Beyond Cryptanalysis is Software Security the Next Threat for Smart Cards - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2015

Beyond Cryptanalysis is Software Security the Next Threat for Smart Cards

Résumé

Smart cards have been considered for a long time as a secure container for storing secret data and executing programs that manipulate them without leaking any information. In the last decade, a new form of attack that uses the hardware has been intensively studied. We have proposed in the past to pay attention also to easier attacks that use only software. We demonstrated through several proof of concepts that such an approach should be a threat under some hypotheses. We have been able to execute self-modifying code, return address programming and so on. More recently we have been able to retrieve secret keys belonging to another application. Then all the already published attacks should have been a threat but the industry increased the counter measures to mitigate for each of the published attack. In such a sensitive domain, we always submit the attacks to the industrial partners but also national agencies before publishing any attack. Within such an approach, they have been able to patch their system before any vulnerabilities should be exploited.
Fichier principal
Vignette du fichier
InvitedTalk.pdf (204.21 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01250585 , version 1 (05-01-2016)

Identifiants

Citer

Jean-Louis Lanet. Beyond Cryptanalysis is Software Security the Next Threat for Smart Cards. C2SI 2015 - First International Conference Codes, Cryptology, and Information Security, May 2015, Rabat, Morocco. pp.74-82, ⟨10.1007/978-3-319-18681-8_6⟩. ⟨hal-01250585⟩
263 Consultations
170 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More