Hackers can steal cryptographic keys by taping power LEDs from 60 feet away

[ad_1]

Enlarge / Left: A smart card reader processing the encryption key of an inserted smart card. Right: Surveillance camera video records the reader’s power LED from a distance of 60 meters.

Nasi et al.

Researchers have developed a new attack that recovers secret encryption keys stored in smart cards and smartphones by using cameras in iPhones or commercial surveillance systems to videotape power LEDs that indicate when card reader or smartphone is on.

The attacks offer a new way to exploit two previously disclosed side channels, a class of attack that measures the physical effects that leak from a device as it performs a cryptographic operation. By carefully monitoring characteristics such as power consumption, sound, electromagnetic emissions, or the time it takes for an operation to occur, attackers can gather enough information to recover the secret keys that underpin security. and confidentiality of a cryptographic algorithm.

Simplified side channel operation

As Wired reported in 2008, one of the oldest known secondary channels was in a top-secret encrypted teleprinter terminal that the United States Army and Navy used during World War II to transmit communications that could not not be read by German and Japanese spies. To the surprise of the Bell Labs engineers who designed the terminal, it caused readings from a nearby oscilloscope whenever a cipher letter was typed. While the device’s encryption algorithm was strong, the electromagnetic emissions emanating from the device were sufficient to provide a side channel that leaked the secret key.

Side channels have been a part of life ever since, and new ones are regularly discovered. The recently discovered side channels tracked as Minerva and Hertzbleed were revealed in 2019 and 2022, respectively. Minerva was able to recover the 256-bit secret key from a US government-approved smart card by measuring timing patterns in a cryptographic process known as scalar multiplication. Hertzbleed allowed an attacker to retrieve the private key used by the post-quantum cryptographic algorithm SIKE by measuring the power consumption of the Intel or AMD CPU performing certain operations. Given the use of time measurement in one and power measurement in the other, Minerva is known as a synchronization side channel, and Hertzbleed can be considered a power side channel.

On Tuesday, academic researchers unveiled new research demonstrating attacks that offer a new way to exploit these types of side channels. The first attack uses an internet-connected surveillance camera to take high-speed video of the power light of a smart card reader or attached device during cryptographic operations. This technique allowed the researchers to extract a 256-bit ECDSA key from the same government-approved smart card used at Minerva. The other allowed researchers to retrieve the SIKE private key from a Samsung Galaxy S8 phone by dragging an iPhone 13’s camera to the power light of a USB speakerphone connected to the handset, from the same way Hertzbleed removed Intel’s SIKE keys. and AMD processors.

Advertisement

Power lights are designed to indicate when a device is turned on. They generally project a blue or purple light whose brightness and color vary according to the power consumption of the device to which they are connected.

Video-based cryptanalysis.

There are limitations to both attacks that make them impractical in many (but not all) real-world scenarios (more on that later). Despite this, the published research is groundbreaking because it offers a whole new way to facilitate side-channel attacks. Not only that, but the new method removes the biggest obstacle preventing existing methods from exploiting secondary channels: the need to have instruments such as an oscilloscope, electrical probes, or other objects touching or being near of the attacked device.

In the case of Minerva, the device hosting the smart card reader had to be compromised for the researchers to collect sufficiently accurate measurements. Hertzbleed, on the other hand, did not rely on a compromised device, but instead took 18 days of constant interaction with the vulnerable device to recover the SIKE private key. To attack many other secondary channels, such as that of the World War II encrypted ticker terminal, attackers must have specialized and often expensive instruments attached to or near the targeted device.

The video attacks presented on Tuesday reduce or completely eliminate these requirements. All that is needed to steal the private key stored on the smart card is an internet-connected surveillance camera that can be up to 62 feet from the targeted reader. The side channel attack on the Samsung Galaxy handset can be performed by an iPhone 13 camera already present in the same room.

Sources

1/ https://Google.com/

2/ https://arstechnica.com/information-technology/2023/06/hackers-can-steal-cryptographic-keys-by-video-recording-connected-power-leds-60-feet-away/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts