Smart Card Vulnerability

Info exchange on hex/plain/masters, handler/service-keys, Prov-IDs, ChIDs, PPUAs, etc. NO KEYS MAY BE POSTED!


Reply
 
LinkBack Thread Tools Display Modes
Old 17-05-2002   #1
"Satellite Expert"
 
wolsty's Avatar
 
Join Date: 01-01-2000
Location: Kernow
Posts: 716
Thanks: 1
Thanked 1 Time in 1 Post

My System: Humax IRCI5400z, Sony Digibox, Digilogic Freeview box, 1.1m Triax, Manhattan DiSEqC mount, various cards, Season Interface
Smart Card Vulnerability

See www.iht.com/articles/57672.html for full text.

Two University of Cambridge computer security researchers on Monday were to detail an ingenious and inexpensive attack that employs a $30 camera flashgun and a microscope to extract secret information contained in widely used smart cards. "This vulnerability may pose a big problem for the industry," they wrote in their paper, "Optical Fault Induction Attacks." The researchers argued that the industry would need to add countermeasures to increase the cards' security.

The key is part of a two-key system that is used to encode and decode information. Typically, after the cardholder authenticates the card by supplying a personal identification number, the private key is used to encrypt the transaction.

The researchers found that they could interrupt the operation of the smart card's microprocessor simply by exposing it to an electronic camera flashbulb. They were able to expose the circuit to the light by scraping most of the protective coating from the surface of the microprocessor circuit that is embedded in each smart card.

With more study, the researchers were able to focus the flash on individual transistors within the chip by beaming the flash through a standard laboratory microscope. By sequentially changing the values of the transistors used to store information, they were able to "reverse engineer" the memory address map, allowing them to extract the secret information.



wolsty
wolsty is offline   Reply With Quote
Old 17-05-2002   #2
Ididndoit
Guest
 
Posts: n/a
RE: Smart Card Vulnerability

Hmm, interesting - bank cards, I guess. Beats DPA with a car battery . Thanx for info.
  Reply With Quote
Reply

Bookmarks

Tags
card, smart, vulnerability


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Foxtel and Austar to roll out 'unhackable' smart card net1 Daily Satellite and Broadcast industry News 4 02-05-2008 01:18 PM
Matrix Reloaded How To by AHAC rolfw Matrix Reloaded, Revolutions and CAS interface 52 27-12-2005 12:02 PM
Smart Card krol Cards & Programmers General 5 20-06-2005 02:42 PM
Irdeto debuts CA module with embedded smart card net1 Irdeto system 0 04-02-2004 07:50 PM
What kind of smart card use??? PLS HELP grex23 Cards & Programmers General 5 30-09-2003 10:00 PM






All times are GMT +1. The time now is 03:36 AM.


All views and information expressed in users' communications and profiles represent the opinions of the users concerned and do not represent the views of Satellites.co.uk. All images and news content are believed to be in the public domain, except where otherwise stated. Forum software by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

Content Relevant URLs by vBSEO 3.3.1