SIM cards

AES-128 encrypted on SIM cards broke

In February of 2015, Edward Snowden revealed that NSA and GCHQ had breached one of the world's largest SIM card manufacturers to clone cards and crack encryption. But a presentation at Black Hat shows that not all of them really needed it.sim cards

Ο Yu Yu (yes, this is my real name, joked the researcher) is a professor of research at Shanghai Jiao Tong University. The researcher has gone through the past few years trying to learn how he can break the encryption codes on 3G and 4G cards.

These cards use AES-128, an encryption that is supposed to be impenetrable by brute force attacks. As it turns out, however, it is easy to break using channel analysis.

Side-channel attacks measure and analyze data such as consumption , τις ηλεκτρομαγνητικές εκπομπές, και την παραγωγή θερμότητας. Με την ανάλυση αυτών των δεδομένων ο ερευνητής μπορεί να μάθει τι ακριβώς συμβαίνει σε ένα chip.

The technique has existed for years, and requires physical access to the target machine.

Yu and his team used an oscilloscope to monitor power levels, a MP300-SC2 protocol for data traffic monitoring, a self-built SIM card reader, and a standard PC to match the results.

With the above they managed to break eight commercial SIM cards in 80 minutes.

The system could of course not read the encryption key directly from the cards. Instead, the research team isolated 256 sections of the key and sent them to those shown by the action of the SIM card.

This of course requires calculations and a bit of luck. But once they perfected the system it became comparatively much easier to break them encryption and clone the card.

Yu proved that cloned SIM cards can successfully imitate the original ones. It also showed how a cloned card could change the password to the Alipay service (one of the largest 3rd party payment system in ) και, ενδεχομένως, να αδειάσει τον .

The hack demonstrated the need for more security for mobile phone users, Yu said.

Given its speed and convenience s intelligence agencies will be very interested in Yu's technique.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).