Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers
Giovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes, Aurélien Francillon
摘要
This paper presents a new side channel that affects mixed-signal chips used in widespread wireless communication protocols, such as Bluetooth and WiFi. This increasingly common type of chip includes the radio transceiver along with digital logic on the same integrated circuit. In such systems, the radio transmitter may unintentionally broadcast sensitive information from hardware cryptographic components or software executing on the CPU. The wellknown electromagnetic (EM) leakage from digital logic is inadvertently mixed with the radio carrier, which is amplified and then transmitted by the antenna. We call the resulting leak "screaming channels". Attacks exploiting such a side channel may succeed over a much longer distance than attacks exploiting usual EM side channels. The root of the problem is that mixed-signal chips include both digital circuits and analog circuits on the same silicon die in close physical proximity. While processing data, the digital circuits on these chips generate noise, which can be picked up by noise-sensitive analog radio components, ultimately leading to leakage of sensitive information. We investigate the physical reasons behind the channel, we measure it on several popular devices from different vendors (including Nordic Semiconductor nRF52832, and Qualcomm Atheros AR9271), and we demonstrate a complete key recovery attack against the nRF52832 chip. In particular, we retrieve the full key from the AES-128 implementation in tinyAES at a distance of 10 m using template attacks. Additionally, we recover the key used by the AES-128 implementation in mbedTLS at a distance of 1 m with a correlation attack. Screaming channel attacks change the threat models of devices with mixed-signal chips, as those devices are now vulnerable from a distance. More specifically, we argue that protections against side channels (such as masking or hiding) need to be used on this class of devices. Finally, chips implementing other widespread protocols (e.g., 4G/LTE, RFID) need to be inspected to determine whether they are vulnerable to screaming channel attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper25
- Losing the Car Keys: Wireless PHY-Layer Insecurity in EV ChargingRichard Baker, Ivan MartinovicUSENIX Security 2019 · 被引用 67 次
- IRShield: A Countermeasure Against Adversarial Physical-Layer Wireless SensingPaul Staat, Simon Mulzer, Stefan Roth, Veelasha Moonsamy 等S&P 2022 · 被引用 62 次
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 被引用 48 次
- Graphics Peeping Unit: Exploiting EM Side-Channel Information of GPUs to Eavesdrop on Your NeighborsZihao Zhan, Zhenkai Zhang, Sisheng Liang, Fan Yao 等S&P 2022 · 被引用 41 次
- Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side ChannelTao Ni, Xiaokuan Zhang, Qingchuan ZhaoCCS 2023 · 被引用 34 次
它引用的顶会 Paper2
相关 Paper
- TEMPEST Comeback: A Realistic Audio Eavesdropping Threat on Mixed-signal SoCsJieun Choi, Hae-Yong Yang, Dong-Ho ChoCCS 2020 · 被引用 33 次
- EMSim: A Microarchitecture-Level Simulation Tool for Modeling Electromagnetic Side-Channel SignalsNader Sehatbakhsh, Baki Berkay Yilmaz, Alenka G. Zajic, Milos PrvulovicHPCA 2020 · 被引用 21 次
- Lend Me Your Ear: Passive Remote Physical Side Channels on PCsDaniel Genkin, Noam Nissan, Roei Schuster, Eran TromerUSENIX Security 2022
- Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege EscalationJiska Classen, Francesco Gringoli, Michael Hermann, Matthias HollickS&P 2022 · 被引用 16 次
- Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh InterconnectsMiles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin 等USENIX Security 2022
