Combined Fault Injection and Real-Time Side-Channel Analysis for Android Secure-Boot Bypassing


연구 분야: Infrastructure



학회: International Conference on Smart Card Research and Advanced Applications


초록

The Secure-Boot is a critical security feature in modern devices based on System-on-Chips (SoC). It ensures the authenticity and integrity of the code before its execution, avoiding the SoC to run malicious code. To the best of our knowledge, this paper presents the first bypass of an Android Secure-Boot by using an Electromagnetic Fault Injection (EMFI). Two hardware characterization methods are combined to conduct this experiment. A real-time Side-Channel Analysis (SCA) is used to synchronize an EMFI during the Linux Kernel authentication step of the Android Secure-Boot of a smartphone-grade SoC. This new synchronization method is called Synchronization by Frequency Detection (SFD). It is based on the detection of the activation of a characteristic frequency in the target electromagnetic emanations. In this work we present a proof-of-concept of this new triggering method. By triggering the attack upon the activation of this characteristic frequency, we successfully bypassed this security feature, effectively running Android OS with a compromised Linux Kernel with one success every 15 min.


Author Profile
Clément Fanjas

CEA-Leti Centre CMP Equipe Commune CEA Leti- Mines Saint-Etienne 13541 Gardanne France

France
Author Profile
Clément Gaine

Univ. Grenoble Alpes CEA Leti 38000 Grenoble France

France
Author Profile
Driss Aboulkassimi

CEA-Leti Centre CMP Equipe Commune CEA Leti- Mines Saint-Etienne 13541 Gardanne France

France

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 France
사이트 Springer
좋아요 수 0

연관 논문 목록 (61건)