4.7 Case Study of the Development …
365
ways, but, by nature, it deteriorates the performance or correctness of the operation of
the Alpha device. In order to implement DoS, an acceptable location was chosen so
that it was hidden during verification tests. Finding the appropriate target is actually
trivial, since modifying almost any signal creates incorrect output. The clock signal
can be “frozen” to such a value that the device stops functioning, data transmission
can be distorted so that it does not send frames correctly formatted according to the
RS232 protocol, even data read from the keyboard can be “skewed” so that incorrect
messages will be transmitted.
This implementation of the DoS Trojan [156] attacks the key used to encrypt
messages, achieves its denial-of-service goals, and remains hidden by making only
minimal code modifications. The triggering mechanism used for this implementation uses a timer so that it functions periodically, switching about every 3.5 min.
Ultimately, the user will not notice in practical work that a similar Trojan embedded
in his device is active, since he only “spoils” the ciphertext sent out in such a way
that the receiver at the other end of the communication channel receives the secret
text, which has already been a completely decoded key, not what they expected.
This attack uses the counter already existing in the structure within a seven-segment
driver subprogram and a small, noticeable only to professionals, modification of the
standard AES-128 subprogram. The seven-segment driver already contains a 12-bit
counter operating at 625 kHz. The addition of 17 extra bits allows for a 7.15 min
cycle time for the high bit. Such an addition of a small number of digits will significantly increase the cycle time, allowing you to successfully pass standard tests for
correct operation. The highest bit is passed through the seven-segment driver as a
false enabling signal, which is connected to the AES-128 core as a “similar” resolution. Inside the AES-128 module, this bit is collected using a check parity circuit
with one of the key bits, in order to spoil approximately 50% of the ciphertext.
As a result, from the user’s point of view, the transmission looks quite normal
externally, but “corrupted” data is transmitted. The single character “A” used as a
test, transmitted together with a random encryption key, creates a final output signal,
where 62 of the 128 bits are transmitted incorrectly (reaching the expected error
frequency of 50%).
The attack based on the analysis of the thermal field of a microcircuit: Another
method of sensitive data leakage that interested the participants of this competition
was based on “heat transmission.” According to the scenario, this attack microcircuit,
FPGA, systematically heats up or works for a long time in its normal state, so that
the attacker could create some binary code used to transmit information. For this
purpose, a malicious user may place an ordinary temperature sensor in an FPGA
microcircuit and monitor the temperature of the device in order to collect stolen
data (for example, key bits). Although this attack requires physical access to the
FPGA, this method can have extensive practical applications. This may include a
real scenario where one of the Alpha devices is captured (recall the German Enigma
captured by the British), allowing the invaders to extract the key and decipher all past
and future data transmissions generated by the Alpha device. This attack will also
work effectively if the malicious user had at least short-term physical access to the
FPGA and was able to extract the key at that time. He could also add some hidden
Précédent

- 384/839

Suivant