Access "Embedded smart card chips are open to hack attacks"
This article is part of the October 2008 issue of Security 7 Award winners sound off on key information security issues
Cracking Smart Cards Attackers "eavesdrop" on power output to steal crypto keys. Smart cards are designed for security and convenience. The secure, multipurpose authentication they provide makes them an attractive option for controlling logical and physical access to businesses and governments. The embedded microchip smart grid technology is also an attractive target for hackers and pirates to commit fraud, theft and piracy. Most of the hacks and countermeasures focus on power analysis attacks, which are performed by attackers using digital oscilloscopes eavesdropping on the power use of transistors as embedded smart card microchips perform cryptographic operations. Simple power analysis (SPA) directly interprets power use to "see" individual bits, and can crack the cryptokeys in seconds. However, basic security practices easily thwart SPA. Differential power analysis (DPA) is the really serious threat. It applies statistical analysis across multiple power consumption measurements to overcome noise and countermeasures that obscure individual bits. The ... Access >>>
Premium Content for Free.
Embedded smart card chips are open to hack attacks
Using power analysis attacks, including Simple Power Analysis, hackers can attack the embedded microchips inside smart cards.
Product Review: Application Security Inc.'s AppDetectivePro
Application Security Inc.'s AppDetectivePro does deep inspections of database configurations to identify security issues. It's ideal for internal and external auditors, security professionals, consultants and others who need to perform on-the-fly database vulnerability assessments.
Learn how to choose NAC services
Figure out the right questions to ask your network access control (NAC) service provider or vendor.
Encryption no longer an optional technology
Unravel the ins and outs of how your organization should deploy encryption.
- Embedded smart card chips are open to hack attacks
Security 7 Award winners tackle important information security issues
The 2008 Security 7 Award winners have their say on information sharing, perimeter security, relationships, convergence, strategy, history and progress.
Product Review: Finjan Vital Security NG-5000
Finjan's Finjan Vital Security NG-5000's Web filtering engines provide strong detection of Web-based security threats.
LogRhythm product review
LogRhythm is a cross-platform log management that manages audit files and IT security management processes.
Product Review: Cymphonix's Network Composer
Cymphonix's Network Composer is a security and visibility appliance that controls and monitorstraffic passing through the network perimeter to the Internet.
- Security 7 Award winners tackle important information security issues
Bruce Schenier, Marcus Ranum debate risk management
Experts Bruce Schneier and Marcus Ranum debate whether risk management is an appropriate strategic direction for information security professionals to follow.
Combat social engineering the 'Carnegie' way
Dale Carnegie's "How to Win Friends and Influence People" can be a valuable tool for CISOs who are up against social engineering issues.
Interview: Chris Nickerson of TruTV's 'Tiger Team'
Chris Nickerson of Lares Consulting explains best practices for penetration tests and the risks of outsourcing.
Information security professionals have their say
Information Security magazine's Security 7 Award winners write personal essays on topics ranging from perimeter security, information sharing, physical and logical security convergence and progress made in the industry.
- Bruce Schenier, Marcus Ranum debate risk management
More Premium Content Accessible For Free
Cloud and mobility in the enterprise has caused a heightened need for organizations to take a closer look at next generation authentication ...
Virtualization and cloud computing are part and parcel of enterprise networks today. Virtualization security, however, is still a bolt-on affair ...
Mobile device security is one of the biggest nightmares InfoSec pros face in the era of bring your own everything (BYOE). Simply banning employees ...