Return
FirmAware: A Multistage Framework for Embedded Firmware Decryption
DOI:10.1016/j.iot.2026.102080.png)
Abstract
En 中文
Firmware encryption is increasingly used by embedded device vendors to protect intellectual property, but it simultaneously creates a ”black box” that hinders vulnerability discovery and forensic analysis. In this paper, we propose FirmAware, a multistage framework for decrypting encrypted firmware across diverse vendors and device families. Unlike existing tools that rely primarily on static signatures, FirmAware employs a tiered strategy: applying public decryption methods, analyzing transitional firmware, which refers to versions that bridge the gap between unencrypted and encrypted releases to recover keys and algorithms, and utilizing hardware-assisted extraction as a final resort. We formalize this process through a five-case classification of transitional firmware based on identification and availability. Through empirical evaluation, we successfully decrypted 239 firmware images from multiple vendors, covering a diverse set of device families. Notably, our cross-case extension analysis reveals a systemic weakness in vendor key management, where a single recovered artifact enabled the decryption of 90 firmware versions across 15 different models. Our results demonstrate that FirmAware provides a scalable methodology to overcome firmware encryption, uncovering critical vulnerabilities in embedded cryptographic practices and enabling deeper security auditing for IoT devices.
Journal
IF:
7.6
Papers:
1.9K
Citations:
6.9K

