Résumé
Clock glitch attacks are among the least expensive fault injection methods that target integrated circuits (ICs). However, the widespread use of phase-locked loops (PLLs) has rendered traditional clock glitch attacks ineffective in most circuits. This article demonstrates that over-clocking can be obtained by injecting faults into the PLL itself, enabling the replication of clock glitch effects. This method is feasible even when the PLL reference clock is internally generated. The phase-frequency detector (PFD) is directly targeted, which makes this attack broadly applicable. Its theoretical fault model is derived and used to build a stochastic analysis of the impact of faults on the output frequency of the PLL. Finally, laser fault injection on a real PLL IC demonstrates the practical feasibility of this method. The PLL output frequency is accurately modified with relative variations ranging from 0% to 178%. This work provides a generic fault injection methodology that enables the replication of clock glitch effects on circuits previously considered immune to them. This work impacts the security of most ICs, and provides a better understanding of PLLs that could be used in the field of electromagnetic compatibility.