首页> 外文会议>Iinternational conference on codes, cryptology, and information security >Beyond Cryptanalysis Is Software Security the Next Threat for Smart Cards
【24h】

Beyond Cryptanalysis Is Software Security the Next Threat for Smart Cards

机译:超越密码分析的是软件安全,这是智能卡的下一个威胁

获取原文

摘要

Smart cards have been considered for a long time as a secure container for storing secret data and executing programs that manipulate them without leaking any information. In the last decade, a new form of attack that uses the hardware has been intensively studied. We have proposed in the past to pay attention also to easier attacks that use only software. We demonstrated through several proof of concepts that such an approach should be a threat under some hypotheses. We have been able to execute self-modifying code, return address programming and so on. More recently we have been able to retrieve secret keys belonging to another application. Then all the already published attacks should have been a threat but the industry increased the counter measures to mitigate for each of the published attack. In such a sensitive domain, we always submit the attacks to the industrial partners but also national agencies before publishing any attack. Within such an approach, they have been able to patch their system before any vulnerabilities should be exploited.
机译:长期以来,智能卡已被视为一种安全的容器,用于存储秘密数据并执行在不泄漏任何信息的情况下操纵它们的程序。在过去的十年中,对使用硬件的新型攻击形式进行了深入研究。过去,我们建议还注意仅使用软件的更简单的攻击。我们通过一些概念证明证明,在某些假设下,这种方法应该是一种威胁。我们已经能够执行自修改代码,返回地址编程等。最近,我们已经能够检索属于另一个应用程序的秘密密钥。然后,所有已经发布的攻击都应该成为威胁,但是业界增加了针对每种已发布攻击的缓解措施。在这样一个敏感的领域,在发布任何攻击之前,我们总是将攻击提交给工业伙伴以及国家机构。通过这种方法,他们能够在应利用任何漏洞之前修补其系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号