ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

Smart cards arm against decryption attacks

Michael Kanellos CNET News.com

Published: 19 Apr 2004 09:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Now that it has received needed patents, Cryptography Research will embark on a more aggressive effort to license technology that can protect devices from differential power analysis, a type of decryption attack.

With differential power analysis, or DPA, a hacker monitors variations in the electrical consumption of a card that performs encryption functions -- then performs reverse analyses to determine passwords. Cryptograph Research discovered this type of attack during the 90s.

To execute a DPA attack, the device must be in the hands of the attacker. So, while a thief could use this approach to determine the password of a bank card, a more common scenario would be for a hacker to use it to unblock pay TV signals on his or her home cable box. Cryptography Research recently obtained more than 60 patents for technology it has developed to defend against these attacks.

The demand for DPA security is growing, said Cryptography Research President Paul Kocher. He estimated that between 250 million and 400 million smart cards come out annually that could be vulnerable to DPA attacks.

Additionally, DPA attacks are a common topic among researchers. Of papers presented annually at security conferences, several are generally dedicated to nuances or variations of DPA attacks, Kocher said. And although writing software to perform an attack might take a few days, a well-executed attack on an unprotected card might take only a few seconds, he said.

Some companies already have adopted Cryptography Research's security technology, since the company had been working with customers to implement its tools prior to obtaining the patents.

The company's defence techniques vary. Some of the more effective ones involve changing the encryption key inside a card on a fairly rapid basis. Doing so severely limits an attacker's ability to ferret out a password, because the underlying electrical patterns are continually changing.

Cryptography Research specialises in plugging complex, and often latent, security problems. The company is currently working with several music and film studios on piracy issues.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
63 out of 111 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Electrical Project Engineer - 400KV Hv/LV - West Midlands -12-Months

A leader within the power industry based in the West Midlands has an immediate requirement for an Electrical Project Engineer for immediate start on ...

Electrical Design Engineer - Contract West Midlands

An excellent opportunity has arisen to work for one of the countries premier firms providing electrical systems for the transport industry. The role ...

Electrical Design Engineer

Huxley associates has an immediate requirement for an Electrical Design Engineer for a client that are a major building services consultancy with a ...

Discussions

61320 61320

Bletchley Park

Saturday 17 May 2008, 9:28 AM

5 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme