4 ms·
I seem to be missing something that makes this unlikely. Most chips have a capacitor across the power pins. That would tend to "integrate" the signal. Recent
by daly 3y ago
I seem to be missing something that makes this unlikely.
Most chips have a capacitor across the power pins. That would tend to "integrate" the signal.
Recent chips operate at sub-volt values but the LED is in the 2+ volt range so they likely are on different rails of the power supply or have buck/boost circuits.
Even trivial designs don't use full in-order processing so multiple ADDs might overlap a MULT. This ain't your father's first processor.
The traces on the board, if not carefully designed, likely have reflection and ringing effects, especially at via points making the signal rather noisy.
Processors are running in the nano/pico range but the led/camera likely can't reach that resolution.
At these speeds the resistor-to-ground circuit on the LED would have capactive and inductive effects that would be hard to model and need to be pre-measured.
If it is a near-field (touch card) key then there are a lot of other noise sources including other chips and circuit trace induced voltages.
Cryptographic coprocessors in Verilog/VHDL are available as open source or vendor IP. They won't leak.
I could construct a "bench level test" that MIGHT be able to detect the computation but I'd need a really good oscilloscope on a well engineered circuit board knowing the exact specs of the processor and knowledge of the algorithm used.
Oh, and as mentioned, nobody who knows anything about crypto already knows and protects against timing/power attacks.
- tjoff 3y ago> Processors are running in the nano/pico range but the led/camera likely can't reach that resolution. You don't need a lot of precision to get enough hints of a key to be able to brute-force the rest. > Oh, and as mentioned, nobody who knows anything about crypto already knows and protects against timing/power attacks. Sounds like this could never be a problem then! But it is.
- dvwobuq 3y ago> I could construct a "bench level test" that MIGHT be able to detect the computation No need. The author of the original paper already did that for you. https://eprint.iacr.org/2023/923 https://eprint.iacr.org/2023/923 "We demonstrate the application of video-based cryptanalysis by performing two side-channel cryptanalytic timing attacks and recover: (1) a 256- bit ECDSA key from a smart card by analyzing video footage of the power LED of a smart card reader via a hijacked Internet-connected security camera located 16 meters away from the smart card reader, and (2) a 378-bit SIKE key from a Samsung Galaxy S8 by analyzing video footage of the power LED of Logitech Z120 USB speakers that were connected to the same USB hub (that was used to charge the Galaxy S8) via an iPhone 13 Pro Max." To all the EEs out there. PSRR and power supply cross talk is a thing...
- hulitu 3y ago> To all the EEs out there. PSRR and power supply cross talk is a thing... Damn, i have to cover my hdd led on the computer case so the neighbours do not see the pornos that i watch. /s