Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity
Haoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang, Yan Long
摘要
Electromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively. This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage. We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30 m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs. Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper35
- Robust Speech Recognition via Large-Scale Weak SupervisionAlec Radford, Jong Wook Kim, Tao Xu, Greg Brockman 等ICML 2023 · 被引用 6,966 次
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes 等CCS 2018 · 被引用 186 次
- Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial SensorsYazhou Tu, Zhiqiang Lin, Insup Lee, Xiali HeiUSENIX Security 2018 · 被引用 132 次
- Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksYazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez 等CCS 2019 · 被引用 87 次
- Detection of Electromagnetic Interference Attacks on Sensor SystemsYouqian Zhang, Kasper RasmussenS&P 2020 · 被引用 68 次
相关 Paper
- EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel SignalsNader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos PrvulovicHPCA 2020 · 被引用 21 次
- TEMPEST Comeback: A Realistic Audio Eavesdropping Threat on Mixed-signal SoCsJieun Choi, Hae-Yong Yang, Dong-Ho ChoCCS 2020 · 被引用 33 次
- Eavesdropping on Black-box Mobile Devices via Audio Amplifier's EMRHuiling Chen, Wenqiang Jin, Yupeng Hu, Zhenyu Ning 等NDSS 2024
- Lend Me Your Ear: Passive Remote Physical Side Channels on PCsDaniel Genkin, Noam Nissan, Roei Schuster, Eran TromerUSENIX Security 2022
- Periscope: A Keystroke Inference Attack Using Human Coupled Electromagnetic EmanationsWenqiang Jin, Srinivasan Murali, Huadi Zhu, Ming LiCCS 2021 · 被引用 34 次
