首页> 外文会议> >Experience Using a Low-Cost FPGA Design to Crack DES Keys
【24h】

Experience Using a Low-Cost FPGA Design to Crack DES Keys

机译:使用低成本FPGA设计破解DES密钥的经验

获取原文
获取原文并翻译 | 示例

摘要

This paper describes the authors' experiences attacking the IBM 4758 CCA, used in retail banking to protect the ATM infrastructure. One of the authors had previously proposed a theoretical attack to extract DES keys from the system, but it failed to take account of real-world banking security practice. We developed a practical scheme that collected the necessary data in a single 10-minute session. Risk of discovery by intrusion detection systems made it necessary to complete the key "cracking" part of the attack within a few days, so a hardware DES cracker was implemented on a US$995 off-the-shelf FPGA development board. This gave a 20-fold increase in key testing speed over the use of a standard 800 MHz PC. The attack was not only successful in its aims, but also shed new light on the protocol vulnerabilities being exploited. In addition, the FPGA development led to a fresh way of demonstrating the non-randomness of some of the DES S-boxes and indicated when pipelining can be a more effective technique than replication of processing blocks. The wide range of insights we obtained demonstrates that there can be significant value in implementing attacks "for real".
机译:本文描述了作者攻击IBM 4758 CCA的经验,该经验用于零售银行业务以保护ATM基础结构。其中一位作者以前曾提出过一种理论上的攻击,以从系统中提取DES密钥,但它没有考虑到现实世界中的银行安全实践。我们开发了一个实用的计划,该计划在一个10分钟的会话中收集了必要的数据。入侵检测系统有发现风险,因此有必要在几天内完成攻击的关键“破解”部分,因此,在价格为995美元的现成FPGA开发板上实施了硬件DES破解程序。与使用标准的800 MHz PC相比,这使关键测试速度提高了20倍。该攻击不仅在目标上取得了成功,而且还为所利用的协议漏洞提供了新的启示。此外,FPGA的发展带来了一种新颖的方式来证明某些DES S盒的非随机性,并指出流水线技术可以比复制处理块更有效的技术。我们获得的广泛见解表明,“真正”实施攻击可能具有重大价值。

著录项

  • 来源
    《》|2002年|p.579-592|共14页
  • 会议地点 Redwood Shores CA(US);Redwood Shores CA(US)
  • 作者

    Richard Clayton; Mike Bond;

  • 作者单位

    University of Cambridge, Computer Laboratory, Gates Building, JJ Thompson Avenue, Cambridge CB3 OFD, United Kingdom;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号