. 24/7 Space News .
New Class Of Attacks On Computer Security Systemss

zap and your security card is toast
Cambridge - May 17, 2002
Researchers at Cambridge University's Computer Laboratory have developed a powerful class of attacks on computer security systems. The attack was invented by Sergei Skorobogatov, a PhD student with the Laboratory's security group, led by Dr Ross Anderson.

They discovered that illuminating a single transistor in an integrated circuit, using a laser or other tightly focussed source of energy, it is possible to induce a transient fault in the circuit. By careful choice of the target transistor and the exact time of the transient, it is possible to circumvent the protection of many of the secure microcontrollers and smartcards in use today.

The use of fault attacks to break security processors had been described by a number of researchers in the past, but the methods available for inducing actual faults were crude (for example, inserting a transient overvoltage into the power supply to the chip).

The Cambridge team used a simple photographer's flashgun, mounted on a microscope to induce faults in the chips.

By now, many security processors contain circuits to stop such attacks. The new attack, however, works with such precision that existing countermeasures will have to be upgraded.

Work on perfecting the attack was completed in the Computer Laboratory a year ago, but has been kept under wraps until now to enable defensive technologies to be developed. Dr Anderson and Dr Simon Moore, also a member of the Laboratory's Security Group, have developed and tested a new silicon technology that can block this and many other previously known attacks.

The team believes the attack is likely to have a disruptive influence on security processor technology. Simply shielding the processor, for example by adding a top metal layer to the chip, is not sufficient; silicon becomes transparent to light in the infrared so the attacks can still be conducted through the rear of the chip. It is also possible that attacks can be conducted using other sources of energy, such as electromagnetic pulses and X-rays.

"Sergei's work will trigger a generation change in smartcard technology," said Dr Anderson. "The immediate effect of his work is that many attacks on computer systems that were developed as theoretical possibilities by the research communities in the 1990s have suddenly become practical."

Their first prototype of a new security processor was unveiled at the IEEE International Symposium on Asynchronous Circuits and Systems in Manchester in April, where it won the best presentation award. The new processor is designed so that the failure of a single transistor or other component should not cause a failure of protection: it should either have no effect, or cause an alarm. This introduces a new kind of security fault-tolerance which may have much wider applicability.

CAPTION: The team's prototype chip has all the new components needed for a secure smartcard: a 16-bit CPU, a Montgomery multiplier, a memory controller that includes bus cryptography so that standard memory blocks can be used, and a smartcard UART. It has conventional versions of the CPU as well as the new secure CPU, and instrumentation circuitry, to enable direct and precise comparisons to be made. The paper on Mr Skorobogatov's attacks can be found at http://www.cl.cam.ac.uk/ftp/users/rja14/faultpap3.pdf The paper on the protection technology can be found at http://www.cl.cam.ac.uk/~swm11/SecureSmartcard/ Sergei Skorobogatov's Webpage http://www.cl.cam.ac.uk/users/sps32/ Ross Anderson's Webpage http://www.cl.cam.ac.uk/users/rja14/ Related Links
SpaceDaily
Search SpaceDaily
Subscribe To SpaceDaily Express

US, India Hold Talks To Combat Cyber Attacks
New Delhi (AFP) Apr 30, 2002
The United States and India have launched high-level security talks to protect their information technology systems from attacks by hostile states and computer-savvy criminals, officials said Tuesday.



Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only














The content herein, unless otherwise known to be public domain, are Copyright 1995-2016 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement All images and articles appearing on Space Media Network have been edited or digitally altered in some way. Any requests to remove copyright material will be acted upon in a timely and appropriate manner. Any attempt to extort money from Space Media Network will be ignored and reported to Australian Law Enforcement Agencies as a potential case of financial fraud involving the use of a telephonic carriage device or postal service.