首页> 外文会议>Workshop on Fault Diagnosis and Tolerance in Cryptography >Precise Spatio-Temporal Electromagnetic Fault Injections on Data Transfers
【24h】

Precise Spatio-Temporal Electromagnetic Fault Injections on Data Transfers

机译:精确的时空电磁故障注入

获取原文

摘要

Fault injection techniques allow an attacker to alter the behavior of an electronic device in order to extract confidential information or be granted unauthorized privileges. To this end, local electromagnetic fault injections (EMFI) are commonly used to corrupt or prevent the execution of instructions. However, little attention is devoted to practical data corruption. This article investigates the local effects of EMFI on data transfer from the Flash memory to the 128-bit data buffer of a cortex-M microcontroller. We demonstrate that the corrupted bits are closely related to the location of the injection probe, allowing us to set or reset from 0 to 128 bits with a byte-level precision. Moreover, the spatial and temporal accuracy of the injection technique allowed us to target the data prefetch mechanism without corrupting the code execution. We highlight the efficiency of the derived fault model with three practical case studies. Firstly, we demonstrate precise key-zeroing and key-setting capability, with further extension to a DFA on the secret key of a cipher from Biham and Shamir, that was never implemented practically. Next, we report practical persistent faults on ARM microcontroller, which allows an attacker to retrieve the secret key of a cipher with a single successful injection.
机译:故障注入技术允许攻击者更改电子设备的行为,以提取机密信息或被授予未经授权的特权。为此,通常使用局部电磁故障注入(EMFI)来破坏或阻止指令的执行。但是,很少关注实际数据损坏。本文研究了EMFI对从闪存到cortex-M微控制器的128位数据缓冲区的数据传输的局部影响。我们证明了损坏的位与注入探针的位置密切相关,从而使我们能够以字节级的精度将0位设置或重置为128位。此外,注入技术的空间和时间准确性使我们可以在不破坏代码执行的情况下确定数据预取机制的目标。我们通过三个实际案例研究突出了导出的故障模型的效率。首先,我们展示了精确的密钥归零和密钥设置功能,并进一步扩展了Biham和Shamir密码的秘密密钥上的DFA,这从未实际实现过。接下来,我们报告ARM微控制器上的实际持久性错误,攻击者可以通过一次成功的注入来获取密码的秘密密钥。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号