2 \author Travis Goodspeed
3 \brief Glitching Support for GoodFET20
5 See the TI example MSP430x261x_dac12_01.c for usage of the DAC.
6 This module sends odd and insufficient voltages on P6.6/DAC0
7 in order to bypass security restrictions of target devices.
15 //! Call this before the function to be glitched.
18 WDTCTL = WDTPW + WDTHOLD; // Stop WDT
29 //Set GSEL high to disable glitching.
31 //Normal voltage, use resistors instead of output.
32 //P5DIR=0x80; //ONLY glitch pin is output.
33 P5OUT|=0x80; //It MUST begin high.
34 //P5REN|=0x7F; //Resistors pull high and low weakly.
39 WDTCTL = WDTPW + WDTHOLD; // Stop WDT
40 TACTL = TASSEL1 + TACLR; // SMCLK, clear TAR
41 CCTL0 = CCIE; // CCR0 interrupt enabled
42 CCR0 = glitchcount+0x10; // Compare Value
43 TACTL |= MC_2; // continuous mode.
47 // Timer A0 interrupt service routine
48 interrupt(TIMERA0_VECTOR) Timer_A (void){
50 //P5DIR=BIT7; //All else high impedance.
58 //! Glitch an application.
59 void glitchapp(u8 app){
60 debugstr("That app is not yet supported.");
64 //! Set glitching voltages.
65 void glitchvoltages(u16 gnd, u16 vcc){
67 //debugstr("Set glitching voltages: GND and VCC");
71 /** N.B., because this is confusing as hell. As per Page 86 of
72 SLAS541F, P6SEL is not what controls the use of the DAC0/DAC1
73 functions on P6.6 and P6.5. Instead, CAPD or DAC12AMP>0 sets
78 ADC12CTL0 = REF2_5V + REFON; // Internal 2.5V ref on
79 // Delay here for reference to settle.
80 for(i=0;i!=0xFFFF;i++) asm("nop");
81 DAC12_0CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1
82 DAC12_1CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1
83 // 1.0V 0x0666, 2.5V 0x0FFF
84 DAC12_0DAT = vcc; //high;
85 DAC12_1DAT = gnd; //low;
88 //! Set glitching rate.
89 void glitchrate(u16 rate){
93 //! Handles a monitor command.
94 void glitchhandle(unsigned char app,
99 glitchvoltages(cmddataword[0],
104 glitchrate(cmddataword[0]);
108 //FIXME parameters don't work yet.
110 handle(cmddata[0],cmddata[1],0);
111 TACTL |= MC0;// Stop Timer_A;
114 _DINT();//disable interrupts
115 TACTL=0; //clear dividers
116 TACTL|=TACLR; //clear config
117 TACTL|=TASSEL_SMCLK| //smclk source
118 MC_2; //continuous mode.
120 //perform the function
121 silent++;//Don't want the function to return anything.
122 handle(cmddata[0],cmddata[1],0);
124 cmddataword[0]=TAR; //Return counter.
128 //Testing mode, for looking at the glitch waveform.
129 glitchvoltages(0xFFF,0);//Inverted VCC and GND.
133 P5OUT&=~BIT7;//Glitch
134 //asm("nop");//asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
135 asm("nop"); //Not necessary.
137 asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
138 asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
145 debugstr("Unknown glitching verb.");