270
3 Hardware Trojans in Electronic Devices
been performed, and several versions of software have been written with which any
independent researcher can verify effectiveness of this method.
This work is in fact a continuation of Adi Shamir’s 2004 presentation, which is
well known to security experts. Back then, he demonstrated the theoretical possibility of extracting keys and the evident difference between sound landscape during
decryption of text with various RSA keys [24].
Now, experts managed to reach a fundamentally new level, thanks in large part
to the developer Lev Pakhmanov, who wrote a unique software for processing such
signals.
“Many computers produce a high-pitched sound during operation due to vibration in certain electronic components,” explains Adi Shamir. “These acoustic oscillations are more than just annoying peeping: they contain information about software
running in the system, including security-related computations.” In 2004, Shamir
demonstrated that different RSA keys produce different patterns; however, it was
unclear back then how to extract separate key bits from them. The main problem
consisted in the fact that standard sound equipment was unable to record sound with
a sufficiently high sampling rate: from 20 kHz for standard microphones and up to
hundreds KHz for ultrasound microphones. In any case, this is by many orders of
magnitude less than the frequency of several GHz utilized my modern computers.
Today, software is available that easily retrieves the full 4096-bit GnuPG keys from
computers of various models after an hour of tapping if the computer is decrypting.
A successful demonstration of such attack using a smartphone, which was placed
30 cm away from the computer, as well as an attack using directional microphones
from a distance of up to 4 m (Fig. 3.27) [25], was carried out and documented.
Background noise, as well as the sounds of the hard drive, fan, and other components, usually doesn’t interfere with the final analysis, since they are produced at
Fig. 3.27 Demonstration of the method of extracting 4096-bit RSA keys using a directional
microphone. Left—Interception device (targeted microphone), right—Attack target (laptop) [25]
Précédent

- 290/839

Suivant