Secret keys in a mobile phone can be revealed simply by monitoring its power consumption
There is a class of attacks that can reveal the secret keys and other stored information in a mobile phone by the simple monitoring of its power consumption, thereby leaving an opportunity for fraudsters to exploit.
Cryptography Research discovered this vulnerability, Differential Power Analysis (DPA), in the mid-1990s in its developments with smart cards. The payment card industry worked alongside Cryptography Research to implement countermeasures to make sure that the chips it uses in payment cards are safe. Today, there are about 4.5 billion cards shipped annually that use Cryptography Research’s countermeasures against DPA attacks.
Cryptography Research says the DPA attack story is unfinished. Today, smartphones offer more applications and use more power to operate these functions. Yet, unlike a complicated desktop system, the phone is a very stripped-down environment, which means the job of an attacker is easier. By using simple equipment, an attacker can plot the amount of power consumed while your mobile phone is operating. After running some statistics, the fraudster can compromise the entire security of your phone.
Cryptography Research says that financial institutions and businesses involved in mobile commerce should be very careful. It is risky for them to take an existing piece of infrastructure designed for one purpose and try to use it for something else, unless they are very aware of where security might be jeopardized.
Print version |
Email to a friend |
View other articles
Latest IT, computer and network security articles
Cloud-based Infrastructure as a Service save up to 55 percent of IT operations spend
IronKey helps Orbotech ensure all high value company and customer data is secure
Passwords are past their sell-by-date
RandomStorm appointment signals European and worldwide expansion
India and Russia are the biggest producers of viruses
Misconfigured networks are the easiest IT resource hackers exploit
The Return of Ransomware and Do-it-Yourself Botnets
Atos Origin secures and manages the IT systems for Singapore 2010 Youth Olympic Games
Djigzo partners with Comodo to provide email encryption and authentication solution
...[view more IT, computer and network security articles]...
Other IT, computer and network security Resources
Security websites for specific products:
Access control and RFID systems - Burglar alarm, intruder alarm and fire alarm systems - Biometric recognition and identification systems - CCTV cameras and systems - IT, computer and network security systems - Health and safety - Security guard services - Surveillance and remote monitoring systems
Security websites for specific markets:
Bank and financial security - Corporate security - School and education security - Sport event and live venue security - Healthcare and hospital security - Hotel restaurant and casino security - Industrial and manufacturing security - Infrastructure and Utilities security - Home and personal security - Public sector security - Retail security - Small Business security - Transport security

