
>>
endobj
48 0 obj
<<
/S /GoTo
/D (section.1)
>>
endobj
49 0 obj
<<
/Title (Background)
/A 285 0 R
/Parent 3 0 R
/Prev 14 0 R
/Next 286 0 R
/First 287 0 R
/Last 287 0 R
/Count -1
>>
endobj
50 0 obj
<<
/Title (Our Contribution)
/A 288 0 R
/Parent 14 0 R
>>
endobj
51 0 obj
<<
/S /GoTo
/D (appendix.C)
>>
endobj
52 0 obj
<<
/Title (Huawei R216h 4G/LTE CoreSight Configuration)
/A 289 0 R
/Parent 3 0 R
/Prev 290 0 R
/Next 15 0 R
>>
endobj
53 0 obj
<<
/Kids [291 0 R 292 0 R 293 0 R 294 0 R 295 0 R 296 0 R]
/Limits [(AlgoLine.1.1) (subfigure.2.1)]
>>
endobj
54 0 obj
<<
/Kids [297 0 R]
/Limits [(subfigure.2.2) (table.2)]
>>
endobj
55 0 obj
<<
/Length 3776
/Filter /FlateDecode
>>
stream
xڝZYs6~ׯGV xicrqR6@q03\-ontCR:)>v+ɋ0Z%""ޮU" zͻTu46,Wyovmv9u}OBj
~]Ļ9]f1꿺zSu_t/0eZ~A*ҵ:^3j'֔J>?6APO}I*p%aKurNV
W/Zt&ыvΑ%@rkX"._ZX(Z(_t |Q]fyPySJOfK}̝i;cSj
]ژvu2uL镹+rce+ CԐjLRּ*"-rZ!Mug}VSD&=W٘~gmk@mbLޜ}M+˺nXD"H@q賂V9ػ8BHAPwECW ڼȘS
Eqʌ.PA X4
TeV}V=ڠpޙгi'uI'2
+`QNw#ߟXa9vbȉU^2zbg9߿睸REYz>!
SRGDڷ7]߂cV
_SJ%PGB%ru]ܟ6}$:f}Wto f@6ԳaP?+K>n.cU"`)RDް*ZӁꃒPevO2 ʇ/,!0nx
?6=="MU2KԱ#<y
V'j*
- aZ$*4T{7mVZ1AE
rl n$GEΞmJ6hY"9{A< jIP:bW#uxY,hS5Φ
u*BY5[8hc(Zb^bxnqhj<ZGtWdF{&;d'k6ɊqT10:g[_yѡDD,coHLDCtB;EqMA:B'1|W@"CLаmX5x-
X{+t>ϬoKá=msS*V)Y6C>ҍcYahU¶|ضQπ`PT#*i
rެδ쭎
e?Nn>D-*yBu
~,LiIp5{ɬ&RKXigjMcȜSڦbEN9^P8FbD!ADDhEuHu7Z%0ue#1(0ng$k=mrS,.X7V^Bh2>Q}({0iǬt,(სdPƊ#8ȕ p![