Video-based Cryptanalysis and Side-channel attacks
Ryen Castillo and Lilian Vu
From the paper itself
2
Company Confidential and Proprietary
Summary of what this means/topics we’ll explore
3
Company Confidential and Proprietary
What new technique did the researchers discover?
How did they recover the secret keys using the power LED?
But first…what’s a side-channel attack?
Side-channel Attacks
5
Company Confidential and Proprietary
Some Examples
6
Company Confidential and Proprietary
Elliptic Curve Cryptography 101
Let’s play pool!
8
Company Confidential and Proprietary
ECDSA
Elliptic Curve Digital Signature Algorithm (ECDSA) is a very popular digital signature
algorithm, used among others in the TLS protocol [Res18], document signing and in
blockchain application
9
Company Confidential and Proprietary
Minerva
At a glance
11
Company Confidential and Proprietary
Minerva
There is a G the elliptic curve generator, that generates the keys, that is multiplied by some scalar nonce k that has some bit length being leaked. By taking enough samples of this leaky nonce and signatures for known messages you ultimately can figure out the private key
12
Company Confidential and Proprietary
Non-leaky bits
13
Company Confidential and Proprietary
Athena IDProtect Leaky Bits
14
Company Confidential and Proprietary
Athena IDProtect Bit Length Dependency
15
Company Confidential and Proprietary
Athena IDProtect Powertrace
16
Company Confidential and Proprietary
Clear dynamic bound on the number of loops in scalar multiplication is visible in a powertrace of an ECDSA signing operation.
Hidden Numbers and Lattices
17
Company Confidential and Proprietary
Adapting the Hidden Number Problem
18
Company Confidential and Proprietary
Solving the problem with Lattices
19
Company Confidential and Proprietary
Hertzbleed
Hertzbleed Summary
21
Company Confidential and Proprietary
Maintaining Steady-state
22
Company Confidential and Proprietary
A Quick Question
23
Company Confidential and Proprietary
Which of these operations are going to run faster?
Which will consume more power?
Hamming Distance
24
Company Confidential and Proprietary
The Vulnerability Itself
25
Company Confidential and Proprietary
In Summary
26
Company Confidential and Proprietary
Finally…let’s recover some keys with video
Rolling Shutter - Overview
The rolling shutter is an image-capturing method in which
a frame of a video (in video footage) is captured by scanning
the scene vertically/horizontally. When this method is used, a
frame/picture is not actually composed of a single snapshot of
a scene taken at a specific point in time but rather is composed
of multiple snapshots taken of vertical/horizontal pieces of
the scene at different times.
With a vertical rolling shutter, a sensor’s pixels are exposed
and read out row-by-row sequentially at different times from
top to bottom (or left to right) according to a configurable
shutter speed (E) which determines the amount of time that
the sensor is exposed to light.
Because each row (or a group
of adjacent rows) in a sensor with a rolling shutter is captured
at a different time, attackers can increase the sampling rate
from the camera’s FPS rate (60/120 FPS) to the rate at which
rows are recorded, a rate which is based on the shutter speed
Rolling Shutter - Experimental Setup
29
Company Confidential and Proprietary
Upsampling the FPS rate of the video camera to the shutter rate: An Arduino’s LED flickering at 4 kHz (left) is recorded by a Samsung Galaxy S22 Ultra using a lens that increases the size of the LED so that it fills the entire screen (middle). A frame of the video recorded by the smartphone that captures the 4 kHz flickering (right)
Minerva Experiment - Setup
30
Company Confidential and Proprietary
As seen on the left, the video camera was directed at the smart card reader (indicated by the red arrow) from 16 meters away. On the right is an image of the smart card reader’s power LED
Minerva Experiment - Extracting Frame Series Associated with ECDSA Signatures
Top: A series of frames that started and ended during the rolling shutter’s scanning time (a Class I series). Middle: A series of frames that started during the transition time between frames (a Class II series). Bottom: A series of frames that ended during the transition time between frames (a Class II series).
Minerva Experiment - Results
A heat map of the estimated execution times of 7,826 ECDSA sign operations as a function of the number of leading zero bits in the nonce.
Hertzbleed Experiment - Setup
The video camera of an iPhone 13 Pro Max is directed (through a lens) at the power LED of Logitech Z120 speakers that are connected to a USB hub used to charge a Samsung Galaxy S8 (which contains the SIKE key)
Hertzbleed Experiment - SIKE Key Recovery
The RGB values of eight SIKE iterations extracted from a video (top). Zooming in on the green channel (bottom).
Hertzbleed Experiment - Results
Minimum times used to extract the first 20 bits (1 to 20) and last 20 bits (358 to 377) of the SIKE key based on eight iterations.
The error detection (left) and correction (right) of bit index 33.
Ok cool…but what’s the catch?
Caveats
37
Company Confidential and Proprietary
Looking at the Future and Questions
38
Company Confidential and Proprietary
References
Nassi, Ben, et al. “Video-Based Cryptanalysis: Extracting Cryptographic Keys from Video Footage of a Device’s Power Led.” Cryptology ePrint Archive, 1 Jan. 1970, eprint.iacr.org/2023/923.
Jancar, Jan, et al. “Minerva: The Curse of Ecdsa Nonces.” Cryptology ePrint Archive, 1 Jan. 1970, eprint.iacr.org/2020/728.
Minerva, minerva.crocs.fi.muni.cz/. Accessed 18 Aug. 2023.
Wang, Yingchen. “Hertzbleed Explained.” The Cloudflare Blog, The Cloudflare Blog, 8 Aug. 2022, blog.cloudflare.com/hertzbleed-explained/.
“Video-Based Cryptanalysis.” Ben Nassi, www.nassiben.com/video-based-crypta. Accessed 18 Aug. 2023.
Nick Sullivan - Oct 24, 2013 8:07 pm UTC. “A (Relatively Easy to Understand) Primer on Elliptic Curve Cryptography.” Ars Technica, 24 Oct. 2013, arstechnica.com/information-technology/2013/10/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography/2/.
39
Company Confidential and Proprietary
Backup Slides
Overview
the attacker recovers secret
keys from a target device using video footage of the power
LED of the target device (i.e., a direct attack) or of the power
LED of a connected peripheral (i.e., an indirect attack) whose
power consumption is also affected by the power consumption
of the target device. The attacker exploits the correlation
between the intensity/brightness of a device’s power LED and
the device’s power consumption (which is affected by the cryp-
tographic operations performed); this correlation stems from
the fact that i many devices, the power LED is connected
directly to the power line of the device’s electrical circuit
which lacks effective means (e.g., filters, voltage stabilizers)
of decoupling the correlation. This correlation, which can be
detected by analyzing the RGB values of the device’s power
LED in video footage, is used by the attacker to perform
cryptanalysis. In order to achieve a sampling rate that can
be used for cryptanalysis, the attacker uses the video camera’s
rolling shutter to upsample the sampling rate by filling the
iii
entire frame with the LED
41
Company Confidential and Proprietary