维普中文期刊产品整合服务

Arm PSA-Certified IoT Chip Security: A Case Study

查看全文 作  者:Fei [1]Chen;Duming [1]Luo;Jianqiang [1]Li;Victor [1,2]C.M.Leung;Shiqi [3]Li;Junfeng [3]Fan 高影响力作者 机构地区:[1]College of Computer Science and Software Engineering,Shenzhen University,Shenzhen 518060,China;[2]Department of Electrical and Computer Engineering,the University of British Columbia,Vancouver,BC V6T 1Z4,Canada;[3]Open Security Research,Inc.,Shenzhen 518000,China高影响力机构 出  处:《Tsinghua Science and Technology》索引2023年第28卷第2期,共14页高影响力期刊 基  金:This work was partially supported by the National Natural Science Foundation of China(Nos.61872243 and U1713212);Guangdong Basic and Applied Basic Research Foundation(No.2020A1515011489);the Natural Science Foundation of Guangdong Province-Outstanding Youth Program(No.2019B151502018);Shenzhen Science and Technology Innovation Commission(No.R2020A045). 摘  要:With the large scale adoption of Internet of Things(IoT)applications in people’s lives and industrial manufacturing processes,IoT security has become an important problem today.IoT security significantly relies on the security of the underlying hardware chip,which often contains critical information,such as encryption key.To understand existing IoT chip security,this study analyzes the security of an IoT security chip that has obtained an Arm Platform Security Architecture(PSA)Level 2 certification.Our analysis shows that the chip leaks part of the encryption key and presents a considerable security risk.Specifically,we use commodity equipment to collect electromagnetic traces of the chip.Using a statistical T-test,we find that the target chip has physical leakage during the AES encryption process.We further use correlation analysis to locate the detailed encryption interval in the collected electromagnetic trace for the Advanced Encryption Standard(AES)encryption operation.On the basis of the intermediate value correlation analysis,we recover half of the 16-byte AES encryption key.We repeat the process for three different tests;in all the tests,we obtain the same result,and we recover around 8 bytes of the 16-byte AES encryption key.Therefore,experimental results indicate that despite the Arm PSA Level 2 certification,the target security chip still suffers from physical leakage.Upper layer application developers should impose strong security mechanisms in addition to those of the chip itself to ensure IoT application security. 关 键 词:Internet of Things(IoT)security chip Arm Platform Security Architecture(PSA)certification electromagnetic side-channel attack Advanced Encryption Standard(AES)encryption key leakage
相关文献

参考文献(49)

引证文献(1)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费