Boffins: Mixed-signal silicon can SCREAM your secrets to all

'Screaming Channels', a side-channel baked into off-the-shelf Wi-Fi, Bluetooth silicon


Side-channel radio attacks just got a whole lot worse: a group of researchers from Eurecom's Software and Systems Security Group has extracted crypto keys from the noise generated by ordinary communications chips.

Unlike more esoteric side-channels, which often need physical access to a target machine or some kind of malware implant, this leak comes from radio devices working as intended by the maker. If an SoC packs analogue and digital operations on the same die, the CPU's operations inevitably leak to the radio transmitter, and can be traced from a distance.

As Tom Hayes of Eurecom wrote to El Reg in an email: “This type of leak is carried by the device's intended radio signal, and thus broadcast over a potentially longer distance” [than previous side-channel attacks].

You seen him? Hasidim

How to quietly slurp sensitive data wirelessly from an air-gapped PC

READ MORE

“In our work we have demonstrated over-the-air extraction of AES keys from a consumer-grade bluetooth device over a distance of 10 meters”, Hayes continued.

The paper describing their work, “Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers”, explains that the physical mechanism involved is very simple. “Leakage from digital logic is inadvertently mixed with the radio carrier, which is amplified and then transmitted by the antenna”, because “mixed-signal chips include both digital circuits and analog circuits on the same silicon die in close physical proximity,” the paper says.

That crosstalk between CPU and radio allowed the group to recover the AES-128 key from tinyAES from 10 metres away, and - using a correlation attack - they claimed to grab the AES-128 key in mbedTLS at a distance of one meter. Ouch.

To demonstrate that this isn't vendor-specific (for example, the result of bad design), the researchers tested the nRF52832, a Bluetooth low-energy chip from Nordic Semiconductor; and a Qualcomm Atheros AR9271, a Wi-Fi USB dongle.

As the spectrograph below shows, the ten rounds of an AES-128 negotiation are easy to identify in the “noise” coming from the Bluetooth LE chip:

Radio trace of an AES-128 negotiation

The ten rounds of AES-128 setup are clearly visible in this radio trace. Image: Eurecom, "Screaming Channels"

Because the digital noise is picked up and amplified by the radio circuits, it can travel a useful distance. The researchers achieved key recovery over 10 metres in an anechoic chamber, but they note that with more development, others could improve on their results.

With a trace captured and cleaned up, the researchers wrote, pre-existing key-recovery tools like https://newae.com/tools/chipwhisperer/ ChipWhisperer recovered the AES encryption keys with only small modifications.

The group has published its paper here, and its code is available at GitHub.

The paper will be presented at BlackHat in August, and at the ACM's Conference on Computer and Communications Security in October.

The team included Giovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes and Aurélien Francillon, all from Eurecom. ®


Other stories you might like

  • Talos names eight deadly sins in widely used industrial software
    Entire swaths of gear relies on vulnerability-laden Open Automation Software (OAS)

    A researcher at Cisco's Talos threat intelligence team found eight vulnerabilities in the Open Automation Software (OAS) platform that, if exploited, could enable a bad actor to access a device and run code on a targeted system.

    The OAS platform is widely used by a range of industrial enterprises, essentially facilitating the transfer of data within an IT environment between hardware and software and playing a central role in organizations' industrial Internet of Things (IIoT) efforts. It touches a range of devices, including PLCs and OPCs and IoT devices, as well as custom applications and APIs, databases and edge systems.

    Companies like Volvo, General Dynamics, JBT Aerotech and wind-turbine maker AES are among the users of the OAS platform.

    Continue reading
  • Despite global uncertainty, $500m hit doesn't rattle Nvidia execs
    CEO acknowledges impact of war, pandemic but says fundamentals ‘are really good’

    Nvidia is expecting a $500 million hit to its global datacenter and consumer business in the second quarter due to COVID lockdowns in China and Russia's invasion of Ukraine. Despite those and other macroeconomic concerns, executives are still optimistic about future prospects.

    "The full impact and duration of the war in Ukraine and COVID lockdowns in China is difficult to predict. However, the impact of our technology and our market opportunities remain unchanged," said Jensen Huang, Nvidia's CEO and co-founder, during the company's first-quarter earnings call.

    Those two statements might sound a little contradictory, including to some investors, particularly following the stock selloff yesterday after concerns over Russia and China prompted Nvidia to issue lower-than-expected guidance for second-quarter revenue.

    Continue reading
  • Another AI supercomputer from HPE: Champollion lands in France
    That's the second in a week following similar system in Munich also aimed at researchers

    HPE is lifting the lid on a new AI supercomputer – the second this week – aimed at building and training larger machine learning models to underpin research.

    Based at HPE's Center of Excellence in Grenoble, France, the new supercomputer is to be named Champollion after the French scholar who made advances in deciphering Egyptian hieroglyphs in the 19th century. It was built in partnership with Nvidia using AMD-based Apollo computer nodes fitted with Nvidia's A100 GPUs.

    Champollion brings together HPC and purpose-built AI technologies to train machine learning models at scale and unlock results faster, HPE said. HPE already provides HPC and AI resources from its Grenoble facilities for customers, and the broader research community to access, and said it plans to provide access to Champollion for scientists and engineers globally to accelerate testing of their AI models and research.

    Continue reading

Biting the hand that feeds IT © 1998–2022