Table of Contents

Miguel Manual

This manual is for miguel 0.0 (edition 0, updated 06 Oct 2016), which is a keyboard controller meant to be TEMPEST-resistant.

Copyright © 2016 Ineiev, super V 93

This manual is part of miguel; it is distributed under the same terms.

Miguel is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 3 of the License, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program. If not, see <https://www.gnu.org/licenses/>.

1 Introduction

This project started as a result of deliberations about generating computer passwords. I was establishing a procedure for myself similar to the one suggested by Diceware (http://world.std.com/~reinhold/diceware.html). Diceware documentation recommends using dice as the random number generator, because electronic random number generators may be far from ideal. However, this method has one more advantage: it is hard to snoop on. It emits practically nothing informative in the radio range, and the optical radiations can be relatively easily controlled (e.g. with screens and curtains).

So far, so good. As long as I don’t output the password on the monitor (which is not likely to be TEMPEST-resistant), the password mustn’t leak—of course, I assume that the attacker intercepts the radiowaves from the computer—and that the keyboard doesn’t emit signals that may identify the keys pressed.

A quick search revealed Compromising Electromagnetic Emanations of Wired and Wireless Keyboards, an article by Martin Vuagnoux, Sylvain Pasini. It suggested that my PS/2 keyboard does emit quite a bit of identifying signals:

The next step is to figure out if it’s feasible to resolve these issues. Monitor electronics are rather complicated and need high-speed processing, but keyboard controller is no rocket science at all: a low cost microcontroller with some simple circuits can easily do the job. And after you decide to replace the controller, all aforementioned vulnerabilities are quite fixable (and probably some other as well).

These measures don’t require any changes in the computer, not even in its software. The device would act exactly like the standard USB keyboard.

Using an encrypted channel would provide even more security, but this would require modified bootloader (definitely) and keyboard driver (most probably); also, it is not clear if the currently used microcontroller has a sufficient amount of program memory.

1.1 Controller Specifications

Maximum column number


Maximum row number


Sampling period

7 ms

Voltage supply

3.4 V to 6 V

Power consumption

active: 20 mA (no LED on), 30 mA (all LEDs on); sleeping: 20 uA

2 Schematics

Schematically, the keyboard controller features a 8-bit microcontroller, a noise generator used to get random numbers, a demultiplexer to add more output lines, lowpass filters connected to the keyboard matrix, switches to control keyboard LEDs, linear regulators to supply power, USB-specific circuits, and connectors.

The complete schematic diagram is provided in hw/miguel.sch in gschem format and exported to hw/schematics/miguel.pdf and hw/schematics/miguel.ps in the distribution tarball. The figures below are excerpts of that complete diagram.

2.1 MCU

The central part is occupied by a 32-pin AVR MCU in the TQFP-32 package (U1) Figure 2.1. ATmega48, ATmega88, ATmega168, ATmega328 will fit. ATmega8 would do (I use no new features), but it wasn’t qualified for 12MHz @ 3.3V.

The amount of program memory in ATmega48 is barely sufficient to implement RNG, keyboard scanning and LEDs control, and standard USB keyboard protocol. This leaves no room for encryption, so it may make sense to use ATmega88 or a processor with higher amount of memory.

The ADC is used to poll the voltage level of power supply; another input is connected to the voltage multiplier that produces the voltage level necessary for the noise-generating transistor (vmult), however, this input isn’t used yet.

The processor clock is generated with a 12MHz crystal ZQ1.

MCU with accompanying elements

Figure 2.1: MCU connections.

2.2 Noise Generator

D20-D22 make voltage multiplier, it’s fed with PWM produced by Timer1; the output voltage level (or rather the output current) can be changed within some extents modifying the frequency. The duty cycle of the same signal regulates the bias for the comparator U6 through Q8 and Q9 (Figure 2.2).

Charge pump and OR gate

Figure 2.2: Charge pump and bias generator.

Noise generator schematics

Figure 2.3: Noise generator.

The base-emitter junction of Q1 is the primary source of the noise, Q2, Q3, and U6 amplify it (Figure 2.3). The output of U6 comes to the T0 pin of U1, Timer0 counts 1-to-0 transitions. The pull-up resistor R14 (4.7k) gives a time constant of about 200ns, so 12MHz sampling rate must be adequate. The least significant bit of Timer0 counter produces decent random numbers with rates up to 100 kbit/s.

When active, the generator draws about 10 mA from the Vdd source.

2.3 Demultiplexers

In order to workaround the insufficient number of input-output lines in the MCU, two demultiplexers are used (Figure 2.4).

U2 and U3 control the LEDs and scan the keyboard matrix. Note that the address signals of U3 are transposed for PCB layout considerations, e.g. the A0 signal of U2 is shared with the A3 signal of U3. The Yn and Xn signals are named from MCU’s point of view: when it enables U3 and outputs 13 to the least significant half of PORTC, Y(13 + 16) = Y29 is drawn low.

2 demultiplexers

Figure 2.4: Demultiplexers.

2.4 Scanning Circuits

The signals for scanning the keyboard matrix go through low-pass filters (Figure 2.5); then the BAS16VV diodes are used to switch off the inactive lines (i.e. when there is a low level in any column, it passes to the row, the high levels in other columns are ignored). By the way, this is better than switching the columns between high impedance state and low level (and then adding low-pass filters): if more than one key is pressed in the row, the filter is discharged through the keyboard matrix; with our circuit, these currents flow within the controller PCB (which is smaller and enclosed in a screen).

Low-pass filters with diodes

Figure 2.5: Column lines.

The signals from the matrix come to MCU pins (mostly PIND), which also have low-pass filters and are pulled up to MCU power supply(Figure 2.6).

Pull-up resistors with capacitors in parallel

Figure 2.6: Row lines.

2.5 LED Switches

There are 4 signals for LEDs: NUM, CAPS, SCROLL and an extra LED to signal RNG failure, battery state and so on. The switches to control them are built on Q4-Q7, D3 and a part of D9 (Figure 2.7). When no pulses come to the inputs of those circuits, the LEDs glow; to switch them off, one needs to sample them continually. The time constant for switching on is about 0.1 s, so it mustn’t be possible to leak too much information with them.

The outputs are to be connected to the cathodes, 3.3V for the anodes is provided on pins 12 and 13 of X1.

Switches to control LEDs

Figure 2.7: LED controls.

2.6 Power Distribution

The device is to be powered with 3 AA-size batteries. As an alternative, it might take power from USB, but this may significantly decrease TEMPEST resistance since the information may leak through power wires. The measured consumption is about 20 mA with all LEDs off; in the sleeping mode, it draws about 0.02 mA.

There are two linear regulators: U5 powers the MCU, U4 powers all the rest. U4 is switched off when both chip select signals for U2 and U3 are low (the wired AND is built on D9): that is, I only want to draw one of U2 and U3 outputs low at once.

Linear voltage regulators

Figure 2.8: Power distribution.

2.7 USB Circuits

The USB protocol is implemented with V-USB; in addition to the usual resistor network used for self-powered devices, I use the USB power line to detect USB connection.

Resistor network for USB lines

Figure 2.9: USB circuits.

2.8 Connectors

The schematic diagram shows two connectors, 30-pin two-row X1 and 15-pin single-row X2. The first 6 pins of X1 form the conventional programming header for the MCU, so actually mounting these pins makes the things considerably more convenient; however, filling the rest pins on the board provides no crucial advantage over soldering the wires directly to the holes.

2 connectors with signal names

Figure 2.10: Connectors.

3 Assembly

The controller is built on a two-layer PCB. The layout in GNU PCB format comes as hw/miguel.pcb. The hw/miguel directory of the tarball contains Gerber files. You’ll need miguel.top, miguel.bottom, miguel.plated-drill.cnc and miguel.fab, the silkscreen and mask layers are not used.

3.1 Assembling the Board

This section mostly applies to the manual procedure.

When all the components are mounted, attach the USB cable and connect the power pin to the USB power line until the board is finally enclosed in screen and powered with batteries.

PCB with USB cable

Figure 3.1: Assembled controller board.

Fix the USB cable on a polygon with a piece of wire or two; the wires of the cable tend to break soon unless the end is fixed Figure 3.2.

Cable tied to board with a wire

Figure 3.2: Initial cable tie.

3.2 Connecting to Keyboard

Keyboards are usually screwed from the bottom side, and each key has a small flexible dome between it and the keyboard matrix. These small parts are easy to lose (unless they are connected in a single field), so you should prepare a box for them beforehand. When assembling the keyboard back, put something under the keyboard so that the keys are not pressed Figure 3.3; if they are, these rubber parts may move from their places.

A keyboard with two blocks under it

Figure 3.3: Supporting keyboard.

Columns are easily distinguished from the rows: they are laid out on the other film, and the number of the rows is much smaller (our controller supports no more than 8).

Now extract the controller board of the keyboard. Cut the conductors to disconnect the processor from the rest of the board, remove unnecessary parts like capacitors, drill holes and mount the additional LED (usually it fits between the Num Lock and the Caps Lock). Drill holes and solder wires to column and row lines (the PS/2 cable of the keyboard provides just sufficient amount of wires to connect the new controller with the old board).

If the pads of the matrix are longer than needed, and the board is protected with a mask, cut off the excessive parts of the pads on the film, they may short the wires.

Old keyboard controller with wires

Figure 3.4: Connecting to old controller board.

The new controller isn’t likely to fit in the case of the keyboard, so cut a hole to output the wires; also, cut a whole for the additional LED.

Standard keyboard LEDs with an extra LED

Figure 3.5: LED positions.

Connect the new controller to the old controller board: LED cathodes to the respective signals, LED anodes to the ‘Vdd’ line, the rows to ‘Zi’, and the columns to ‘Xi’; test the connections, check for shorts.

Assemble the keyboard. An extra caution should be taken to make sure that the contacts of the matrix are pressed tightly against the old board. If they aren’t, the new controller usually doesn’t respond to any keypresses.

3.3 Programming MCU

The leading software for uploading firmware into AVR seems to be avrdude (https://savannah.nongnu.org/projects/avrdude). Sometimes I still use uisp, but it is not maintained anymore and needs patching to support newer chips.

I program MCUs with a self-made ByteBlaster, but avrdude supports many other programmers as well. Please see avrdude documentation for details on how to upload firmware.

A fresh MCU will use its internal clock generator. In order to make it work with the crystal, you’ll need to change its fuse bytes, in case of ATmega88PA and similar devices you set the low fuse to ‘EF’, leaving the rest as per factory default.

3.4 Writing Keytable

Configure firmware with the ‘--enable-raw-scancodes’ option, build and upload it. Connect the keyboard to your PC, build and run the test-usb utility coming with the miguel package (this may require the root access). Take doc/keys.txt and press each key on the keyboard1, writing the received raw scancodes at the start of the respective line instead of the decimal code, like

66 04 Keyboard a and A4 31
73 05 Keyboard b and B 50
5C 06 Keyboard c and C4 48
5E 07 Keyboard d and D 33
60 08 Keyboard e and E 19

Then remove the ends of lines after the key codes:

66 04
73 05
5C 06
5E 07
60 08

When you are done, run the tab, another utility coming with miguel:

./tab < keys.txt > keytab.h

The utility generates a scancode table, one line per column; the empty cells are filled with ‘0x03’, the code for an error. The lower part of the table will be empty because some columns are not used, for example, the columns used to control LEDs; also, I’ve never encountered any keyboards with more than 18 columns. The lower part (containing at most 2 keys) is hardcoded to save flash space; the array is made shorter, the keys out of the array are hardcoded in ‘scan_to_code()’, and unused columns are enumerated in the ‘unused_columns’ array (its size is defined with the ‘UNUSED_COLUMNS’ macro); see firmware/keytab-gen.h for a reference implementation.

In many cases you’ll want to resold the wires to make the used part of the table compact; also, some keyboards have identical matrices, but you’ll have to rearrange the rows and the columns to match the same scancode table.

Now you can configure firmware for the working program, that is, without the ‘--enable-raw-scancodes’ option, build and flash it.

Use test-usb to check that the keyboard outputs correct key codes.

3.5 Enclosing in Screen

All elements of the device except the connectors are enclosed in a screen made of thin foiled FR–4; an additional internal screen is wrapped around the noise generator (Noise Generator) to protect the source of the noise from fast switching signals. These screens don’t touch each other. The screens are mounted to the ‘GND’ conductors of the board.

First, cut thin bands for the walls, tin them, apply to the board, bend and cut apertures for the conductors. Solder them to the board, cut the cover and tin its edges. Then solder the cover to the walls. Don’t leave slits except for the conductors on the board and to separate the internal screen.

After soldering each part of the screen make sure that you haven’t added any shorts: the power pins should show non-zero resistance, the extra LED should blink with a frequency of about 1 Hz (continuous light means failure of the noise generator), the test-usb utility should show exactly one scancode when pressing every key2.

Mounting a screen over a part of the board

Figure 3.6: Screen of noise generator.

Screen over the upper part of the board

Figure 3.7: Top screen.

Screen beneath the board

Figure 3.8: Bottom screen.

Fix USB cable on the screen with a piece of wire or two.

If needed, trim the wires. Don’t make them too short: they should be long enough to let you disassemble the keyboard without unsoldering most of them.

3.6 Mounting on Keyboard

Now it’s time to fix the whole construction on the case of the keyboard. Attach the battery holders to the keyboard, feed the controller from the batteries instead of the USB power line, mount the controller on the keyboard. Take care to provide a reliable contact with the batteries, they shouldn’t drop out of their holders.

Batteries in holders and board in screen fixed
on keyboard with screws

Figure 3.9: Device fully assembled.

4 Software

The package comes with three programs: tab, test-usb and clav. The two former are technological utilities used to setup the connection of the controller to the matrix, they run on a PC. The latter is firmware to run in the controller.

Software is configured and built using the standard GNU procedure:

tar xzf miguel-x.tar.gz && mkdir build && cd build
../miguel-x/configure && make

The ‘install’ target, while supported, is not very useful: the utilities are launched from the build directory, and clav.hex is used with avrdude.

The tab utility has few dependencies. In order to build test-usb, you’ll need libusb-1.0 installed. Building clav requires avr-libc and its dependencies.

Firmware is configured with a separate script invoked from the main confiure script; however, you can run firmware/configure directly.

These are the most important options of firmware configure script:


The controller reports undecoded scancodes, the column number in the higher 5 bits, and the row number in the lower 3 bits of each byte. This is necessary when writing the keytable for the keyboard or adjusting the wires to an existing keytable.


This option selects the keytable to use.


The program suppresses phantom keys by default: when it sees more than two non-modifier keys pressed at once, it skips the report. This algorithm takes little program memory and seems to practically solve the issue, but, on the one hand, it sometimes suppresses certainly valid keypresses, on the other hand, it still allows some phantom key combinations. This option switches it off.


The standard USB keyboard protocol allows the PC set the period of reports dropped when the state of keys doesn’t change, and drivers typically set it to infinity. If the attacker can see the bursts of USB packets, the timings of keypresses may reveal some information about the pressed keys. This option limits the maximum idle period.


Some reports don’t come from the controller to the PC, I have no idea why. To workaround this, I added the possibility to send multiple reports on the same event, and it helped in many cases (such behavior may confuse very old drivers, though). This option sets the number of repeated reports. It is not going to be needed when the maximum idle period is set to some small value.

5 Usage Notes

Even very old software supports USB keyboards, but in order to use it with the bootloader you may need to enable USB keyboards in BIOS (the kernel doesn’t need it and detects the keyboard independently).

The keyboard should behave very similarly to the standard one except it has an additional LED. It indicates the battery level and signals about failures of random number generator.

When the keyboard is switched on, its microcontroller switches the extra LED on and runs the start-up random number generator test. It longs a second or two. If the hardware passes the test, the LED starts blink twice a second or so. The longer it is switched on, the higher the voltage of the battery.

The microcontroller continues running random number test, and if it encounters a failure, it switches the LED on and runs the start-up test again. In other words, long spans of the extra LED light indicate random number generator failure (this may mean that it’s time to recharge the battery). Note that it still scans the keyboard and reports the keypresses.

Another possibility is cycling the USB power line: when the controller encounters low VUSB level, it switches off until VUSB is high again. In this mode, no LEDs are active, no keys are scanned, and the microcontroller puts itself in a sleeping mode.

6 Benchmarks

I’ve run two tests to estimate the relative emissions from the original and the modified keyboard. Both were done with a general oscilloscope, with no special radio equipment involved.

6.1 Wire Loop

This is the most simple test. A loop of wire is laid on the keyboard and connected to the oscilloscope.

Wire loop connected to oscilloscope probe on keyboard

Figure 6.1: Setup.

With the original keyboard, oscilloscope shows peaks up to 200 mV with a period of the oscillations of about 30 ns. When the controller is replaced, the oscilloscope doesn’t detect such peaks. It means that the gain is at least 20 dB. The next test suggests that this estimation is very conservative.

Screen with pulses

Figure 6.2: Signal detected with wire loop.

6.2 Matrix Current

In the next test, I measured the current running through the matrix. In the original keyboard, I added a 10 Ohm resistor in series with a column, attached two probes, and used the oscilloscope to derive the difference of the voltages. Then I repeated the test with the modified keyboard, but this time I used a 10 kOhm resistor. In both cases, I pressed a key on the respective column.

The original keyboard shows pulses with a peak of about 400 mV and a width of about 30 ns. The voltage of 400 mV corresponds to a current of about 40 mA.

Two signals with the difference in red

Figure 6.3: Original keyboard, 10 Ohm.

The signal from the modified keyboard is noisy, with a maximum of about 100 mV, which translates to currents of 10 uA. It’s hard to tell if the oscillations are an artifact of the procedure, but at any rate their typical period is about 1 us.

Pulses in noise

Figure 6.4: Modified keyboard, 10 kOhm.

The keyboard matrix may be thought of as a small magnetic dipole (the smallest time at hand, 30 ns, corresponds to 60 m wavelength, it’s much more than the size of the keyboard). The power emitted by such dipoles is directly proportional to the squares of the amplitude and the frequency of the current. This means that the decrease in current is equivalent to 70 dB, and the lower frequency may result in additional 30 dB gain.

70 dB means that the attacker with the same equipment has to be 3000 times closer3. My threat model assumes that they have no access to the room where the keyboard works (if they had, they possibly could install a kind of keylogger), so in order to intercept the emissions from the modified keyboard, they must be able to intercept the emissions from the original keyboard at a range of a few kilometers. I conclude that the matrix emission hardly can be an issue for the modified keyboard, it must be easier to exploit some other side channel.

7 Licensing Terms

All texts originally written for this project are distributed under the GNU GPL version 3 or (at your option) any later version. However, the external USB library for AVR is distributed under the GPLv3-only, so the firmware part as a whole is under the GPLv3-only.

Note that codes for some additional keys like Sleep are absent; they would require a separate USB report descriptor, and they are currently not supported. You can write down their scancodes and replace ‘0x03’ with ‘0x00’ in those positions of the resulting table.


For the modifier keys, that is, ‘Shift’, ‘Ctrl’, ‘Alt’, ‘GUI’, it should be a single bit in the first byte of the report.


Greater distances generally allow more advanced equipment, for example, large directed antennas, but I don’t take this into account.

This is a home page for miguel, a keyboard controller.

It's in an early stage of development, but manual and a release are already available.

