2 \author Travis Goodspeed
3 \brief Glitching Support for GoodFET20
5 See the TI example MSP430x261x_dac12_01.c for usage of the DAC.
6 This module sends odd and insufficient voltages on P6.6/DAC0
7 in order to bypass security restrictions of target devices.
15 //! Call this before the function to be glitched.
18 WDTCTL = WDTPW + WDTHOLD; // Stop WDT
29 //Set GSEL high to disable glitching.
37 WDTCTL = WDTPW + WDTHOLD; // Stop WDT
38 TACTL = TASSEL1 + TACLR; // SMCLK, clear TAR
39 CCTL0 = CCIE; // CCR0 interrupt enabled
40 CCR0 = glitchcount+0x30; //clock divider
42 _EINT(); // Enable interrupts
46 // Timer A0 interrupt service routine
47 interrupt(TIMERA0_VECTOR) Timer_A (void)
52 TACTL |= MC0;// Stop Timer_A;
60 //! Glitch an application.
61 void glitchapp(u8 app){
62 debugstr("That app is not yet supported.");
66 //! Set glitching voltages.
67 void glitchvoltages(u16 gnd, u16 vcc){
69 //debugstr("Set glitching voltages: GND and VCC");
74 ADC12CTL0 = REF2_5V + REFON; // Internal 2.5V ref on
75 // Delay here for reference to settle.
76 for(i=0;i!=0xFFFF;i++) asm("nop");
77 DAC12_0CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1
78 DAC12_1CTL = DAC12IR + DAC12AMP_5 + DAC12ENC; // Int ref gain 1
79 // 1.0V 0x0666, 2.5V 0x0FFF
80 DAC12_0DAT = vcc; //high;
81 DAC12_1DAT = gnd; //low;
84 //! Set glitching rate.
85 void glitchrate(u16 rate){
89 //! Handles a monitor command.
90 void glitchhandle(unsigned char app,
96 glitchvoltages(cmddataword[0],
101 glitchrate(cmddataword[0]);
105 //FIXME parameters don't work yet.
107 handle(cmddata[0],cmddata[1],0);
110 _DINT();//disable interrupts
111 TACTL=0; //clear dividers
112 TACTL|=TACLR; //clear config
113 TACTL|=TASSEL_SMCLK| //smclk source
114 MC_2; //continuout mode.
116 //perform the function
117 silent++;//Don't want the function to return anything.
118 handle(cmddata[0],cmddata[1],0);
120 cmddataword[0]=TAR; //Return counter.
124 glitchvoltages(0xFFF,0);//Inverted VCC and GND.
128 P5OUT&=~BIT7;//Glitch
129 //asm("nop");//asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
130 asm("nop"); //Not necessary.
132 asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
133 asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");asm("nop");
140 debugstr("Unknown glitching verb.");