跳到主要导航 跳到搜索 跳到主要内容

Small tweaks do not help: Differential power analysis of MILENAGE implementations in 3G/4G USIM cards

  • Junrong Liu
  • , Yu Yu*
  • , FranÇois Xavier Standaert
  • , Zheng Guo
  • , Dawu Gu
  • , Wei Sun
  • , Yijie Ge
  • , Xinjun Xie
  • *此作品的通讯作者
  • Shanghai Jiao Tong University
  • CAS - Institute of Information Engineering
  • State Key Laboratory of Cryptology
  • Université catholique de Louvain
  • Shanghai Viewsource Information Science and Technology Co., Ltd
  • Shanghai Modern General Recognition Technology Corporation

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Side-channel attacks are an increasingly important concern for the security of cryptographic embedded devices, such as the SIM cards used in mobile phones. Previous works have exhibited such attacks against implementations of the 2G GSM algorithms (COMP-128, A5). In this paper, we show that they remain an important issue for USIM cards implementing the AES-based MILENAGE algorithm used in 3G/4G communications. In particular, we analyze instances of cards from a variety of operators and manufacturers, and describe successful Differential Power Analysis attacks that recover encryption keys and other secrets (needed to clone the USIM cards) within a few minutes. Further, we discuss the impact of the operator-defined secret parameters in MILENAGE on the difficulty to perform Differential Power Analysis, and show that they do not improve implementation security. Our results back up the observation that physical security issues raise long-term challenges that should be solved early in the development of cryptographic implementations, with adequate countermeasures.

源语言英语
主期刊名Computer Security – ESORICS 2015 - 20th European Symposium on Research in Computer Security, Proceedings
编辑Peter Y.A. Ryan, Günther Pernul, Edgar Weippl
出版商Springer Verlag
468-480
页数13
ISBN(印刷版)9783319241739
DOI
出版状态已出版 - 2015
已对外发布
活动20th European Symposium on Research in Computer Security, ESORICS 2015 - Vienna, 奥地利
期限: 21 9月 201525 9月 2015

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
9326
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议20th European Symposium on Research in Computer Security, ESORICS 2015
国家/地区奥地利
Vienna
时期21/09/1525/09/15

指纹

探究 'Small tweaks do not help: Differential power analysis of MILENAGE implementations in 3G/4G USIM cards' 的科研主题。它们共同构成独一无二的指纹。

引用此