跳到主要导航 跳到搜索 跳到主要内容

On the need of physical security for small embedded devices: A case study with COMP128-1 implementations in SIM cards

  • Yuanyuan Zhou
  • , Yu Yu
  • , François Xavier Standaert
  • , Jean Jacques Quisquater
  • Brightsight
  • Tsinghua University
  • Université catholique de Louvain

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Ensuring the physical security of small embedded devices is challenging. Such devices have to be produced under strong cost constraints, and generally operate with limited power and energy budget. However, they may also be deployed in applications where physical access is indeed possible for adversaries. In this paper, we consider the case of SIM cards to discuss these issues, and report on successful side-channel attacks against several (old but still deployed) implementations of the COMP128-1 algorithm. Such attacks are able to recover cryptographic keys with limited time and data, by measuring the power consumption of the devices manipulating them, hence allowing cards cloning and communications eavesdropping. This study allows us to put forward the long term issues raised by the deployment of cryptographic implementations. It provides a motivation for improving the physical security of small embedded devices early in their development. We also use it to argue that public standards for cryptographic algorithms and transparent physical security evaluation methodologies are important tools for this purpose.

源语言英语
主期刊名Financial Cryptography and Data Security - 17th International Conference, FC 2013, Revised Selected Papers
230-238
页数9
DOI
出版状态已出版 - 2013
活动17th International Conference on Financial Cryptography and Data Security, FC 2013 - Okinawa, 日本
期限: 1 4月 20135 4月 2013

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
7859 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议17th International Conference on Financial Cryptography and Data Security, FC 2013
国家/地区日本
Okinawa
时期1/04/135/04/13

指纹

探究 'On the need of physical security for small embedded devices: A case study with COMP128-1 implementations in SIM cards' 的科研主题。它们共同构成独一无二的指纹。

引用此