Open Source Hardware Hardware Security Jul 02, 2026 1 min de lecture

ChipShover: The Secret Weapon for IC Fault Injection Research

B
Bright Coding
Auteur
ChipShover: The Secret Weapon for IC Fault Injection Research
Advertisement

ChipShover: The Secret Weapon for IC Fault Injection Research

Stop wrestling with $50,000 microscope stages that drain your grant money. There's a hidden movement happening in hardware security labs across the globe, and it involves a surprisingly affordable XYZ positioning system that's making Electromagnetic Fault Injection (EMFI) and side-channel analysis accessible to researchers who refuse to pay inflated prices for precision they can build themselves.

What if I told you that a positioning table capable of 156.25 nanometer step resolution—yes, you read that correctly, sub-micron precision—could sit on your bench for roughly the cost of a high-end laptop? Not $30,000. Not $15,000. We're talking about a system that bridges the impossible gap between flimsy 3D printers and overpriced commercial microscope stages.

The painful reality every hardware security researcher faces? You need insane precision to position EM probes, fault injection coils, and laser systems over microscopic IC features. One wrong move, one vibration, one positioning error of a few microns, and your carefully crafted fault injection campaign collapses into noise. Commercial solutions extort your budget. DIY alternatives wobble like a cheap IKEA table. You're stuck between bankruptcy and inaccuracy.

Enter ChipShover. Born from NewAE Technology—the same minds behind the legendary ChipWhisperer and ChipSHOUTER—this open-source XYZ table with its silky Python↗ Bright Coding Blog interface is quietly becoming the backbone of serious IC analysis workflows. And here's the kicker: it's designed by people who actually do fault injection daily, not by committee-driven corporations padding their margins.

Ready to see why top researchers are abandoning traditional positioning systems? Let's dive deep into what makes ChipShover the most disruptive tool in hardware security this decade.


What Is ChipShover?

ChipShover is an open-source XYZ positioning table and controller ecosystem specifically engineered for close-proximity IC analysis. It combines physical precision mechanics, customizable interposers for tool mounting, a Marlin-based open-source controller, and a dead-simple Python API that turns complex spatial sweeps into a few lines of readable code.

NewAE Technology Inc.—the Canadian company founded by Colin O'Flynn that revolutionized side-channel power analysis with the ChipWhisperer—created ChipShover to solve a problem they themselves encountered daily. When you're performing EMFI or dragging EM probes across chip surfaces, you need repeatable, programmatic positioning that doesn't require a second mortgage. The ChipShover repository houses everything: mechanical designs, controller firmware, Python libraries, and extensive documentation.

Why is it trending now? Three converging forces: the explosion of hardware security research, the democratization of fault injection techniques previously locked behind proprietary walls, and a global supply chain that made researchers rethink dependencies on single-vendor solutions. ChipShover's open-source DNA means you're never held hostage. When a component goes obsolete, the community adapts. When you need a custom interposer for your weird probe, you print it.

The system's philosophy is radical simplicity with uncompromised capability. It occupies a deliberate sweet spot—more rigid and precise than repurposed 3D printers, vastly more affordable and hackable than commercial microscope stages. NewAE sells a complete kit called the PS1 (Positioning System 1) for those wanting turnkey operation, yet every element remains open enough for hardcore DIY builders to source their own parts and save significantly.


Key Features That Separate ChipShover from the Pack

Sub-Micron Precision Without Sub-Micron Pricing. The medium-resolution stage achieves a staggering 156.25 nm step size with approximately 3 µm backlash and general error. That's roughly one-sixth the wavelength of blue light. For context, many commercial stages costing 10-20× more advertise similar specifications. The low-resolution variant still delivers 781.25 nm steps—entirely adequate for numerous EMFI applications where you're targeting bond wires or larger power distribution networks.

Dual-Variant Architecture. ChipShover doesn't force a one-size-fits-all approach. The medium-resolution stage uses a solid machined aluminum frame with motorized microscope stages—premium mechanical foundations that justify the PS1 kit price. The low-resolution stage leverages widely available CNC frames from AliExpress (~$500), dramatically lowering entry barriers. Both share the same controller ecosystem and Python API.

Open-Source Controller Firmware. The controller runs a customized Marlin 2 build on Arduino DUE hardware (Microchip SAM3X). Marlin's massive 3D printer community means firmware expertise is everywhere. NewAE's modifications add ChipShover-specific capabilities while preserving the battle-tested motion control algorithms that drive millions of printers reliably.

ChipShover-One: Purpose-Built Controller Board. NewAE designed their own controller with features absent from generic boards: 3 endstop inputs per axis (2 mechanical endstops plus 1 higher-resolution home sensor), swappable driver boards for different motor requirements, ~2.4A drive current for demanding stages, RS485 + I2C + GPIO extensions per axis, a physical E-Stop that literally cuts motor power, and a color LCD interface. The beta unit runs $1300 enclosed and tested, with a ~$350 lower-cost version planned.

50×50mm Standard Tool Mounting. The interposer system accepts ChipSHOUTER EMFI tools, pen-style EM probes, and anything you design. The bolt pattern is intentionally universal—3D print adapters, machine aluminum holders, or laser-cut acrylic fixtures. Your imagination, not vendor lock-in, defines the tooling.

Zero-Friction Python Integration. The API abstracts G-code generation, serial communication, coordinate transformations, and safety interlocks. Jupyter notebook users can iterate positioning algorithms interactively. Automation scripts integrate cleanly into existing analysis pipelines.


Real-World Use Cases Where ChipShover Dominates

1. Electromagnetic Fault Injection (EMFI) Campaigns

EMFI requires positioning a high-voltage pulse coil or antenna with surgical precision over IC targets. Different chip regions exhibit wildly different fault susceptibilities—some near the CPU core, others near voltage regulators. ChipShover enables automated spatial fault sensitivity mapping: sweep the coil across the die surface, inject at each point, classify fault responses. Without programmatic positioning, this is weeks of mind-numbing manual work. With ChipShover, it's an overnight script.

2. Side-Channel EM Probe Localization

Electromagnetic side-channel analysis depends on finding the "hot spots" where cryptographic operations leak information. A pen-style EM probe must hover nanometers above the die surface, often following complex raster patterns. ChipShover's Z-plunge capability—touching down at each point rather than dragging—protects delicate probe tips while maintaining consistent coupling. The Python sweep generators produce optimal coverage paths automatically.

3. Laser Fault Injection (LFI) Beam Alignment

Laser systems demand even stricter positioning than EM tools. The beam must align with specific transistor geometries, often through backside silicon thinning. ChipShover's machined aluminum frame provides the mechanical stability that laser setups crave—no vibration-induced beam wander, no thermal drift from flimsy frames. Multiple labs have adapted ChipShover stages for infrared LFI by designing custom interposers.

4. Die Surface Reconstruction and Documentation

Before attacking a chip, you need to know its physical layout. ChipShover can carry a microscope camera or contact profilometer in automated raster patterns, building 3D surface maps or high-resolution image mosaics. The sub-micron repeatability ensures tile alignment without feature-based registration struggles. Researchers have built complete die atlases this way, correlating optical features with extracted netlists.


Step-by-Step Installation & Setup Guide

Hardware Assembly

For the PS1 Kit (Recommended):

  1. Unpack the machined aluminum frame, motorized microscope stages, controller, power supply, and accessories
  2. Bolt stages to frame using included hardware—torque to 5 N·m, check squareness with machinist's square
  3. Mount your chosen interposer (ChipSHOUTER holder or EM probe holder) to the Z-axis carriage
  4. Connect motor cables to controller: X, Y, Z steppers to labeled headers
  5. Connect endstops: wire the two mechanical endstops and optional high-resolution home sensor per axis
  6. Connect power supply (24V DC, included) to controller and mains

For DIY Low-Resolution Build:

  1. Source CNC frame from AliExpress (search "3040 CNC frame" or similar, verify 1605 ball screws on Z-axis minimum)
  2. Purchase stepper motors separately (NEMA 23 recommended for rigidity)
  3. Source controller: either ChipShover-One or Archim2 (see below)
  4. Print interposers from repository STL files or machine from provided drawings

Controller Firmware Installation

ChipShover-One or Archim2 with Marlin 2:

# Clone the customized Marlin firmware
git clone https://github.com/newaetech/ChipSHOVER-Marlin.git
cd ChipSHOVER-Marlin

# Install PlatformIO (if not present)
pip install platformio

# Build for ChipShover-One board
pio run -e chipshover_one

# Or build for Archim2
pio run -e archim2

# Upload firmware via USB (board in bootloader mode)
pio run -e chipshover_one --target upload

Python Interface Installation

# Create virtual environment (recommended)
python -m venv chipshover-env
source chipshover-env/bin/activate  # Linux/Mac
# chipshover-env\Scripts\activate  # Windows

# Install from PyPI (when published) or repository
pip install chipshover
# OR for development version:
pip install git+https://github.com/newaetech/ChipShover.git

# Verify installation
python -c "from chipshover import ChipShover; print('Ready for precision positioning')"

Serial Connection Setup

Identify your controller's serial port:

  • Windows: Check Device Manager for "USB Serial Device (COMx)"—typically COM3 or higher
  • Linux: ls /dev/ttyACM* or ls /dev/ttyUSB*—usually /dev/ttyACM0
  • macOS: ls /dev/tty.usbmodem* or ls /dev/tty.usbserial*

Test connectivity before mounting delicate probes:

from chipshover import ChipShover

# Replace 'com3' with your actual port
shv = ChipShover('com3')  # Windows example
# shv = ChipShover('/dev/ttyACM0')  # Linux example

print(f"Firmware version: {shv.version}")
print(f"Current position: {shv.position}")

Critical Calibration Steps

  1. Home all axes: shv.home()—this establishes machine coordinate origin
  2. Verify step/mm settings: Move known distance, measure with dial indicator
  3. Backlash compensation: Measure with indicator, apply Marlin backlash correction if needed
  4. Z-probe offset: For touch-down applications, calibrate trigger point to actual surface contact

REAL Code Examples from the Repository

The ChipShover repository contains the definitive Python interface examples. Here are the actual usage patterns, explained in depth.

Advertisement

Example 1: Basic XY Surface Sweep with Z-Plunge

This is the canonical ChipShover pattern—sweeping a rectangular area while touching down at each point. Critical for EM probes that cannot drag across surfaces without damage.

from chipshover import ChipShover

# Initialize connection to controller on COM3
# The ChipShover class handles all G-code generation internally
shv = ChipShover('com3')

# Home all axes to establish machine origin
# This is MANDATORY before any positioning operations
# Uses configured endstops: mechanical first, then high-res home if available
shv.home()

# Sweep from (10.0, 10.0) to (12.5, 12.5) in 0.05mm steps
# z_plunge=1.5 means: at each (x,y), move Z down 1.5mm from current height,
# then return to original Z before moving to next point
# This creates a "touch and lift" pattern perfect for delicate probes
for x, y in shv.sweep_x_y(10, 12.5, 10, 12.5, step=0.05, z_plunge=1.5):
    # x, y are float values in millimeters (machine coordinates)
    # The generator yields ONLY when physically at position and Z returned
    # Safe to perform your analysis operation here
    print("At %f, %f" % (x, y))
    
    # YOUR FAULT INJECTION OR MEASUREMENT CODE HERE
    # Example: trigger_chipshouter_pulse()
    # Example: capture_power_trace()
    # Example: read_glitch_response()

# After loop: Z is at safe height, position at last point
# Explicit cleanup recommended for long-running scripts
shv.close()

What's happening under the hood? The sweep_x_y generator constructs optimized G-code paths, accounting for acceleration limits, jerk settings, and Z-clearance heights. It automatically handles the "snake" vs. "raster" path decision based on efficiency. The z_plunge parameter triggers a relative Z move: descend, dwell (configurable), ascend. All motion waits for controller acknowledgment—no premature triggering.

Example 2: Custom Coordinate System and Absolute Positioning

For applications requiring workpiece-relative coordinates rather than machine coordinates:

from chipshover import ChipShover

shv = ChipShover('com3')
shv.home()

# Define a work offset: corner of your IC package
# G54-style coordinate systems would be set via Marlin configuration
# Here we demonstrate manual offset application
die_corner_x, die_corner_y = 15.23, 8.67  # Measured with camera alignment

# Move to specific die feature in absolute coordinates
# Example: AES S-box located at (2.5, 3.1) mm from package corner
target_x = die_corner_x + 2.5
target_y = die_corner_y + 3.1

# Absolute move with explicit feedrate (mm/min)
shv.move_absolute(x=target_x, y=target_y, feedrate=1000)

# Fine positioning at lower speed for final approach
shv.move_absolute(x=target_x, y=target_y, feedrate=100)

# Now perform your sensitive operation at exact location
print(f"Positioned at die-relative ({target_x - die_corner_x}, {target_y - die_corner_y})")

shv.close()

Critical insight: The two-stage move (fast then slow) minimizes positioning time while maximizing final accuracy. High feedrates induce inertial overshoot; the final creep approach eliminates this. This pattern is essential when targeting specific logic gates or memory arrays visible in your die photograph.

Example 3: Integration with Jupyter for Interactive Analysis

The Python interface shines in notebook environments where you iteratively refine attack positions:

from chipshover import ChipShover
import matplotlib.pyplot as plt
import numpy as np

# Persistent connection across multiple cells
shv = ChipShover('com3')

# Cell 1: Setup
shv.home()

# Cell 2: Define search grid around suspected vulnerable region
# Based on previous power analysis or optical inspection
center_x, center_y = 20.0, 15.0
half_span = 0.5  # 1mm total search area
step = 0.02      # 20 micron resolution

# Cell 3: Execute grid and collect fault responses
responses = []
positions = []

for x, y in shv.sweep_x_y(
    center_x - half_span, center_x + half_span,
    center_y - half_span, center_y + half_span,
    step=step, z_plunge=0.8
):
    # Your fault injection trigger here
    # response = inject_and_classify()
    response = np.random.choice([0, 1, 2])  # Placeholder: no fault, reset, successful glitch
    
    responses.append(response)
    positions.append((x, y))
    
    # Real-time visualization update possible here
    print(f"({x:.3f}, {y:.3f}): response {response}")

# Cell 4: Visualize fault sensitivity map
xs, ys = zip(*positions)
plt.figure(figsize=(8, 6))
scatter = plt.scatter(xs, ys, c=responses, cmap='RdYlGn_r', s=50)
plt.colorbar(scatter, label='Response Type')
plt.xlabel('X Position (mm)')
plt.ylabel('Y Position (mm)')
plt.title('EMFI Fault Sensitivity Map')
plt.gca().set_aspect('equal')
plt.show()

# Cell 5: Return to safe position, keep connection open for next experiment
shv.move_absolute(z=10, feedrate=3000)  # Clear height

Why this matters: The generator pattern integrates seamlessly with Python's data science ecosystem. You're not fighting a C API or parsing serial strings—you're iterating over positions like any other data structure. The z_plunge safety, combined with explicit move commands, prevents expensive probe crashes during interactive exploration.


Advanced Usage & Best Practices

Vibration Isolation Is Non-Negotiable. Even the rigid PS1 frame suffers if your bench wobbles. Place ChipShover on a granite surface plate or optical breadboard. Use Sorbothane feet for high-frequency damping. If you're doing laser work, consider active pneumatic isolation.

Thermal Management for Extended Sweeps. Stepper motors heat during long operations. The medium-resolution stage's microscope stages handle this well, but DIY builds may see thermal drift. Add pauses in your sweep loops, monitor motor temperatures, or reduce current via driver potentiometer adjustment.

Custom G-Code Injection. For operations the Python API doesn't expose, access the raw serial interface:

# Send arbitrary Marlin G-code
shv.send_gcode("M906 X1200 Y1200")  # Set motor currents
response = shv.send_gcode("M114")    # Query position

Multi-Tool Workflows. Design interposers with quick-change mechanisms. A magnetic kinematic mount, adapted from 3D printer toolchangers, lets you swap from EMFI coil to probe in seconds without losing registration.

Networked Controllers. The ChipShover-One's optional Ethernet enables remote labs. Combine with JupyterHub for team-wide access to a single precision stage—critical for distributed research groups.


Comparison with Alternatives

Feature ChipShover (PS1) Repurposed 3D Printer Commercial Microscope Stage Custom CNC Build
Resolution 156.25 nm ~5-10 µm (typical) 10-100 nm Variable
Rigidity Excellent (machined Al) Poor (extrusion frame) Excellent Variable
Python API Native, clean None / DIY serial Proprietary / $$ None / DIY
EMFI Ready Yes (interposers included) Requires major mod Requires adapter Requires design
Cost (complete) ~$3,000-5,000 (kit) ~$300-800 $15,000-50,000+ $1,000-3,000
Open Source Firmware + partial HW Varies No Varies
Community Growing (NewAE ecosystem) Massive (3D printing) Limited Fragmented
Support Commercial + community Community only Commercial only None

The verdict? ChipShover dominates the middle ground. It's 10× more capable than hacked 3D printers for serious IC work, yet 5-10× cheaper than commercial stages with comparable precision. The Python API and NewAE ecosystem integration seal the decision for anyone doing ChipWhisperer/ChipSHOUTER workflows.


Frequently Asked Questions

Is ChipShover suitable for beginners in hardware security?

Yes, with caveats. The PS1 kit is genuinely turnkey—NewAE provides support, documentation, and a community familiar with newcomers. However, EMFI and side-channel analysis themselves have steep learning curves. ChipShover removes the positioning barrier, not the analysis barrier.

Can I use ChipShover for non-security applications?

Absolutely. Any application needing precise XYZ positioning benefits: microscopy automation, probe station control, laser marking alignment, even artistic applications. The 50×50mm tool mount accepts custom adapters.

What's the actual positioning repeatability?

~3 µm for the medium-resolution stage, dominated by mechanical backlash in the microscope stage drivetrain. The 156.25 nm step size represents resolution (smallest addressable move), not accuracy. For EMFI, this is excellent; for transistor-level targeting, consider closed-loop encoders.

Do I need the ChipShover-One controller, or will Archim2 work?

Archim2 works for many applications, with limitations: ~1 µm effective resolution, mechanical endstop homing only, lower drive current. If budget-constrained, start with Archim2; upgrade to ChipShover-One when you hit its limits.

How does ChipShover integrate with ChipWhisperer or ChipSHOUTER?

Seamlessly. The Python API runs in the same environment as ChipWhisperer's software. Trigger ChipSHOUTER pulses at each sweep position, capture ChipWhisperer traces, correlate results—all in one script.

Is the hardware fully open source?

The firmware is fully open (Marlin 2 fork). The ChipShover-One controller schematics are available but not yet full OSHW; NewAE indicates this will evolve. Mechanical designs and interposer files are open. The PS1 kit's machined frame is commercial.

What about international shipping and voltage?

NewAE ships globally. The PS1 power supply accepts 100-240V AC; specify regional plug when ordering. DIY builders source locally-compatible 24V supplies.


Conclusion: Why ChipShover Belongs in Your Lab

ChipShover isn't merely a cheaper alternative to commercial positioning stages—it's a fundamentally different approach to precision motion in hardware security. By embracing open-source firmware, modular hardware, and Python-native control, NewAE has created a system that improves with community contribution rather than deprecating with vendor whims.

The sub-micron resolution, purpose-built controller features, and seamless integration with the broader NewAE ecosystem make ChipShover the logical choice for researchers serious about EMFI, side-channel analysis, and IC characterization. Whether you invest in the turnkey PS1 kit or embark on a budget-conscious DIY build, you're joining a growing movement of practitioners who refuse to let positioning limitations constrain their security research.

The hardware security landscape rewards precision and repeatability. ChipShover delivers both without extracting a ransom. Your next fault injection campaign, your next side-channel measurement, your next silicon-level discovery—all start with getting your probe exactly where it needs to be.

Ready to build? Head to the official ChipShover repository for complete documentation, mechanical files, firmware source, and the Python package. Star the repo, join the discussions, and start positioning with purpose. The chips aren't going to fault themselves.


ChipSHOUTER and ChipShover are registered trademarks of NewAE Technology Inc. This article is independent analysis based on publicly available repository information.

Advertisement
Advertisement

Commentaires 0

Aucun commentaire pour l'instant. Soyez le premier à réagir !

Laisser un commentaire

Advertisement