首页> 外文会议>International conference on selected areas in cryptography >When Reverse-Engineering Meets Side-Channel Analysis - Digital Lockpicking in Practice
【24h】

When Reverse-Engineering Meets Side-Channel Analysis - Digital Lockpicking in Practice

机译:当逆向工程遇到侧通道分析时-实践中的数字锁定

获取原文
获取外文期刊封面目录资料

摘要

In the past years, various electronic access control systems have been found to be insecure. In consequence, attacks have emerged that permit unauthorized access to secured objects. One of the few remaining, allegedly secure digital locking systems-the system 3060 manufactured and marketed by SimonsVoss-is employed in numerous objects worldwide. Following the trend to analyze the susceptibility of real-world products towards implementation attacks, we illustrate our approach to understand the unknown embedded system and its components. Detailed investigations are performed in a step-by-step process, including the analysis of the communication between transponder and lock, reverse-engineering of the hardware, bypassing the read-out protection of a microcontroller, and reverse-engineering the extracted program code. Piecing all parts together, the security mechanisms of the system can be completely circumvented by means of implementation attacks. We present an EM side-channel attack for extracting the secret system key from a door lock. This ultimately gives access to all doors of an entire installation. Our technique targets a proprietary function (used in combination with a DES for key derivation), probably originally implemented as an obscurity-based countermeasure to prevent attacks.
机译:在过去的几年中,已经发现各种电子访问控制系统是不安全的。结果,出现了允许未经授权访问安全对象的攻击。剩下的据称是安全的少数数字安全锁系统之一-由SimonsVoss制造和销售的3060系统-已在全球众多对象中使用。随着趋势分析现实世界产品对实现攻击的敏感性,我们说明了我们了解未知嵌入式系统及其组件的方法。详细的研究将分步进行,包括分析应答器和锁之间的通信,对硬件进行反向工程,绕过微控制器的读取保护以及对提取的程序代码进行反向工程。将所有部分连接在一起,可以通过实施攻击完全规避系统的安全机制。我们提出了一种EM侧通道攻击,用于从门锁中提取秘密系统密钥。最终,这可以访问整个安装过程中的所有门。我们的技术针对的是专有功能(与DES结合使用以进行密钥派生),可能最初是作为基于模糊性的对策来防止攻击的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号