Evaluation de la sécurité physique des SoC

Thomas Trouchkine · HAL (Le Centre pour la Communication Scientifique Directe) · 2021

Since the democratization of mobile devices, sensitive operations likepayment, identification or healthcare, usually done using securityevaluated smartcards, are handled by these devices. However, mo-bile devices neither are designed for security nor security evaluated.Therefore, their resistance against powerful attacks, like physical at-tacks is questionable.In this thesis, we aim at evaluating the security of mobile devicesagainst physical attacks, in particular perturbation attacks. These at-tacks aims at modifying the execution environment of the device to in-duce bugs during its computation. These bugs are called faults. Thesefaults can compromise the security of a device by allowing the crypt-analysis of its secret or forcing an unauthorized authentication forinstance.Mobile devices are powered by modern processors, which are theheart of this work, and are never evaluated against fault attacks. How-ever, our knowledge about fault attacks on smartcards is not rele-vant as the processors powering smartcards are way less complex,in terms of number of modules, technology node and optimizationmechanisms, than modern processors.Regarding this situation, we aim at providing rationals on the se-curity of modern processors against fault attacks by defining a faultcharacterization method, using it on representative modern proces-sors and analyzing classical security mechanisms against the charac-terized faults.We characterized three devices, namely the BCM2837, BCM2711b0and the Intel Core i3-6100T against fault attacks using two differentinjection mediums: electromagnetic perturbations and a laser. We de-termined that these devices, despite having different architecture andusing different mediums are faulted in similar ways. Most of the time,a perturbation on these devices modify their executed instructions.As this is a powerful fault, we also analyzed classical security mech-anisms embedded in such devices. We successfully realized a dif-ferential fault analysis on the AES implementation of the OpenSSLlibrary, which is used in every Linux based operating system. Wealso analyzed the Linux user authentication process involved in thesudo program. This work highlights the lack of tools to efficiently ana-lyze Linux programs, which are rather complex with dynamic linkingmechanisms, against fault attacks.

Read the paper · More papers on PaperTik