[论文解读] Interleaving Commands: a Threat to the Interoperability of Smartcard Based Security Applications
本文识别并演示了基于智能卡的安全系统中一个关键的互操作性漏洞:来自一张智能卡的命令交错可干扰另一张智能卡上的操作,即使两者均通过通用准则认证。作者通过实验表明,数字签名过程可能在未报错的情况下静默完成,尽管接收了非预期的命令,这在多个智能卡共存的中间件环境中破坏了信任与安全性。
Although smartcards are widely used, secure smartcard interoperability has remained a significant challenge. Usually each manufacturer provides a closed environment for their smartcard based applications including the microchip, associated firmware and application software. While the security of this "package" can be tested and certified for example based on the Common Criteria, the secure and convenient interoperability with other smartcards and smartcard applications is not guaranteed. Ideally one would have a middleware that can support various smartcards and smartcard applications. In our ongoing research we study this scenario with the goal to develop a way to certify secure smartcard interoperability in such an environment. Here we discuss and experimentally demonstrate one critical security problem: if several smartcards are connected via a middleware it is possible that a smartcard of type S receives commands that were supposed to be executed on a different smartcard of type S'. Such "external commands" can interleave with the commands that were supposed to be executed on S. Here we demonstrate this problem experimentally with a Common Criteria certified digital signature process on two commercially available smartcards. Importantly, in some of these cases the digital signature processes terminate without generating an error message or warning to the user.
研究动机与目标
- 调查多智能卡中间件环境中命令交错引发的安全风险。
- 评估外部命令对认证智能卡应用的影响,特别是在数字签名过程中的影响。
- 证明互操作性问题可导致静默且未被察觉的安全违规,即使具备通用准则认证。
- 强调在目标智能卡上执行非预期命令时缺乏错误检测的问题。
- 倡导采用形式化认证机制,以确保在多样化智能卡平台之间的安全互操作性。
提出的方法
- 研究人员使用中间件环境连接了两张市售的、通过通用准则认证的智能卡。
- 他们将本应发送给一张智能卡(S')的命令注入到另一张智能卡(S)的通信流中,模拟多卡环境下的命令交错。
- 监控数字签名过程,以检测其在接收到外部非预期命令时是否仍能成功完成。
- 实验聚焦于涉及加密操作的实际场景,特别是签名生成过程。
- 团队分析了在执行这些交错命令期间,系统是否缺乏错误消息或警告。
- 他们在标准中间件条件下评估智能卡的行为,以评估静默命令干扰的实际风险。
实验结果
研究问题
- RQ1在多智能卡中间件环境中,本应发送给一张智能卡的命令是否可能被意外执行在另一张智能卡上?
- RQ2认证智能卡应用在加密操作期间在多大程度上能检测或报告非预期的命令干扰?
- RQ3在接收到外部非预期命令时,数字签名过程在何种条件下仍能无错误完成?
- RQ4命令交错如何影响互操作系统中基于智能卡的应用程序的安全性和完整性?
- RQ5外部命令的静默执行对认证智能卡系统的可信度有何影响?
主要发现
- 即使两张智能卡均通过通用准则认证,来自一张智能卡的命令交错仍可成功执行在另一张智能卡上。
- 目标智能卡上的数字签名过程在接收到非预期命令的情况下,未生成任何错误或警告消息即完成。
- 系统未检测或拒绝外部命令,表明中间件级别的隔离存在关键缺陷。
- 该攻击向量对用户和应用程序均未被察觉,破坏了认证的安全保证。
- 该行为表明对基于智能卡的安全应用互操作性和可信度构成重大威胁。
- 结果表明,当前的认证模型未能充分应对多设备环境中跨智能卡的命令干扰问题。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。