Home News Latest Security News Infineon DRM/encryption chip succumbs to physical attack

Infineon DRM/encryption chip succumbs to physical attack

Security researcher Christopher Tarnovsky has successfully subverted an Infineon SLE 66 microcontrollera hardware component that implements the Trusted Platform Module (TPM) specification. His method of attack, which requires physical access to the hardware, was presented at the Black Hat conference. TPM chips can be used for a variety of purposes, but are principally employed for data encryption or DRM. Infineon is a well-known TPM manufacturer whose components are shipped in mainstream computing and consumer electronics products including the Xbox 360 ...


Security researcher Christopher Tarnovsky has successfully subverted an Infineon SLE 66 microcontroller—a hardware component that implements the Trusted Platform Module (TPM) specification. His method of attack, which requires physical access to the hardware, was presented at the Black Hat conference.

TPM chips can be used for a variety of purposes, but are principally employed for data encryption or DRM. Infineon is a well-known TPM manufacturer whose components are shipped in mainstream computing and consumer electronics products including the Xbox 360 and many modern Apple computers. The basic concept behind a TPM is that it has "write-only" memory. A cryptographic key is baked into the chip when it is manufactured. This key can be used to decrypt data, but is only accessible to the chip itself and can't be read.

Infineon integrates relatively sophisticated security mechanisms into the hardware in order to repel a wide range of conceivable physical attacks, thus preventing a third party from reading the embedded key. The SLE 66 is designed to protect against EM snooping, various kinds of side channel attacks, and pretty much any other conventional approach that you can think of.

In order to circumvent the SLE 66's security, Tarnovsky used an electron microscope and needles. After nine months of intricate work, he managed to pull out the "write-only" data. He says that he has reported his findings to Infineon and the Trusted Computing Group, the organization that devised the TPM standard.



Read Full Article

Written on Friday, 12 February 2010 03:31 by

Viewed 76 times so far.
Like this? Tweet it to your followers!

Latest articles from

Latest 'tweets' from GovernmentSecurity


 

Information Security Resources

Latest Articles

Security Log Management Tips

News image

The security log for Windows is full of great information, but unless you know how to control, manage, and analyze the information, it is going to take you much longer ...

GSO | Thursday, 26 August 2010 | Hits: 136

Read more

GFI LANguard - Voted WindowSecurity.com

Winner in the Patch Management Category of Readers’ Choice Awards: GFI LANguard August 25, 2010 - GFI LANguard was selected the winner in the Patch Management category of the WindowSecurity.com Readers’ Choice Awards. Ecora Patch Manager and ...

GSO | Wednesday, 25 August 2010 | Hits: 104

Read more

Product Review: ObserveIT

News image

Product: ObserveIT Remote Access Auditor Product Homepage:click here When dealing with a security issue or compliance audit, your server logs are often the most important asset you have ...

GSO | Wednesday, 18 August 2010 | Hits: 169

Read more

Latest News

Scammers using IM to deliver "IQ Test" s

News image

An IM variant of the well-known "Solve the IQ test, get your results on you mobile phone" scam has been spotted by a Trend Micro analyst. He received a couple ...

GSO | Friday, 3 September 2010 | Hits: 52

Read more

Facebook boosts security by adding remot

Following the May rollout of the security feature that made it possible for Facebook users to be notified of unapproved account access, the social network announced another one that will ...

GSO | Friday, 3 September 2010 | Hits: 21

Read more

Trojan attacks remain widespread

News image

GFI's statistics for the month of August show that users were under attack throughout the month primarily by the same Trojan horse programs that have persisted for several months. Trojans ...

GSO | Friday, 3 September 2010 | Hits: 43

Read more

Latest Blogs

Welcome

Welcome to GovernmentSecurity.org Network security articles and hacking prevention resources for the government and general public. Covering all aspects of Computer Hacking, including tutorials and exploit do...

Stephen | Friday, 30 April 2010 | Hits: 1211

Read more

Main Site Alternate Colors

As many of you have noticed we recently launched a new design after receiving many complaints about ...

Stephen | Tuesday, 19 January 2010 | Hits: 1482

Read more

We have launched the new GovernmentSecur

News image

We decided to launch the new site, though we have not completed all the planned fe...

GSO | Saturday, 10 October 2009 | Hits: 3577

Read more

Syndicate





Member Login



Other Links

Latest Exploits