Title
When Reverse-Engineering Meets Side-Channel Analysis - Digital Lockpicking in Practice.
Abstract
In the past years, various electronic access control systems have been found to be insecure. In consequence, attacks have emerged that permit unauthorized access to secured objects. One of the few remaining, allegedly secure digital locking systems-the system 3060 manufactured and marketed by Simons Voss-is employed in numerous objects worldwide. Following the trend to analyze the susceptibility of real-world products towards implementation attacks, we illustrate our approach to understand the unknown embedded system and its components. Detailed investigations are performed in a step-by-step process, including the analysis of the communication between transponder and lock, reverse-engineering of the hardware, bypassing the read-out protection of a microcontroller, and reverse-engineering the extracted program code. Piecing all parts together, the security mechanisms of the system can be completely circumvented by means of implementation attacks. We present an EM side-channel attack for extracting the secret system key from a door lock. This ultimately gives access to all doors of an entire installation. Our technique targets a proprietary function (used in combination with a DES for key derivation), probably originally implemented as an obscurity-based countermeasure to prevent attacks.
Year
DOI
Venue
2013
10.1007/978-3-662-43414-7_29
Lecture Notes in Computer Science
Keywords
Field
DocType
Access control,Symmetric key cryptosystem,Digital lock,Wireless door openers,EM side-channel attack,Obscurity
Countermeasure,Key derivation function,Computer security,Lock (computer science),Computer science,Reverse engineering,Transponder (aeronautics),Microcontroller,Access control,Side channel attack
Conference
Volume
ISSN
Citations 
8282
0302-9743
2
PageRank 
References 
Authors
0.36
8
5
Name
Order
Citations
PageRank
David Oswald124020.38
Daehyun Strobel2353.22
Falk Schellenberg3276.05
Timo Kasper432527.82
Christof Paar53794442.62