Paper 2023/579
Revealing the Secrets of Radio-Enabled Embedded Systems: on extraction of raw information from any on-board signal through RF
Abstract
In this work we are interested in evaluating the possibility of extracting information from radio-enabled embedded-systems from a long distance. That is, our focus is capturing information from sources in the micrometer to tens of centimeters scale, such as intra- or inter- device busses, board-level routing traces etc. Moreover, we focus on distances in the range of millimeters to tens of centimeters from the (on-chip or on-board) embedded-system Tx Antenna to the signal source.
Side-channels denotes presence of information in illegitimate channels. Side-channel analysis (SCA) attacks typically require statistical analysis and many leakage traces, focusing on micrometer level signals (sources) which emanate direct Near-Field information up to centimeters-level distances. In the same context (Near-Field and micrometer-level) simple power analysis (SPA) like attacks typically extract either direct raw information from one or few leakages or utilize statistical analysis on various samples from the same trace, similarly to horizontal attacks. Lately, radio-enabled systems were shown to emanate to a large distance (Far-Field), information from micrometer level sources, such as CPU processing, through the RF Tx Antenna: so far, SCA-like statistical analysis were shown. On the other hand, various reports exist on direct information eavesdropping/ sniffing or data exfiltration, emanated from centimeter to tens of centimeters scale sources, e.g., SATA, USB, Power-lines, Serial interface, Air-Gap systems, Screens and even optical fibers. All these elements are typically being used as a source and a direct Tx Antenna (huge, several to tens of centimeters) of the sensitive information. These antennas typically transmit information to short distances and the decay is very steep (proportional to
Metadata
- Available format(s)
-
PDF
- Category
- Implementation
- Publication info
- Preprint.
- Keywords
- Code InjectionFLASHJTAGNFCRadio TransceiversRFSide-channel attacksSniffingSpectral modulationSerial
- Contact author(s)
-
erez danieli @ biu ac il
menachem goldzweig @ biu ac il
mosheavi @ gmail com
itamar levi @ biu ac il - History
- 2023-04-28: approved
- 2023-04-24: received
- See all versions
- Short URL
- https://ia.cr/2023/579
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2023/579, author = {Erez Danieli and Menachem Goldzweig and Moshe Avital and Itamar Levi}, title = {Revealing the Secrets of Radio-Enabled Embedded Systems: on extraction of raw information from any on-board signal through {RF}}, howpublished = {Cryptology {ePrint} Archive, Paper 2023/579}, year = {2023}, url = {https://eprint.iacr.org/2023/579} }