2 \author Travis Goodspeed
3 \brief Glitching Support for GoodFET20
5 See the TI example MSP430x261x_dac12_01.c for usage of the DAC.
6 This module sends odd and insufficient voltages on P6.6/DAC0
7 in order to bypass security restrictions of target devices.
15 //! Call this before the function to be glitched.
18 //Don't forget to call glitchvoltages().
21 TACTL=0; //Clear dividers.
22 TACTL|=TACLR; //Clear TimerA Config
24 TASSEL_SMCLK | //SMCLK source,
25 MC_1 | //Count up to CCR0
26 TAIE; //Enable Interrupt
27 CCTL0 = CCIE; // CCR0 interrupt enabled
30 //Enable general interrupts, just in case.
38 //Set GSEL high to disable glitching.
46 WDTCTL = WDTPW + WDTHOLD; // Stop WDT
47 TACTL = TASSEL1 + TACLR; // SMCLK, clear TAR
48 CCTL0 = CCIE; // CCR0 interrupt enabled
50 TACTL |= MC1; // Start Timer_A in continuous mode
51 _EINT(); // Enable interrupts
55 // Timer A0 interrupt service routine
56 interrupt(TIMERA0_VECTOR) Timer_A (void)
62 TACTL |= MC0; // Stop Timer_A;
68 u16 glitchH=0xfff, glitchL=0xfff,
69 glitchstate=2, glitchcount=0;
71 //! Glitch an application.
72 void glitchapp(u8 app){
73 debugstr("That app is not yet supported.");
77 //! Set glitching voltages.
78 void glitchvoltages(u16 gnd, u16 vcc){
80 //debugstr("Set glitching voltages.");
83 ADC12CTL0 = REF2_5V + REFON; // Internal 2.5V ref on
84 // Delay here for reference to settle.
85 for(i=0;i!=0xFFFF;i++) asm("nop");
86 DAC12_0CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1
87 DAC12_1CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1
88 // 1.0V 0x0666, 2.5V 0x0FFF
89 DAC12_0DAT = vcc; //high;
90 DAC12_1DAT = gnd; //low;
93 //! Set glitching rate.
94 void glitchrate(u16 rate){
98 //! Handles a monitor command.
99 void glitchhandle(unsigned char app,
104 glitchvoltages(cmddataword[0],
109 glitchrate(cmddataword[0]);
113 //FIXME parameters don't work yet.
115 handle(cmddata[0],cmddata[1],0);
118 _DINT();//disable interrupts
119 TACTL=0; //clear dividers
120 TACTL|=TACLR; //clear config
121 TACTL|=TASSEL_SMCLK| //smclk source
122 MC_2; //continuout mode.
124 //perform the function
125 silent++;//Don't want the function to return anything.
126 handle(cmddata[0],cmddata[1],0);
128 cmddataword[0]=TAR; //Return counter.
132 glitchvoltages(0xFFF,0);//Inverted VCC and GND.
136 P5OUT&=~BIT7;//Glitch
137 //asm("nop");//asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
138 asm("nop"); //Not necessary.
140 asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
141 asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
148 debugstr("Unknown glitching verb.");