1 of 41

Video-based Cryptanalysis and Side-channel attacks

Ryen Castillo and Lilian Vu

2 of 41

From the paper itself

2

Company Confidential and Proprietary

3 of 41

Summary of what this means/topics we’ll explore

3

Company Confidential and Proprietary

What new technique did the researchers discover?

  • These researchers figured out how to recover secret keys of any target device that has a power LED

How did they recover the secret keys using the power LED?

  • They examined the intensity and brightness of the device’s power LED since its related to its power consumption. They used recording devices like video cameras of smartphones and zoomed into the power LED to:
    • 1. get the limited eight bit resolution of a single RGB channel which is sufficient enough to detect the differences in the power consumption caused by the cryptographic computations.
    • 2. use the camera’s rolling shutter to upsample the sampling rate of the intensity/brightness of the power LED to the desired level needed to perform cryptanalysis.
  • With this, they leveraged existing side-channel attacks to extract the private keys

4 of 41

But first…what’s a side-channel attack?

5 of 41

Side-channel Attacks

  • By definition
    • A side-channel attack is any attack based on extra information that can be gathered because of the fundamental way a computer protocol or algorithm is implemented, rather than flaws in the design of the protocol or algorithm itself
  • What does this mean looking at?
    • Cache accesses
    • Timing
    • Power-monitoring
    • Acoustics
    • Optical
    • Software Initiated

5

Company Confidential and Proprietary

6 of 41

Some Examples

  • Meltdown
  • Spectre
  • Rowhammer
  • Lamphone
  • Keyboard Acoustics
  • Collide+Power
  • Downfall
  • Inception

6

Company Confidential and Proprietary

7 of 41

Elliptic Curve Cryptography 101

8 of 41

Let’s play pool!

  • Define our starting point A
  • A dot B = -C reflect across x axis to C
  • A dot C = -D reflect across x axis to D
  • A dot D = -E reflect across x axis to E
  • let’s do this N times and arrive at some final point P
  • Congratulations! You now have a private key and public key
  • public key: AP our initial and ending points
  • private key: N the number of hops/operations we did to arrive at this ending point.

8

Company Confidential and Proprietary

9 of 41

ECDSA

Elliptic Curve Digital Signature Algorithm (ECDSA) is a very popular digital signature

algorithm, used among others in the TLS protocol [Res18], document signing and in

blockchain application

9

Company Confidential and Proprietary

10 of 41

Minerva

11 of 41

At a glance

  • In the case of ECDSA or other signature schemes with random nonces, the bit-length of the random nonces is leaked.
  • This is much more significant as each signature then presents new usable information on the private key. The way this information is used to recover the private key is via first converting the problem to an instance of the Hidden Number Problem and solving it via lattice reduction techniques.

11

Company Confidential and Proprietary

12 of 41

Minerva

There is a G the elliptic curve generator, that generates the keys, that is multiplied by some scalar nonce k that has some bit length being leaked. By taking enough samples of this leaky nonce and signatures for known messages you ultimately can figure out the private key

12

Company Confidential and Proprietary

13 of 41

Non-leaky bits

13

Company Confidential and Proprietary

14 of 41

Athena IDProtect Leaky Bits

14

Company Confidential and Proprietary

15 of 41

Athena IDProtect Bit Length Dependency

15

Company Confidential and Proprietary

16 of 41

Athena IDProtect Powertrace

16

Company Confidential and Proprietary

Clear dynamic bound on the number of loops in scalar multiplication is visible in a powertrace of an ECDSA signing operation.

17 of 41

Hidden Numbers and Lattices

  • Voneh and Venkatsen in 1996 presented a paper, Hardness of computing the most significant bits of secret keys in Diffie-Hellman and related schemes
  • This paper introduces a method for proving the hardness of computing the most significant bits of keys in the Diffie-Hellman scheme.
  • They also showed a way to solve it by transforming it into a lattice Closest Vector Problem (CVP) solvable via lattice reduction and Babai's nearest plane algorithm.

17

Company Confidential and Proprietary

18 of 41

Adapting the Hidden Number Problem

18

Company Confidential and Proprietary

19 of 41

Solving the problem with Lattices

19

Company Confidential and Proprietary

20 of 41

Hertzbleed

21 of 41

Hertzbleed Summary

  • Real practical side-channel relying on changes in CPU frequency
    • Originally demonstrated against SIKE, accomplishing full key extraction via remote timing
    • SIKE and SIDH were deprecated due to unrelated security concerns stemming from “An efficient key recovery attack on SIDH” by Castryck and Decru from late 2022 and originally published in 2023
  • Dynamic voltage and frequency scaling (DVFS)
    • Power management scheme of modern x86 processors
    • Will adjust CPU frequency based on the data being processed
      • When under a sustained workload will modify the steady-state frequency of the CPU
      • Different performance levels (P-levels)
        • Ex P0 state has CPU run at maximum performance
      • Thermal Design Point (TDP)
        • Expected power consumption at sustained workload

21

Company Confidential and Proprietary

22 of 41

Maintaining Steady-state

22

Company Confidential and Proprietary

23 of 41

A Quick Question

23

Company Confidential and Proprietary

Which of these operations are going to run faster?

Which will consume more power?

24 of 41

Hamming Distance

24

Company Confidential and Proprietary

25 of 41

The Vulnerability Itself

  • Now we see where the vulnerability is! When running sustained workloads, CPU overall performance is capped by TDP. Under modern DVFS, it maximizes its performance by oscillating between multiple P-states. At the same time, the CPU power consumption is data-dependent. Inevitably, workloads with different power consumption will lead to different CPU P-state distribution. For example, if workload w1 consumes less power than workload w2, the CPU will stay longer in lower P-state (higher frequency) when running w1.

25

Company Confidential and Proprietary

26 of 41

In Summary

26

Company Confidential and Proprietary

27 of 41

Finally…let’s recover some keys with video

28 of 41

Rolling Shutter - Overview

The rolling shutter is an image-capturing method in which

a frame of a video (in video footage) is captured by scanning

the scene vertically/horizontally. When this method is used, a

frame/picture is not actually composed of a single snapshot of

a scene taken at a specific point in time but rather is composed

of multiple snapshots taken of vertical/horizontal pieces of

the scene at different times.

With a vertical rolling shutter, a sensor’s pixels are exposed

and read out row-by-row sequentially at different times from

top to bottom (or left to right) according to a configurable

shutter speed (E) which determines the amount of time that

the sensor is exposed to light.

Because each row (or a group

of adjacent rows) in a sensor with a rolling shutter is captured

at a different time, attackers can increase the sampling rate

from the camera’s FPS rate (60/120 FPS) to the rate at which

rows are recorded, a rate which is based on the shutter speed

29 of 41

Rolling Shutter - Experimental Setup

29

Company Confidential and Proprietary

Upsampling the FPS rate of the video camera to the shutter rate: An Arduino’s LED flickering at 4 kHz (left) is recorded by a Samsung Galaxy S22 Ultra using a lens that increases the size of the LED so that it fills the entire screen (middle). A frame of the video recorded by the smartphone that captures the 4 kHz flickering (right)

30 of 41

Minerva Experiment - Setup

30

Company Confidential and Proprietary

As seen on the left, the video camera was directed at the smart card reader (indicated by the red arrow) from 16 meters away. On the right is an image of the smart card reader’s power LED

31 of 41

Minerva Experiment - Extracting Frame Series Associated with ECDSA Signatures

Top: A series of frames that started and ended during the rolling shutter’s scanning time (a Class I series). Middle: A series of frames that started during the transition time between frames (a Class II series). Bottom: A series of frames that ended during the transition time between frames (a Class II series).

32 of 41

Minerva Experiment - Results

A heat map of the estimated execution times of 7,826 ECDSA sign operations as a function of the number of leading zero bits in the nonce.

33 of 41

Hertzbleed Experiment - Setup

The video camera of an iPhone 13 Pro Max is directed (through a lens) at the power LED of Logitech Z120 speakers that are connected to a USB hub used to charge a Samsung Galaxy S8 (which contains the SIKE key)

34 of 41

Hertzbleed Experiment - SIKE Key Recovery

The RGB values of eight SIKE iterations extracted from a video (top). Zooming in on the green channel (bottom).

35 of 41

Hertzbleed Experiment - Results

Minimum times used to extract the first 20 bits (1 to 20) and last 20 bits (358 to 377) of the SIKE key based on eight iterations.

The error detection (left) and correction (right) of bit index 33.

36 of 41

Ok cool…but what’s the catch?

37 of 41

Caveats

  • Camera distance matters!
    • At 60ft the lights need to be off in the room
    • At 6ft the lights can be on.
  • Time
    • Video needs to be captured for 65 minutes, in which the reader must constantly perform the operation
  • Requires an existing side-channel attack
    • There must be an underlying side-channel attack that leaks power consumption, timing, or other physical characteristics as the device is performing cryptographic operations

37

Company Confidential and Proprietary

38 of 41

Looking at the Future and Questions

  • These caveats seems pretty limiting, will this ever happen?
  • SIKE is now deprecated…why do we care?
  • Other questions?

38

Company Confidential and Proprietary

39 of 41

References

Nassi, Ben, et al. “Video-Based Cryptanalysis: Extracting Cryptographic Keys from Video Footage of a Device’s Power Led.” Cryptology ePrint Archive, 1 Jan. 1970, eprint.iacr.org/2023/923.

Jancar, Jan, et al. “Minerva: The Curse of Ecdsa Nonces.” Cryptology ePrint Archive, 1 Jan. 1970, eprint.iacr.org/2020/728.

Minerva, minerva.crocs.fi.muni.cz/. Accessed 18 Aug. 2023.

Wang, Yingchen. “Hertzbleed Explained.” The Cloudflare Blog, The Cloudflare Blog, 8 Aug. 2022, blog.cloudflare.com/hertzbleed-explained/.

“Video-Based Cryptanalysis.” Ben Nassi, www.nassiben.com/video-based-crypta. Accessed 18 Aug. 2023.

Nick Sullivan    -  Oct 24, 2013 8:07 pm UTC. “A (Relatively Easy to Understand) Primer on Elliptic Curve Cryptography.” Ars Technica, 24 Oct. 2013, arstechnica.com/information-technology/2013/10/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography/2/.

39

Company Confidential and Proprietary

40 of 41

Backup Slides

41 of 41

Overview

the attacker recovers secret

keys from a target device using video footage of the power

LED of the target device (i.e., a direct attack) or of the power

LED of a connected peripheral (i.e., an indirect attack) whose

power consumption is also affected by the power consumption

of the target device. The attacker exploits the correlation

between the intensity/brightness of a device’s power LED and

the device’s power consumption (which is affected by the cryp-

tographic operations performed); this correlation stems from

the fact that i many devices, the power LED is connected

directly to the power line of the device’s electrical circuit

which lacks effective means (e.g., filters, voltage stabilizers)

of decoupling the correlation. This correlation, which can be

detected by analyzing the RGB values of the device’s power

LED in video footage, is used by the attacker to perform

cryptanalysis. In order to achieve a sampling rate that can

be used for cryptanalysis, the attacker uses the video camera’s

rolling shutter to upsample the sampling rate by filling the

iii

entire frame with the LED

41

Company Confidential and Proprietary