Hardwear.io NL 2023 | Triple Exploit Chain With Laser Fault Injection On A Secure Element - Olivier

แชร์
ฝัง
  • เผยแพร่เมื่อ 26 พ.ย. 2023
  • We identified a new vulnerability allowing an attacker to extract internal EEPROM masking keys using a very long laser pulse while the circuit is running. The knowledge of those keys leverage two new attacks that we also identified during this work, which are authentication and session key derivation hijacking. To achieve this, EEPROM data readout by the processor is overridden using laser illumination. By chaining all three attacks, we were able to access a protected secret key. This was applied to a real device, a hardware wallet for which we managed to extract the seed, but this chip is also widely used in many IoT applications. This attack may be applicable to the previous revisions as well.
    This work was conducted in a black box approach, with background experience of previous attacks on less secure devices from this family. Due to the very high number of faults required to retrieve the secret key, it is to this day the most complex multiple laser fault injection attack ever presented.
    Finally, to prove that we were able to perform this attack, the hardware wallet manufacturer using this secure element sent us three devices to break as a challenge. Sample preparation was risky, and we broke two wallets when trying to desolder the circuits or decapsulate the packages to access the silicon. We will, in addition to the laser attack, present hints and tricks we developed to overcome these practical difficulties, resulting in the successful wallet seed recovery of the last remaining challenge wallet !
    #hw_ioNL2023 #faultinjection #IoT
    -------------------------------------------------------------------------------------------------------------------------------------------------------
    Website: hardwear.io
    X : / hardwear_io
    LinkedIn: / hardwear.io-hardwarese...
    Facebook: / hardwear.io
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 2

  • @WhatYouHaventSeen
    @WhatYouHaventSeen 8 หลายเดือนก่อน +2

    Very impressive work. Well done!

  • @rodsilva80
    @rodsilva80 8 หลายเดือนก่อน

    Well done!