A Framework-Driven Evaluation and Survey of MCU Fault Injection Resilience for IoT
Seniushin I. Glazyrina N. Atanbayev Y. Bairamov K. Satiyeva Y. Nurman O. Altaibek M.
November 2025Multidisciplinary Digital Publishing Institute (MDPI)
Applied Sciences (Switzerland)
2025#15Issue 22
With the increasing prevalence of Internet of Things (IoT) devices in areas like authentication, data protection, and access control, general purpose microcontrollers (MCUs) have become the primary platform for security-critical apps. However, the expense of these attacks has decreased significantly in recent years, making them a viable threat to MCU-based devices. We present a framework-driven perspective with a comparative survey of MCU fault injection resilience for IoT. The survey supports—and is organized around—the procedural evaluation framework we introduce. We discuss the basic requirements for security first, and then categorize the common types of hardware intrusion, including side-channel attacks, fault injection attacks, and invasive methods. We synthesize reported security technologies employed by MCU vendors, such as TrustZone/TEE, Physical Unclonable Functions (PUF), secure boot, flash encryption, secure debugging, and tamper detection, in the context of FIA scenarios. A comparison of representative MCUs—STM32U585, NXP LPC55S69, Nordic nRF54L15, Espressif ESP32-C6, and Renesas RA8M1—highlights cost–security trade-offs relevant to token-class deployments. We position this work as a framework/perspective: an evidence-first FI evaluation protocol for token-class MCUs, a portable checklist unifying PSA/SESIP/CC expectations, and a set of concrete case studies (e.g., ESP32-C6 secure boot hardening). We do not claim a formal systematic review.
fault injection attack , hardware security , IoT security , microcontroller , PUF , secure boot , side-channel attack , TrustZone
Text of the article Перейти на текст статьи
TSARKA RD LLP, Astana, 010000, Kazakhstan
TSARKA Labs LLP, 010000, Astana, Kazakhstan
Department of Digital Development, L.N. Gumilyov, Eurasian National University, Astana, 010008, Kazakhstan
TSARKA RD LLP
TSARKA Labs LLP
Department of Digital Development
10 лет помогаем публиковать статьи Международный издатель
Книга Публикация научной статьи Волощук 2026 Book Publication of a scientific article 2026