228
3 Hardware Trojans in Electronic Devices
Called party
Called party
Caller party
Caller party
Invitation
Invitation
Attempt
Attempt
Call
Call
Acceptance
Acceptance
Confirmation
Goodbye
Acceptance
SIP Server -
Session Initiation Protocol server
ZRTP -
Cryptographic encryption key negotiation protocol used in voice over IP transmission systems VOIP
SRPT -
Secure Real-time Transport Protocol
Hello -
Greeting
HeiioACK -
Greeting confirmation
Commit -
Transaction completion
Fig. 3.6 ZRTP security principle 2009
2014
Expert state that as of the end of the current year, more than 750 million mobile phones
around the world appeared vulnerable to intruders due to insufficiently protected SIM
cards [11].
Karsten Nohl, the head of Security Research Labs, announces the discovered
vulnerability of SIM cards with data encryption standard (DES). Even though this is
an outdated standard, it is still used by many manufacturers, and hundreds of millions
of SIM cards support DES. This vulnerability allowed (by sending a fake message
from a telecom operator to the phone) to receive a 56-bit key in the reply message
(the answer is sent automatically, and about 25% of DES-cards are exposed to such
“deception”).
Précédent

- 248/839

Suivant