HexDef

LAYER 01 Physical, Analog & Silicon

The physical ground truth of all computing systems. Master curriculum spanning semiconductor solid-state physics, lithography, analog power delivery, RF electromagnetics, industrial cyber-physical automation (OT/SCADA), board-level interfaces, and physical side-channel cryptanalysis.

6 Core Domains
31 Technical Modules
100% Physical Ground Truth

1.1 Semiconductor Physics & Silicon Fabrication

4 Modules
1.1.1

Semiconductor Doping & PN Junctions

BS - Core

Definition: Introducing controlled impurities (P-type trivalent or N-type pentavalent atoms) into monocrystalline silicon lattices to establish depletion regions and unidirectional current-conducting diodes.

Security & Hardware Application: The atomic foundation of every discrete transistor; microscopic dopant density fluctuations create silicon process variation utilized in hardware root-of-trust authentication.

1.1.2

MOSFETs, FinFETs & Gate-All-Around (GAAFETs)

BS/MS - Core

Definition: Field-Effect Transistor architectures where gate electric fields modulate source-to-drain channel conduction, transitioning from planar gates to 3D vertical fins and horizontally stacked nanosheets at sub-3nm nodes.

Security & Hardware Application: The fundamental nanoscale switch of microprocessors; susceptible to source-to-drain quantum tunneling leakage, parasitic capacitance, and threshold voltage degradation under physical stress.

1.1.3

CMOS Fabrication & Lithography (EUV)

MS - Advanced

Definition: Complementary Metal-Oxide-Semiconductor manufacturing processes utilizing 13.5nm Extreme Ultraviolet (EUV) photolithography, high-vacuum deposition, and atomic layer etching to pattern billions of transistors on silicon wafers.

Security & Hardware Application: The global strategic supply-chain chokepoint (ASML/TSMC/Intel); targeted by advanced persistent threats for mask-level design theft and foundry-level hardware supply-chain interdiction.

1.1.4

Silicon Aging, Electromigration & Wearout

MS/PhD - Frontier

Definition: Long-term physical degradation mechanisms where momentum transfer from high-density electron flow physically displaces metallic atoms in on-chip interconnect wires, alongside Hot Carrier Injection (HCI) and Time-Dependent Dielectric Breakdown (TDDB).

Security & Hardware Application: Intentional over-volting and thermal-cycling attacks can artificially accelerate electromigration wearout to permanently brick security coprocessors or force persistent latch-up faults.

1.2 Analog Electronics, Signals & Power Systems

4 Modules
1.2.1

Analog-to-Digital (ADC) & Digital-to-Analog (DAC) Converters

BS - Core

Definition: Mixed-signal quantization interfaces that discretize continuous real-world analog physical voltages into binary values via Successive Approximation (SAR) or Delta-Sigma architectures governed by the Nyquist-Shannon theorem.

Security & Hardware Application: The bridge between physical sensor instrumentation and CPU telemetry; feeding high-frequency analog bias or intentional out-of-band signals can induce aliasing and deceive ADC inputs prior to software filtering.

1.2.2

Power Delivery Networks (PDNs) & Voltage Regulators (PMICs)

BS/MS - Core

Definition: Multi-stage power distribution circuitry (decoupling capacitors, bulk inductors, and Power Management ICs) engineered to supply low-impedance, ripple-free direct-current voltage across dynamic processor workload transients.

Security & Hardware Application: Primary target for hardware voltage glitching; using low-impedance MOSFET shunts (crowbar circuits) to short the VDD rail for nanoseconds forces the CPU to skip instruction execution cycles.

1.2.3

Analog Filtering & Operational Amplifiers (Op-Amps)

BS - Core

Definition: High-gain differential voltage amplifier circuits paired with active RC networks to isolate desired frequency bands and reject common-mode electromagnetic noise on analog sensor lines.

Security & Hardware Application: Poorly shielded Op-Amp front-ends can be driven into rail saturation or induced oscillation via resonant acoustic waves (ultrasonic MEMS jamming) or focused microwave RF radiation.

1.2.4

Clock Generation, Crystal Oscillators & PLLs

BS/MS - Core

Definition: Resonant piezoelectric quartz crystals paired with on-chip Phase-Locked Loops (PLLs) to synthesize stable, high-frequency square-wave master clock signals distributed across low-skew clock trees.

Security & Hardware Application: Clock-glitching exploits inject double clock edges or momentary phase shifts to cause setup-time violations in CPU flip-flops, bypassing cryptographic validation branches.

1.3 Radio Frequency (RF), Wireless Physics & Telecommunications

5 Modules
1.3.1

Software-Defined Radio (SDR)

BS - Core

Definition: Radio architectures where analog modulation, mixing, and demodulation are performed in software code via high-speed In-phase/Quadrature (I/Q) digital signal processing on wideband transceivers (HackRF, USRP, RTL-SDR).

Security & Hardware Application: Enables arbitrary transmission and interception across 1MHz to 6GHz; fundamental for auditing custom proprietary wireless protocols and sniffing unencrypted telemetry.

1.3.2

RF Replay Attacks & Signal Jamming

BS - Core

Definition: Capturing raw RF emissions over the air to replay them without cryptographic modification, or broadcasting high-power destructive interference to degrade receiver Signal-to-Noise Ratios (SNR) below demodulation thresholds.

Security & Hardware Application: Bypassing fixed-code gate systems, exploiting rolling-code keyless entry systems via simultaneous jamming and selective capture (Rolljam), and denying drone C2 wireless links.

1.3.3

Short-Range Wireless Standards (RFID, NFC, Zigbee, BLE)

BS - Core

Definition: Near-field magnetic induction and low-power 2.4GHz / sub-GHz physical layer protocols operating over constrained distances for access tokens, sensory telemetry, and mesh networking.

Security & Hardware Application: Cloning unauthenticated 125kHz badge IDs (Proxmark), eavesdropping on unencrypted BLE advertising packets, and injecting unauthorized Zigbee home automation commands.

1.3.4

GPS / GNSS Spoofing & Meaconing

BS/MS - Core

Definition: Transmitting synthesized or delayed satellite RF signals with slightly higher power than legitimate space-vehicle signals to force receivers into calculating inaccurate pseudo-ranges and timestamps.

Security & Hardware Application: Hijacking autonomous marine/aerial navigation systems, inducing false geographic boundary triggers, and desynchronizing financial networks that rely on GNSS Stratum-1 time servers.

1.3.5

Cellular Layer 1 & IMSI Catchers (Stingrays)

MS - Advanced

Definition: Rogue Base Transceiver Stations (BTS) operating on licensed cellular bands that broadcast unauthenticated control-channel beacons, forcing mobile devices to connect and disclose hardware identities.

Security & Hardware Application: Physical geolocation tracking via International Mobile Subscriber Identity (IMSI) capture, cryptographic cipher-downgrade attacks (forcing 2G A5/0 null encryption), and over-the-air call/SMS interception.

1.4 Cyber-Physical Systems (CPS) & Industrial Automation (OT/SCADA)

5 Modules
1.4.1

Programmable Logic Controllers (PLCs) & RTUs

BS - Core

Definition: Industrial embedded microcomputers executing deterministic scan cycles (Input → Logic → Output) to read continuous 4–20mA sensory current loops and drive high-voltage relays, motors, and hydraulic actuators.

Security & Hardware Application: The primary physical execution target in critical infrastructure attacks (Stuxnet, Industroyer); rewriting PLC ladder logic directly forces kinetic physical damage to turbines and centrifuges.

1.4.2

SCADA & Human-Machine Interfaces (HMIs)

BS - Core

Definition: Centralized supervisory control stations and graphical operator panels that poll remote telemetry tags and display operational metrics to control-room engineers.

Security & Hardware Application: Adversaries exploit HMI software to present falsified "normal" process measurements to human operators while secretly driving physical processes beyond safe operating thresholds in the background.

1.4.3

The Purdue Model (ISA-99 / IEC 62443 Segmentation)

BS/MS - Architecture

Definition: A hierarchical architectural framework segmenting industrial automation into strict defensive tiers from Level 0 (physical sensors/actuators) through Level 3 (site operations) to Level 5 (enterprise IT) via Industrial DMZs (IDMZs).

Security & Hardware Application: Designing unidirectional data diodes and firewall conduits to ensure a compromised corporate network (Level 4/5) cannot pivot into safety-critical control networks (Level 1/2).

1.4.4

Legacy Industrial & Fieldbus Protocols (Modbus, DNP3, CAN Bus)

BS - Core

Definition: Unauthenticated, cleartext serial and fieldbus communication standards designed in the 1970s–1980s for deterministic, low-overhead communication across industrial plant floors and automotive wiring harnesses.

Security & Hardware Application: Lack of cryptographic integrity allows attackers who gain physical access to copper wire buses to perform instant command injection, register overwrites, and CAN bus arbitration hijacking.

1.4.5

Safety Instrumented Systems (SIS & Emergency Shutdown)

MS - Advanced

Definition: Dedicated, physically segregated control loops built with Triple Modular Redundancy (TMR) engineered to execute emergency shutdowns before physical overpressure, explosion, or toxic release occurs.

Security & Hardware Application: The highest-consequence target in cyber warfare (e.g., Triton/Trisis malware); designed to disable physical emergency fail-safes so secondary destructive attacks succeed without automated interruption.

1.5 Board-Level Hardware & Embedded Interfaces

5 Modules
1.5.1

Hardware Debug Interfaces (UART, JTAG, SWD)

BS - Core

Definition: Standardized physical test points and boundary-scan protocols (IEEE 1149.1 JTAG, ARM Serial Wire Debug) engineered for post-silicon validation, in-circuit programming, and hardware-level emulation.

Security & Hardware Application: Solder-probing unprotected debug pins allows direct extraction of CPU registers, halt-state control, password verification bypasses, and root shell access on embedded Linux devices.

1.5.2

Serial Bus Sniffing (SPI, I2C, I3C)

BS - Core

Definition: Low-pin-count synchronous chip-to-chip serial communications protocols connecting microcontrollers to peripheral sensors, crypto co-processors, and external flash memory.

Security & Hardware Application: Attaching logic analyzer probes directly onto PCB copper traces enables passive capture of cryptographic keys, sensor readings, and raw bootloader images transmitted during power-on sequencing.

1.5.3

Non-Volatile Memory Extraction (EEPROM / Flash Dumping)

BS - Core

Definition: In-circuit or desoldered extraction of persistent storage ICs (SPI NOR flash, parallel NAND with Out-Of-Band spare areas, eMMC, and UFS chips) using hardware programmers.

Security & Hardware Application: Dumping unencrypted firmware binaries directly from hardware for static reverse engineering, hardcoded credential recovery, and binary vulnerability discovery.

1.5.4

Logic Analyzers & Digital Storage Oscilloscopes

BS - Core

Definition: Essential electrical bench instruments that sample multi-channel digital logic states and analog voltage waveforms at gigasample-per-second rates with customizable trigger conditions.

Security & Hardware Application: Reverse engineering unknown proprietary pinouts, measuring glitch timing offsets with sub-nanosecond precision, and visualizing protocol timing violations.

1.5.5

Hardware Root-of-Trust, OTP eFuses & Boot ROM

BS/MS - Core

Definition: Immutable on-die silicon Mask ROM containing factory initial boot code, paired with microscopic One-Time Programmable (OTP) physical electronic fuses that store public key hashes and security state flags.

Security & Hardware Application: Anchors the cryptographic chain of trust for secure boot; prevents firmware rollback attacks and locks JTAG debug access once production devices leave the factory floor.

1.6 Silicon-Level Security & Physical Side-Channels

8 Modules
1.6.1

Differential & Correlation Power Analysis (DPA / CPA)

MS - Advanced

Definition: Statistical cryptanalysis measuring instantaneous power consumption across thousands of cryptographic operations, correlating micro-volt fluctuations to Hamming weight and Hamming distance leakage models.

Security & Hardware Application: Recovering 128-bit and 256-bit AES secret keys from smart cards and secure elements without attacking the mathematical algorithms or breaking mathematical encryption.

1.6.2

Electromagnetic (EM) Side-Channel Analysis

MS - Advanced

Definition: Capturing spatial and temporal electromagnetic emissions radiating from on-chip ALU data paths and memory buses using near-field magnetic loops and low-noise preamplifiers.

Security & Hardware Application: Non-invasive cryptographic key extraction and instruction-flow reconstruction through chip encapsulation without requiring direct electrical contact with power rails.

1.6.3

Voltage & Clock Fault Injection (Glitching)

MS - Advanced

Definition: Intentionally disturbing CPU operating parameters for precise nanosecond windows to induce single-cycle computational bit flips in execution registers or program counters.

Security & Hardware Application: Forcing instruction decoders to corrupt branch evaluations (flipping BEQ to NOP) to bypass password verification and signature validation routines.

1.6.4

Laser Fault Injection (LFI) & Optical Probing

PhD - Frontier

Definition: Focusing pulsed 1064nm infrared laser beams through the backside silicon substrate of a thinned chip to induce localized photoelectric carrier generation in specific logic transistors.

Security & Hardware Application: Microscopic, targeted single-bit flips in protected SRAM registers and hardware state machines; utilized by national labs to extract hardware crypto keys and defeat physical shields.

1.6.5

Physically Unclonable Functions (PUFs)

MS - Advanced

Definition: Exploiting unrepeatable atomic manufacturing tolerances (SRAM uninitialized state bias, ring oscillator gate delay variations) to generate unique, reproducible digital keys from silicon physics.

Security & Hardware Application: Generating volatile cryptographic keys on demand that vanish instantly upon power-off, neutralizing physical memory extraction and chip cloning attacks.

1.6.6

TEMPEST & Van Eck Phreaking

MS/PhD - Frontier

Definition: Reconstructing readable video displays, keyboard strokes, or network traffic by capturing compromising unintentional electromagnetic radiation leaking through cables, monitors, and chassis.

Security & Hardware Application: Remote physical surveillance across walls and open space; requires military-standard TEMPEST zoning (MIL-STD-461), optical isolation, and Faraday enclosures.

1.6.7

Hardware Trojans & ASIC Supply-Chain Tampering

PhD - Frontier

Definition: Malicious modifications introduced into integrated circuit layout masks or dopant patterns during third-party fabrication that remain dormant until triggered by rare digital or physical conditions.

Security & Hardware Application: Stealth silicon backdoors capable of disabling hardware cryptographic security modules, leaking keys over side-channels, or inducing catastrophic hardware latch-ups on demand.

1.6.8

IC Decapsulation, Fuming Nitric Acid & Microprobing

PhD - Frontier

Definition: Chemical dissolution of plastic epoxy packaging using fuming nitric and sulfuric acids to expose raw silicon dies, followed by placing sub-micron tungsten needles directly on internal bus wires under a Scanning Electron Microscope (SEM).

Security & Hardware Application: Direct non-software bus sniffing of on-chip unencrypted communications between CPU cores and internal cryptographic memory; defeating physical active security mesh shields.

← Back to 9-Layer Systems Architecture HEXDEF SYSTEMS ARCHITECTURE TAXONOMY