TEMPEST Comeback: A Realistic Audio Eavesdropping Threat on Mixed-signal SoCs
Jieun Choi, Hae-Yong Yang, Dong-Ho Cho
摘要
This study presents a new TEMPEST threat that an attacker can surreptitiously obtain original plain audio information from a distance by exploiting recently emerging unintentional electromagnetic (EM) radiations. As lightweight sensor-based Internet of things (IoT) services become widespread, a mixed-signal system on chip (MSoC) spontaneously integrates all components, such as digital, analog, and even power circuits, into a single chipset to minimize the size of IoT devices. Accordingly, we pay attention to the accelerated integration of a switching regulator (SWREG), which is one of the typical power circuits and may substantially increase the unintentional EM leakages, re-enabling the audio TEMPEST attack. In this paper, we posit that a root cause of new audio coupled EM leakages is the unavoidable integration of SWREG which innately has strong and low-frequency (i.e., several MHz) switching noises; an audio signal is conductively coupled on the single common substrate of an MSoC with a system clock and the newly emerging the SWREG noises. The unique features of the suggested EM leakages compared to previous leakages are that their frequency distribution is dense (i.e., at frequency intervals of the SWREG noise), wideband (i.e., from several MHz to over 1 GHz), and static (i.e., time-invariant center frequencies). These features make the new TEMPEST attack due to the SWREG noise have a longer attack range and be more robust to interferences. Consequently, the presented TEMPEST attack becomes considerably practical. To verify the new TEMPEST attack due to the SWREG noise, we first perform a feasibility analysis by measuring and analyzing the audio-conveyed EM emanations of the popular MSoCs in an anechoic chamber. Next, we demonstrate how critical and practical the threat is by capturing the leakages from the commercial devices in an office environment. Furthermore, we propose a new signal reinforcement method with the three benefits (dense, wideband, and static) of the suggested radiations: the spectral addition of phase-aligned signals. The experimental results show that the test sweep tones of the Sogou voice recorder (nRF52810 chipset) and Xiaomi earbuds (CSR8640 chipset) can be reconstructed over 10 meters. Additionally, an attack feasibility analysis on digital signal (I2C) is performed in a short-range. The overall results indicate that the new TEMPEST attack becomes more practical than the previous side-channel analysis. Finally, we suggest several technical countermeasures that help to design safe IoT devices.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper15
- mmEve: eavesdropping on smartphone's earpiece via COTS mmWave deviceChao Wang, Feng Lin, Tiantian Liu, Kaidi Zheng 等MobiCom 2022 · 被引用 60 次
- MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage SignalsRui Xiao, Tianyu Li, Soundarya Ramesh, Jun Han 等MobiCom 2023 · 被引用 20 次
- TickTock: Detecting Microphone Status in Laptops Leveraging Electromagnetic Leakage of Clock SignalsSoundarya Ramesh, Ghozali Suhariyanto Hadi, Sihun Yang, Mun Choon Chan 等CCS 2022 · 被引用 11 次
- mmEar: Push the Limit of COTS mmWave Eavesdropping on HeadphonesXiangyu Xu, Yu Chen, Zhen Ling, Li Lu 等INFOCOM 2024 · 被引用 9 次
- EchoLight: Sound Eavesdropping based on Ambient Light ReflectionGuoming Zhang, Zhijie Xiang, Heqiang Fu, Yanni Yang 等INFOCOM 2024 · 被引用 9 次
相关 Paper
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes 等CCS 2018 · 被引用 186 次
- TEMPEST-LoRa: Cross-Technology Covert CommunicationXieyang Sun, Yuanqing Zheng, Wei Xi, Zuhao Chen 等CCS 2025 · 被引用 2 次
- Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware NonlinearityHaoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang 等USENIX Security 2026
- Glowworm Attack: Optical TEMPEST Sound Recovery via a Device's Power Indicator LEDBen Nassi, Yaron Pirutin, Tomer Cohen Galor, Yuval Elovici 等CCS 2021
- Sound of Interference: Electromagnetic Eavesdropping Attack on Digital Microphones Using Pulse Density ModulationArifu Onishi, S. Hrushikesh Bhupathiraju, Rishikesh Bhatt, Sara Rampazzi 等USENIX Security 2025
