Defeating the smartcard code-crackers

Smart as they are, the protective codes of smart cards can be cracked using off-the-shelf technology. But the latest secure chips developed by one European team may soon frustrate hackers and thieves. Produced using a new and much faster design process, these chips can withstand more attacks than before.

Some two million new smartcards are rolled out every month, so the encrypted personal data that people store on these cards must be safe. And to date it has been. Yet the security threat is growing, as the electronic devices capable of breaking the card codes become cheaper and more powerful.

"It takes little more than an oscilloscope and a standard PC to mount a digital attack on an unprotected smartcard," says Klaus-Michael Koch. He is coordinator of the IST project SCARD, which aims to increase the security of chips on smart cards.

With equipment like this and some know-how, attackers can expose the content that a smart card is supposed to protect. Using techniques such as side-channel analysis (SCA), they can reveal part of a secret key, notably by examining a chip's power leakage as it performs computations or by scrutinising its thermal or electromagnetic radiation. If the card's owner is the attacker, he or she could upload money to an electronic purse, access a satellite TV system for free or claim to be someone else.

Improved design flow
Under SCARD, the partners wanted to put together a 'design flow' that allows semi-automatic implementation of countermeasures. The design flow is the digital design of a chip – the specifications, modelling of performance, algorithms and functionality up until the stage when the chip developer can start the synthesizer and compiler. Typically, this design process is costly and may take several years.

In-chip countermeasures must be included during the design period. They cannot be simulated, so developers must experiment with the shielding of a card's chip to limit temperature and voltage variations, or they must laboriously place transistors on it by hand.

For the hardware security issue, the partners developed prototypes of a design flow and carried out chip testing. They also paved the way for an automatic chip design process which would allow other companies to develop new and more secure chips.

"We succeeded in making the hardware more secure against side-channel analysis (SCA)," says Koch. "The chip we built was used to deduce the measurability limits, enabling us to assess the sort of countermeasures necessary against differential power attacks."

Countermeasures mask chip contents
To tackle leaky circuits, the SCARD partners developed two main countermeasures. The first introduces circuits with constant power consumption, irrespective of the tasks being performed. Says Koch, "Each clock cycle has the same energy. But these circuits must be perfectly executed, since even a three or four percent difference in energy can be seen." The second involves adding random values to the chip, masking the circuit's real values. Noise could also be added, though this is not currently feasible in smartcards due to energy-loss restrictions.

They have also developed an eight-bit test chip, featuring both unprotected and (seven) protected versions of the same circuit. The chip includes a microcontroller, is fully programmable and has reduced leakage. It is also capable of resisting over 500,000 attempted measurements, as opposed to the 15,000-measurement threshold for an ordinary (unprotected) chip. As a result, researchers can for the first time directly compare the effect of certain countermeasures on unprotected or protected versions of the same circuit on the same chip.

"Our new chip is not one hundred percent secure," acknowledges Koch. "However, it is far more difficult to crack than existing unprotected versions and represents a quantum leap forward in security." Though the project is now over, further research will be conducted on the remaining 25 test chips.

The new chip was produced using the project's own design flow, taking just one year from specification to production. "We demonstrated that our chip design flow – our set of tools and methods – really works," he notes.

Patents applied for
Two partners, Institut für Angewandte Informationsverarbeitung und Kommunikationstechnologie (IAIK, Austria) and Infineon, have applied for international patents stemming from their project work. These include countermeasures with new secure logic styles that cover innovative transistor circuits. Some of the countermeasure technology developed is also being used in IAIK's security crypto-modules.

The project results are now being disseminated through teaching – since some of the project partners are universities or technical small and medium-sized enterprises. A recent workshop in Louvain-la-Neuve, Belgium, to present SCARD's results attracted some 100 security-industry experts.

Contact:
Klaus-Michael Koch
Director of Research and Development
Technikon Forschungs- und Planungsgesellschaft mbH
Richard-Wagner-Str. 7
A-9500 Villach
Austria
Tel: +43 424 223355
Fax: +43 424 223355-77
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Source: IST Results Portal

Most Popular Now

Oracle Buys Cerner

Oracle Corporation (NYSE: ORCL) and Cerner Corporation jointly announced an agreement for Oracle to acquire Cerner through an all-cash tender offer for $95.00 per share, or approximately $28.3 billion in...

Philips and IJsselland Hospital Sign Lon…

Royal Philips (NYSE: PHG, AEX: PHIA), a global leader in health technology, today announced it has signed a 12-year strategic partnership with IJsselland Hospital (Capelle aan den Ijssel, The Netherlands)...

Computer Programs and Mobile Apps may He…

The COVID-19 pandemic has had a major impact on mental health across the globe. Depression is predicted to be the leading cause of lost life years due to illness by...

AI Points the Way to Better Doctor-Patie…

A computer analysis of hundreds of thousands of secure email messages between doctors and patients found that most doctors use language that is too complex for their patients to understand...

Could EKGs Help Doctors use AI to Detect…

Pulmonary embolisms are dangerous, lung-clogging blot clots. In a pilot study, scientists at the Icahn School of Medicine at Mount Sinai showed for the first time that artificial intelligence (AI)...

Mayo Clinic Researchers Use AI, Biomarke…

Treatment options for rheumatoid arthritis have often relied on trial and error. Now Mayo Clinic researchers are exploring the use of artificial intelligence (AI) and pharmacogenomics to predict how patients...

Open Call DIGITAL-2021-DEPLOY-01-TWINS-H…

The development of digital twins in healthcare (DTH) has progressed substantially, profiting from advances in science and technology. In order to exploit their benefits in view of better prevention approaches...

Computer Model of Blood Enzyme

Membrane-associated proteins play a vital role in a variety of cellular processes, yet little is known about the membrane-association mechanism. Lipoprotein-associated phospholipase A2 (Lp-PLA2) is one such protein with an...

Mjog by Livi Launches Remote Monitoring …

Mjog by Livi has launched a remote monitoring tool that will help GPs support and monitor people with depression through messages sent to their smartphones. The latest data from the Office...

4.5 Million Euros in EU Funding for Saar…

This year, three computer scientists from Saarbrücken were awarded an "ERC Starting Grant" by the European Research Council. This award, endowed with 1.5 million euros each, is among the most...

2022 EU4Health Work Programme Adopted to…

Today the Commission has adopted the second EU4Health work programme. In 2022, the EU4Health will continue to invest in building stronger, more resilient health systems and pave the way for...

Five NHS Trusts in Surrey and Sussex to …

A consortium of NHS trusts that covers a population of circa 1.2 million will gain immediate access to important patient imaging, and will mobilise a regional workforce for patients, following...