Mechanism · Hardware-enabled guarantees (flexHEG) and guarantee processors
Firmware-only retrofits rely on Secure Boot, which fault injection can bypass
On this page
SignificantTheoretical argumentOpen
Part II notes that the most common attack on Secure Boot replaces the firmware and applies a voltage glitch while the signature is being checked. It also notes that sophisticated actors may use microprobing or laser voltage probing to read key registers 2.
Sources: [2]