Combined fault injection and real-time side-channel analysis for Android Secure-Boot bypassing - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Lecture Notes in Computer Science Année : 2023

Combined fault injection and real-time side-channel analysis for Android Secure-Boot bypassing

Résumé

The Secure-Boot is a critical security feature in modern devices based on System-on-Chips (SoC). It ensures the authenticity and integrity of the code before its execution, avoiding the SoC to run malicious code. To the best of our knowledge, this paper presents the first bypass of an Android Secure-Boot by using an Electromagnetic Fault Injection (EMFI). Two hardware characterization methods are combined to conduct this experiment. A real-time Side-Channel Analysis (SCA) is used to synchronize an EMFI during the Linux Kernel authentication step of the Android Secure-Boot of a smartphone-grade SoC. This new synchronization method is called Synchronization by Frequency Detection (SFD). It is based on the detection of the activation of a characteristic frequency in the target electromagnetic emanations. In this work we present a proof-of-concept of this new triggering method. By triggering the attack upon the activation of this characteristic frequency, we successfully bypassed this security feature, effectively running Android OS with a compromised Linux Kernel with one success every 15 minutes.
Fichier principal
Vignette du fichier
Combined_FI_and_Real-Time_SCA_for_Android_Secure-Boot_Bypassing.pdf (13.14 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

cea-04536513 , version 1 (08-04-2024)

Identifiants

Citer

Clément Fanjas, Clément Gaine, Driss Aboulkassimi, Simon Pontié, Olivier Potin. Combined fault injection and real-time side-channel analysis for Android Secure-Boot bypassing. Lecture Notes in Computer Science, 2023, 13820, pp.25-44. ⟨10.1007/978-3-031-25319-5_2⟩. ⟨cea-04536513⟩
7 Consultations
5 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More