Sitemap
Press enter or click to view image in full size
Capture of a SIKE key from a Samsung device [1]

Member-only story

Your LEDs Could Be Leaking Your Encryption Keys!

Cracking a PQC and an ECDSA Key using Colour

3 min readJun 22, 2023

The brute forcing of an encryption key will typically take billions and billions of years to crack. But, if there’s a leakage of some of the information around the key, this could be cut to just minutes. One of the most useful attacks is a side channel attack, which involves some leakage through a secondary channel, such as light, radio waves, or electrical noise. Now, new research has shown that it is possible to recover encryption keys from variations in the intensities of LEDs [here][1]:

Press enter or click to view image in full size

The work involved using an iPhone to record the light from an LED, such as one used in a card reader. This involved the ability to derive a 256-bit ECDSA key, and also a SIKE key (used within Post Quantum Cryptography) from a Samsung Galaxy S8 phone. Most work up to this point has used a fairly complex capture and analysis setup, but this work shows that the side channel can be detected purely with the capture from an iPhone:

“One of the most significant things of this paper is the fact that you don’t need to connect the probe, connect a scope, or use a software-defined radio,” — Ben…

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.