Method for protecting terminal from side channel attack
By controlling the terminal's energy consumption components to modify the battery meter data, simulating user input, and combining software shielding technology, the problem of battery status data being attacked is solved, and security protection for smart terminals is achieved.
Patent Information
- Application Number
- CN202380093215.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-06
- Filing Date
- 2023-12-05
- Publication Date
- 2025-09-12
AI Technical Summary
Existing smart terminals have security risks in the data transmission process of battery fuel gauges, which leads to new side-channel attacks. Attackers can obtain secret information entered by users by analyzing battery status data.
By controlling the terminal's energy-consuming components, such as the vibrator, modifying the battery status data provided by the battery gauge, and simulating user input to interfere with attacker analysis, it combines software shielding technology to prevent side-channel attacks.
It effectively prevents side-channel attacks, protects the privacy information entered by users, and maintains the security of the terminal and user experience.
Smart Images

Figure CN120641901A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security, and more particularly to a method for protecting a terminal from side-channel attacks. Background Art
[0002] Smartphone-type mobile terminals now store a large amount of personal user data and are used for sensitive operations such as transactions. Therefore, protecting them is necessary, and attack attempts to compromise their content are becoming more and more frequent.
[0003] A side channel attack (SCA) is a computer attack that seeks out and exploits flaws in the implementation of security methods and procedures (whether software or hardware) without questioning their theoretical robustness.
[0004] More specifically, although an algorithm may be mathematically completely secure, hardware-related flaws may still appear during "real" use and, for example, allow obtaining secret information such as user authentication codes.
[0005] A classic example is fault injection, that is, deliberately introducing errors into a system to induce certain revealing behavior.
[0006] More recently, acoustic or consumption attacks consist of either studying the noise generated by the processor (the noise it emits, the intensity and nature of which vary depending on how much it consumes) or directly studying its power consumption to give details about the code.
[0007] In reality, each instruction executed by a microprocessor uses a certain number of transistors. At any given moment, measuring the current consumed reflects the microprocessor's activity. Therefore, certain more expensive operations increase power consumption, making it particularly possible to distinguish between valid and invalid code.
[0008] Side channel attacks are diverse, difficult to predict, and therefore desirable to make impossible.
[0009] The present invention aims to improve this situation. Summary of the Invention
[0010] Therefore, according to a first aspect, the present invention relates to a method for protecting a terminal comprising a data processing device, a battery and a battery fuel gauge for providing data describing the battery status to the data processing device, said method preventing side channel attacks using said data describing the battery status, characterised in that the method comprises the following steps carried out by the data processing device:
[0011] (b) When the terminal is likely to be attacked, controlling at least one energy-consuming component of the terminal to modify data describing a battery status provided by a battery fuel meter.
[0012] According to advantageous and non-limiting features:
[0013] The energy-consuming component is a vibrator.
[0014] The method comprises the steps of (a) requesting a user to input a code on an interface of a terminal, and (b) executing the step while the user inputs the code on the interface.
[0015] The data processing device is configured to activate the vibrator each time a character of the code is entered on the interface.
[0016] In step (b), the energy-consuming component of the terminal is controlled to be either activated at least once in a virtually manner or to be temporarily deactivated.
[0017] In step (b), either the vibrator or another energy-consuming component of the terminal is controlled to be virtually activated in addition to the characters of the code being entered on the interface, or the vibrator is controlled not to be activated when at least one character of the code is entered on the interface.
[0018] The method comprises a step (c) of detecting, after step (b), whether the attack is attempted based on the modified data describing the battery status.
[0019] Step (b) simulates the execution of the target process on the terminal by controlling the energy consumption components to obtain data describing the battery status that are the same as those to be obtained for the target process.
[0020] The target process is entering code on the terminal interface.
[0021] The method includes the step (d) of implementing a response measure based on the result of step (c).
[0022] The responsive action includes software masking of data describing the battery status provided by the battery fuel gauge.
[0023] According to a second aspect, the present invention relates to a terminal comprising a data processing device, at least one energy-consuming component, a battery, and a battery fuel meter for providing data describing a battery status to the data processing device, wherein the data processing device is configured to:
[0024] - when the terminal may be subject to a side channel attack using the data describing the battery status, controlling the energy consumption component so as to modify the data describing the battery status provided by the battery fuel gauge.
[0025] According to the third and fourth aspects, the present invention relates to a computer program product comprising code instructions for executing the method according to the first aspect, the method being used to protect a terminal comprising a data processing device, a battery and a battery fuel meter for providing data describing a battery status to the data processing device to prevent side channel attacks using the data describing the battery status; and a storage device readable by a computer device, on which a computer program product is recorded, the computer program product comprising code instructions for executing the method according to the first aspect, the method being used to protect a terminal comprising a data processing device, a battery and a battery fuel meter for providing data describing a battery status to the data processing device to prevent side channel attacks using the data describing the battery status. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Other features and advantages of the present invention will become apparent after reading the following description of preferred embodiments. This description will be made with reference to the accompanying drawings, in which:
[0027] [ Figure 1 ] Figure 1 An example of a mobile terminal having a battery fuel gauge is shown;
[0028] [ Figure 2 ] Figure 2 shows a side-channel attack using data describing the battery state;
[0029] [ Figure 3 ] Figure 3 is a schematic diagram of a system for implementing the method according to the present invention;
[0030] [ Figure 4 ] Figure 4 is a flow chart illustrating the steps of an embodiment of a method according to the present invention. DETAILED DESCRIPTION
[0031] New attacks
[0032] The inventors discovered, by analyzing power consumption, that the advancement of battery-powered mobile terminals, such as smartphones, enables a new type of side-channel attack (which, however, has little to do with known attacks of this type).
[0033] This is paradoxical, since the ongoing quest to increase the autonomy of these terminals has led to improvements in the energy efficiency of electronic components (to reduce power consumption) to the point where variations in consumption become almost imperceptible, and thus power analysis attacks become more sophisticated.
[0034] However, in order to optimize the charge and discharge cycles of the battery (and avoid a decrease in its capacity), these batteries have been made intelligent by adding turnkey components on the terminal (that is, data processing devices with their own microcontroller type) dedicated to controlling the remaining state of charge "SoC" (similar to the fuel gauge in a vehicle, which is called a "fuel gauge"). Even though the term "fuel gauge" is the one commonly used by those skilled in the art, the term "battery fuel gauge" will also be used.
[0035] Reference Figure 1 In a conventional manner, data processing means 11 (eg a processor), a battery 15 and a battery gauge 16 are represented in the terminal 1. It can be seen that the battery gauge 16 is mounted so that:
[0036] - a fuel gauge 16 is connected to the terminals of the battery 15;
[0037] - the device 11 (typically a component of the terminal 1 ) is powered via the electricity meter 16 ;
[0038] - Data is exchanged between the fuel gauge 16 and the data processing device via a computer bus (such as I2C).
[0039] The fuel gauge 16 is configured to continuously acquire data describing the state of the battery 15 (typically the current, the voltage at its terminals, the remaining state of charge, typically the temperature) and to transmit this information via the bus to the data processing means 11. All these data can be measured and / or calculated, and in this respect the fuel gauge 15 can use any known battery capacity inference technique, such as one based on voltage measurement (by estimating the internal resistance and applying a discharge curve) or one based on measurement of the input and output charge by modeling the self-discharge as a function of temperature (a technique known as a "coulomb counter").
[0040] In a particularly effective manner, battery fuel gauge 16 may also combine two techniques: voltage measurements when battery 15 is not under load; and current measurements when battery 15 is receiving or delivering energy.
[0041] Therefore, the battery voltage is used to update its current state of charge based on its voltage evolution curve as a function of its remaining capacity. Then, when a load is applied, a coulomb counter method is used to measure the energy entering and leaving the system. Using both voltage and charge measurements, the maximum capacity of the battery can be estimated. The battery's internal resistance can also be calculated using the measured current and the two battery voltages with and without load. Therefore, using the battery's maximum capacity and its internal resistance, an accurate value for the remaining capacity can be obtained.
[0042] On a terminal 1 equipped with an operating system (OS), the latter may or may not choose to make the information sent by the battery gauge 16 (data describing the state of the battery 15) accessible to applications. For example, in an Android environment, this data may be forwarded proactively at the request of an application without requiring permission.
[0043] The inventors discovered that this functionality presents a security risk and could open the door to new side-channel attacks. In fact, each application is actually granted not only read permissions (because the request is forwarded by the operating system) but also write permissions (because by triggering more or less intensive use of various components, the application actually affects the metrics measured by these sensors).
[0044] Tests showed that by using a deliberately developed malicious app, an attacker could recover the PIN code entered by the user, despite the operating system's proposed software isolation between apps.
[0045] exist Figure 2 The top peak in the graph represents the interception of touches on the numeric keypad based on data from the battery gauge 16. It should be noted that most phones are factory-set to activate the vibrator on every touch, making malicious detection easier.
[0046] Once this data has been collected, a temporal analysis can be performed. Knowing the layout of the keyboard, it is possible to exploit the constraints it implies, as well as the distances between all the keys. For the sequence of durations between touches, a simple script yields a set of possible PINs, which can even be reduced by using gyroscope data with simple assumptions (for example, it is known that a right-handed person will make a characteristic movement, touching the key 1 on the keyboard with his / her thumb, since it is the key farthest from the right).
[0047] It should be understood that the present new side channel attack using the data describing the state of the battery 15 provided by the fuel meter 16 has little to do with the known power analysis attacks on the data processing device 11:
[0048] The new attack does not seek to differentiate between processor operations, but instead detects specific user actions directly through their impact on the battery.
[0049] - The new attack theoretically allows to directly obtain one or several possible codes, rather than just knowing whether the entered code is correct.
[0050] method
[0051] The invention relates to a method for protecting a terminal 1 against the new side-channel attack just described, which method will make use of data from a battery gauge 16 .
[0052] Reference Figure 3 , terminal 1 includes:
[0053] - data processing means 11,
[0054] - typically data storage means 12 (battery), an interface 13 such as a touch screen capable of displaying a virtual keyboard and / or a physical keyboard,
[0055] a battery 15 which supplies power to at least the data processing means 11 (and in practice to the entire terminal 1 - it should be noted that the terminal 1 can generally be connected to a power supply in order to charge the battery 15, but in practice the terminal is always powered by the battery 15, and hence the terminal 1 is referred to as "battery powered");
[0056] - A battery fuel gauge 16, which provides the data processing device 11 with data describing the state of the battery 15. It can be imagined that the data can be the voltage (in V), the current (in A) and / or the remaining capacity (in Ah) of the battery 15 at the terminals of the battery 15.
[0057] Terminal 1 is typically a mobile terminal such as a smartphone, touch screen tablet, etc., but can also be an EPT or any battery-powered device
[0058] Furthermore, the terminal 1 comprises at least one "energy-consuming component" 11, 12, 13, 14, also powered by a battery. By energy-consuming component is meant a component that, when activated, has a significant consumption, that is, an effect on the battery 15 that can be detected by a battery gauge 16. To reiterate, the consumption of the activation of said energy-consuming component (in mAh, or more precisely, Ah) is greater than a predefined detection threshold.
[0059] The energy-consuming components 11, 12, 13, and 14 can be the processing device 11, the data storage device 12, the interface 13, or the vibrator 14 of the terminal 1. This is typically the case in a virtual keyboard environment, where the data processing device 11 is configured to activate the vibrator 14 each time a character is entered on the interface 13 (that is, each time the virtual keyboard is touched). This effectively implements "tactile feedback," giving the user the sensation of using a real keyboard. Alternatively, the energy-consuming component can be a speaker, antenna, camera, flash, GPS chip, or the like.
[0060] It should be noted that the terminal 1 may be connected to a server 2 centrally protecting against side-channel attacks, for example, via a network 10 such as the Internet.
[0061] Reference Figure 4The method implemented by the data processing device 11 of the terminal 1 mainly includes step (b), which is implemented when the terminal 1 may be subject to the side channel attack, controlling at least one energy-consuming component 11, 12, 13, 14 of the terminal 1 to modify the data describing the status of the battery 15 provided by the battery fuel meter 16.
[0062] The metric “when the terminal 1 may be subject to the side channel attack” generally corresponds to:
[0063] - either in response to the identified attack context, for example the server 2 can warn the terminal 1 that it has detected suspicious activity;
[0064] - or corresponds to a sensitive use of the terminal 1 , in particular the entry of a code on the interface 13 , for example to carry out a transaction, access personal data, etc.
[0065] Taking the latter case as an example, the method thus begins with step (a) of requesting a code to be entered on interface 13, and while the user is entering the code on interface 13 (that is, in this case, "when terminal 1 is potentially vulnerable to the attack" = "while entering the code"), the control of energy-consuming components 11, 12, 13, and 14 of terminal 1 is implemented to modify the data describing the state of battery 15 provided by battery gauge 16. It should be noted that if data processing device 11 is configured to activate vibrator 14 each time a character is entered on interface 13, then vibrator 14 should be activated each time a code character is entered, which facilitates side-channel attacks because it is an energy-consuming component.
[0066] By controlling the energy-consuming components 11, 12, 13, 14, it is understood that this component is used in an "unpredictable" manner, which will change its consumption and, therefore, corrupt the data describing the state of the battery 15. To reiterate, the battery gauge 16 will continue to send data describing the state of the battery 15, but this data will be "scrambled" by the energy-consuming components and will be unavailable to the side-channel attack, which will therefore fail.
[0067] In particular, the energy components are controlled as follows:
[0068] - is activated at least once in a virtual manner (that is, it is activated pointlessly when it should not be activated, generating parasitic consumption),
[0069] - is temporarily deactivated (ie, it is not activated when it should be activated, thereby creating a parasitic under-consumption).
[0070] It should be noted that the control of this component is preferably such that the general operation of the terminal 1 and therefore the user experience is not interrupted. Furthermore, it is preferably randomized to prevent an attacker from being able to predict the interruption and take it into account.
[0071] In a preferred example of password input, the vibrator 14 is controlled as follows:
[0072] - is activated in a virtual manner outside the input of characters of said code on the interface 13 (that is, it generates a parasitic consumption and simulates a non-existent / different key input), it being noted that another energy-consuming component 11, 12, 13 can be used instead of the vibrator 14 to generate said parasitic consumption,
[0073] - or is not activated when at least one character of the code is entered on the interface 13 (that is,
[0074] It hides the actual keystrokes).
[0075] Preferably, when entering the code, there is at least:
[0076] - legitimate activation of the vibrator 14 (when the characters of the code are entered);
[0077] - Virtual activation of the vibrator 14 (outside of any input of code characters)
[0078] - Lack of valid activation of the vibrator 14 (when entering code characters).
[0079] As an alternative to the vibrator 14, the following energy consuming component control can be performed:
[0080] - performing virtual operations on the data processing device 11;
[0081] - virtual memory writes (especially if the device 12 is a hard disk);
[0082] - A virtual display (or lack of display) on the interface 13;
[0083] -The speaker emits sound at a high volume but at an inaudible or barely audible frequency such as 5Hz.
[0084] Diagnostic or provocative mode
[0085] In another embodiment, the goal is to prevent side-channel attacks by checking the vulnerability of the terminal 1 or by actively encouraging attackers to take actions to eliminate it (active defense technology called honeypot).
[0086] To this end, step (b) simulates the implementation of the target process on the terminal 1 by controlling the energy consumption components 11, 12, 13, 14 to obtain the same consumption curve as that obtained on the target process (the same data describing the state of the battery 15).
[0087] Typically, the target process is to enter a code on the interface 13 of the terminal 1 (in particular a decoy code, i.e. a given code different from the expected code, which, as will be seen, can constitute a "signature" of the attack) so as to simulate the entry of said code, for example by activating the vibrator 14, so as to reproduce the sequence that would be obtained when entering the decoy code.
[0088] Of course, there may always be a step (a) requesting the entry of a code on the interface 13 of the terminal 1 , since it is this step that could attract an attacker and trigger the observation of said data describing the state of the battery 15 (in order to carry out a side channel attack).
[0089] The difference is that, instead of requiring user intervention (that is, preferably, step (b) does not involve the user entering a code on interface 13), terminal 1 itself can completely simulate the user entering the code on interface 13, thus enabling a fully automatic mode. To reiterate, after step (a), terminal 1 does not wait for the user to enter the expected code (his real code), but instead simulates the entry of a given decoy code, which the attacker does not distinguish. Alternatively, the user can still enter his code, but we ensure that we simulate the entry of a given decoy code that is different from the code entered by the user, i.e., the expected code (by ensuring that data describing the state of battery 15 are obtained specifically by adapting the energy consumption to the input of these decoy codes).
[0090] It is then possible to see whether it is easy to find the decoy code from the modified data describing the state of the battery 15 provided by the battery gauge 16 (by activating the vibrator 14) (which would reveal a vulnerability - the user could simply be alerted, various checks could be set (with what frequency, with what accuracy, etc., responses to requests) in order to obtain an assessment of the risk that has occurred, and these results could be presented to the user or used by sensitive software solutions to better assess their environment), or even to implement a step (c) of detecting whether the attack has been attempted based on the modified data describing the state of the battery 15 after step (b).
[0091] This approach offers the possibility of catching an attacker, and by seeing if there's an attempt to use the decoy code later, it's possible to determine that the system is under attack or actively monitored, and take appropriate action. In other words, attack (c) is typically a step to detect the use of the decoy code. In reality, the decoy code can't appear by chance; it's a signature: it can only be obtained by obtaining modified data describing the state of battery 15, and its use is therefore evidence of an attack (and in doing so, the attacker who uses this decoy code exposes himself).
[0092] To this end, the method may include a step (d) of implementing a response measure based on the result of step (c), which response measure may range from simply warning the user to attempting to identify and neutralize the attacker by completely blocking (at least temporarily blocking) the data describing the state of the battery 15 provided by the battery fuel gauge 16 in software (that is, the data processing device 11 prevents other applications from accessing it). This may temporarily harm battery life (because the application will no longer be able to finely optimize energy consumption), but the real risk of attack will be eliminated.
[0093] terminal
[0094] According to a second aspect, the invention relates to a terminal 1 for implementing the method according to the first aspect.
[0095] Thus, as described above, the terminal 1 comprises a data processing device 11, at least one energy-consuming component 11, 12, 13, 14 (typically a vibrator 14), a battery 15, and a battery fuel gauge 16 which provides the data processing device 11 with data describing the state of the battery 15. It may also comprise a data storage device 12, an interface 13, etc.
[0096] The data processing means 11 are configured to use said data describing the state of the battery 15 to implement steps aimed at protecting the terminal 1 from side-channel attacks, these steps comprising:
[0097] - when the terminal 1 is potentially subject to such a side channel attack using the data describing the state of the battery 15 (for example, when a code is entered on the interface 13), controlling the energy-consuming components 11, 12, 13, 14 to modify the data describing the state of the battery 15 provided by the battery fuel gauge 16;
[0098] - where appropriate, detecting, based on the modified data describing the state of the battery 15 , whether an attempt has been made to carry out said attack; or even implementing response measures based on the result of the detection.
[0099] Computer program product
[0100] According to a fourth and fifth aspect, the invention relates to a computer program product comprising code instructions for executing (on the data processing means 11 of the terminal 1) the method according to the first aspect, the method for protecting the terminal 1 from side-channel attacks using said data describing the state of the battery 15 provided by the battery gauge 16, and a storage device readable by the computer device in which the computer program product is located (for example the data storage means 12 of the terminal).
Claims
1. A method for protecting a terminal (1), the terminal (1) comprising a data processing device (11), a battery (15) and a battery fuel gauge (16) for providing data describing the state of the battery (15) to the data processing device (11), the method preventing side channel attacks using the data describing the state of the battery (15), characterized in that The method comprises the following steps performed by a data processing device (11): (b) when the terminal (1) is potentially vulnerable to the attack, simulating the implementation of a target process on the terminal (1) by controlling at least one energy-consuming component (11, 12, 13, 14) of the terminal (1) so as to modify the data describing the state of the battery (15) provided by the battery fuel meter (16) and obtain data describing the state of the battery (15) identical to those that the target process would obtain; (c) detecting whether the attack is attempted based on the modified data describing the state of the battery (15).
2. The method according to claim 1, wherein The energy consumption component is a vibrator (14).
3. The method according to any one of claims 1 and 2, comprising a step (a) of requesting a code input on an interface (13) of the terminal (1), and step (b) is implemented while the user inputs the code on the interface (13).
4. The method according to claim 2, wherein: The data processing device (11) is configured to activate the vibrator (14) each time a character of the code is entered on the interface (13).
5. The method according to any one of claims 1 to 4, wherein In step (b), the energy-consuming components (11, 12, 13, 14) of the terminal (1) are controlled to be activated at least once in a virtual manner or to be temporarily deactivated.
6. The method according to claim 4 and 5, wherein: In step (b), either the vibrator (14) or another energy-consuming component (11, 12, 13) of the terminal (1) is controlled to be activated in a virtually manner in addition to the characters of the code being input on the interface (13), or the vibrator (14) is controlled not to be activated when at least one character of the code is input on the interface (13).
7. The method according to any one of claims 1 to 6, wherein The target process is to input a code on the interface (13) of the terminal (1).
8. A method according to any one of claims 1 to 7, comprising the step (d) of implementing a response measure based on the result of step (c).
9. The method according to claim 8, wherein The response includes software masking of data provided by the battery fuel gauge (16) describing the status of the battery (15).
10. A terminal (1), comprising a data processing device (11), at least one energy consuming component (11, 12, 13, 14), a battery (15), and a battery fuel gauge (16) for providing data describing a state of the battery (15) to the data processing device (11), wherein the data processing device (11) is configured to: - when the terminal (1) may be subject to a side channel attack using the data describing the state of the battery (15), emulating the implementation of a target process on the terminal (1) by controlling the energy consumption components (11, 12, 13, 14) in order to modify the data describing the state of the battery (15) provided by the battery fuel meter (16) and obtain data describing the state of the battery (15) identical to those that the target process would obtain; - detecting whether said attack is attempted based on the modified data describing the state of said battery (15).
11. A computer program product comprising code instructions for executing a method according to any one of claims 1 to 9, said method being for protecting a terminal (1) when said program is executed on a computer, said terminal (1) comprising a data processing device (11), a battery (15) and a battery gauge (16) for providing data describing the state of said battery (15) to said data processing device (11), said method preventing side channel attacks using said data describing the state of said battery (15).
12. A computer-readable storage device having a computer program product recorded thereon, the computer program product comprising code instructions for executing a method according to any one of claims 1 to 9, the method being for protecting a terminal (1), the terminal (1) comprising a data processing device (11), a battery (15), and a battery fuel gauge (16) for providing data describing the state of the battery (15) to the data processing device (11), the method preventing side-channel attacks using the data describing the state of the battery (15).