Technology Review - Published By MIT
Advertisement

TR Editors' blog

Insights, opinions, and our editors' analysis of the latest in emerging technologies.

Blog Topics

Recent Posts

Recent Comments

  • nancy16 : When doing research on cancer. Scientist should not indulge in whether the cancer was inherited...
  • david k : There is strong history of the street view as art.  Ed Ruscha took photos along the Sunset Strip...
  • chimenti : Under NADIN what procedure does a pilot follow for submitting a flight plan and how is the...
  • fiberman : How amusing. A contributor to the WSJ suggests eating your fellow man. Well, isn't that just what...
  • kstauff : I believe the deficit left by the Bush administration for fiscal '08 was around $500 billion. ...
  • kstauff : You're right, I overestimated the number of democrats in both houses, although I believe that the...
  • kstauff : Are you as angry at Roosevelt, Truman, Kennedy, Johnson and Clinton for the wars they prosecuted?...
  • kstauff : The Obama administration told us it would be 8% without the stimulus.  You tell me if he and his...
  • ... : Just to make it apparent, there's already a Chromium browser which uses the Chrome codebase for...
  • Adalast : people keep throwing around the "New Deal" and saying that it was horrible and didn't help our...
Advertisement
Monday, October 26, 2009

Eavesdropping on Smartphone Secrets

Researchers say that smartphones are vulnerable to an attack used to steal information from smartcards.
By Erica Naone

As cell phones become more like pocket computers, many people are calling for closer scrutiny of their security. Such people usually point out that today's phones are a lot like the desktop PCs of the mid-1990s. Attackers can apply a huge body of experience from attacking desktop machines when looking for a way into mobile devices.

However, some experts argue that mobile phones are actually simple enough to be vulnerable to attacks originally designed for embedded systems.

"The phone is a very stripped-down environment," says Benjamin Jun, vice president of technology at Cryptography Research, a security research company based in San Francisco, CA. "Which means that someone who's trying to attack the device generally has an easier time, because it's not as complicated as a desktop system."

To demonstrate this, Cryptography Research adapted a smartcard attack for use against today's smartphones.

About a decade ago, the company found that a technique called differential power analysis would allow an attacker to extract the cryptographic keys from a smartcard by analyzing its patterns of power consumption. As it turns out, Jun says, the same type of analysis will reveal the cryptographic keys that a phone uses to access a carrier's network or to secure data stored on the device. In contrast, such an attack would be hard to pull off on a more complicated device, simply because a laptop, for example, would run more programs at the same time and produce a lot more noise.

The smartcard attack called for the attacker to be in possession of the object, but, in adapting it for smartphones, the researchers found a way to do the same types of calculations based on leaked electromagnetic signals picked up with an antenna.

Jun believes attacks on mobile devices are particularly serious because these devices are being used to access high-value corporate data.

But the bad news has a flip side. Jun notes that, just as attackers have experience exploiting vulnerabilities on embedded systems, manufacturers have experience developing countermeasures. Because embedded systems have even more limited memory and processing power than today's mobile devices, he thinks these countermeasures would be relatively easy to translate to smartphones.

"The main question is whether protections can be done entirely in software or not," Jun says. Entirely software-based solutions would be cheapest to roll out, he notes. Hardware countermeasures, however, are readily available and have already been shipped in millions of smartcards.

Comments

Advertisement

Log In

Forgot your password?     Register »
Advertisement
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
•  Subscribe
Save 36%
•  Table of Contents
•  MIT News
» Gift Subscription
» Digital Subscription
» Reprints, Back Issues
» Subscribe
» Table of Contents
» MIT News

More Technology News from Forbes

Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.