SIM cards

AES-128 encrypted on SIM cards broke

In February 2015, Edward Snowden revealed that the NSA and GCHQ had hacked into one of the world's largest SIM card manufacturers to clone cards and break encryption. But a presentation at shows that it was not all that really needed.sim cards

Ο Yu Yu (yes, that's my real name, the researcher joked) is a research professor at Shanghai Jiao Tong University. The researcher has spent the last few years trying to find out how the encryption codes on the 3G and 4G cards.

These cards use AES-128, an encryption that is supposed to be impenetrable by brute force attacks. As it turns out, however, it is easy to break using channel analysis.

Side-channel attacks measure and analyze data such as power consumption, electromagnetic emissions, and heat generation. By analyzing these data the researcher can learn what exactly is happening on a chip.

Η υπάρχει εδώ και χρόνια, και απαιτεί φυσική πρόσβαση στο - Target.

Yu and his team used an oscilloscope to monitor power levels, an MP300-SC2 protocol analyzer to of data traffic, a homemade SIM card reader, and a standard PC to correlate the results.

With the above they managed to break eight commercial SIM cards in 80 minutes.

The system could of course not read the encryption key directly from the cards. Instead, the research team isolated 256 sections of the key and sent them to those shown by the action of the SIM card.

This of course requires calculations and a little luck. But as soon as the system was fine-tuned it was much easier to break the encryption keys and clone the card.

Yu has proved that cloned SIM cards can successfully imitate authentic ones. It also showed how a cloned card could change the Alipay service password (one of China's largest 3rd party payment system) and eventually empty the account.

The hack demonstrated the need for more security for mobile phone users, Yu said.

Given the speed and ease of the violation, intelligence services will be very interested in Yu's technique.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).