Method for protecting a terminal against a side channel attack
By controlling energy-consuming components to distort battery state data, the method protects mobile terminals from new side-channel attacks that exploit battery gauges, maintaining security and user experience.
Patent Information
- Application Number
- FR2022012834
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-06
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-12-06
AI Technical Summary
New side-channel attacks exploit the intelligent battery gauges in mobile terminals to detect user actions, compromising security by analyzing power consumption patterns, despite software isolation between applications.
Control energy-consuming components like vibrators or speakers to modify battery state data, simulating normal operations to confuse attackers and prevent data theft by masking consumption patterns.
Effectively thwarts new side-channel attacks by disrupting battery gauge data, making it unusable for attackers, while maintaining user experience and ensuring security.
Smart Images

Figure 00000014_0000 
Figure 00000015_0000 
Figure 00000016_0000
Abstract
Description
Title of the invention: Method for protecting a terminal against a side channel attack [0001 ] GENERAL TECHNICAL FIELD
[0002] The present invention relates to the field of computer security. More specifically, it relates to a method for protecting a terminal against a side channel attack.
[0003] STATE OF THE ART
[0004] Smartphone-type mobile terminals today store a large amount of users' personal data and are used for sensitive operations such as transactions. Securing them is therefore a necessity, and attempts at attacks to compromise their content are increasingly numerous.
[0005] A side-channel attack (SCA) is a computer attack which, without calling into question the theoretical robustness of security methods and procedures, seeks out and exploits flaws in their implementation, whether software or hardware.
[0006] More precisely, while an algorithm may be perfectly mathematically secure, hardware-related flaws may nevertheless appear during “practical” use, and allow, for example, the obtaining of secret information such as a user authentication code.
[0007] The typical example is fault injection, that is, the deliberate introduction of errors into the system to provoke certain revealing behaviors.
[0008] More recently, acoustic or consumption attacks consist of studying either the noise generated by the processor (it emits noise which varies in intensity and nature according to its consumption), or directly its electrical consumption to provide information on the code.
[0009] Indeed, each instruction carried out by a microprocessor uses a certain number of transistors. At each instant, the measurement of the current consumed can reflect the activity of the microprocessor. Certain operations, more expensive, therefore increase the electrical consumption, so that it is possible to distinguish differences between valid and invalid codes. Side channel attacks are numerous and varied, difficult to predict, and it is therefore desirable to make them impossible.
[0011] The invention improves the situation PRESENTATION OF THE INVENTION
[0012] The present invention therefore relates, according to a first aspect, to a method for protecting a terminal comprising data processing means, a battery and a battery gauge providing the data processing means with data describing the state of the battery, against an attack by auxiliary channel using said data describing the state of the battery, the method being characterized in that it comprises the implementation by the data processing means of steps of: a. When said terminal is likely to be subject to said attack, control of at least one energy-consuming component of the terminal so as to modify the descriptive data of the state of the battery provided by the battery gauge.
[0013] According to advantageous and non-limiting characteristics:
[0014] Said energy-consuming component is a vibrator.
[0015] The method comprises a step (a) of requesting entry of a code on an interface of the terminal, step (b) being implemented during the entry of said code by a user on said interface.
[0016] The data processing means are configured to activate said vibrator each time a character of said code is entered on the interface.
[0017] In step (b), said energy-consuming component of the terminal is controlled either to be activated at least once in a dummy manner, or to be temporarily deactivated.
[0018] In step (b), either said vibrator or another energy-consuming component of the terminal is controlled to be activated artificially outside of an entry of a character of said code on the interface, or said vibrator is controlled not to be activated when at least one character of said code is entered on the interface.
[0019] The method comprises a step (c) of detecting whether said attack is attempted on the basis of the descriptive data of the state of the battery modified following step (b).
[0020] Step (b) simulates the implementation of a target process on the terminal by controlling the energy-consuming component so as to obtain the same descriptive data of the state of the battery as those that would be obtained for said target process.
[0021] The target process is entering a code on a terminal interface.
[0022] The method comprises a step (d) of implementing a response measure in function of the result of step (c).
[0023] Said response measure comprises a software blocking of the descriptive data of the state of the battery provided by the battery gauge.
[0024] According to a second aspect, the invention relates to a terminal comprising data processing means, at least one energy-consuming component, a battery and a battery gauge providing the data processing means with data describing the state of the battery, the data processing means being configured to: - When said terminal is likely to be subject to a side channel attack using said descriptive data of the battery state, control said energy-consuming component so as to modify the descriptive data of the battery state provided by the battery gauge.
[0025] According to a third and a fourth aspect, the invention relates to a computer program product comprising code instructions for executing a method according to the first aspect of protecting a terminal comprising data processing means, a battery and a battery gauge providing the data processing means with data descriptive of the state of the battery, against a side channel attack using said data descriptive of the state of the battery;and a storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for the execution of a method according to the first aspect of protecting a terminal comprising data processing means, a battery and a battery gauge providing the data processing means with data descriptive of the state of the battery, against a side channel attack using said data descriptive of the state of the battery.; PRESENTATION OF FIGURES
[0026] Other characteristics and advantages of the present invention will appear on reading the following description of a preferred embodiment. This description will be given with reference to the appended drawings in which:
[0027] [Fig.l] [Fig.l] represents an example of a mobile terminal with a battery gauge;
[0028] [Fig.2] [Fig.2] illustrates a side-channel attack using battery state descriptive data;
[0029] [Fig.3] [Fig.3] is a diagram of a system for implementing the method according to the invention;
[0030] [Fig.4] [Fig.4] is a flowchart illustrating the steps of an embodiment of the method according to the invention. DETAILED DESCRIPTION
[0031] New attack
[0032] The inventors discovered that advances in battery-powered mobile terminals such as smartphones make possible a new type of side-channel attack by analyzing power consumption (which, however, has little to do with known attacks of this type).
[0033] This is paradoxical because the continuous search for improving the autonomy of these terminals has led to increasing the energy efficiency of the electronic components (to reduce consumption) to such an extent that variations in consumption became almost imperceptible, and therefore consumption analysis attacks much more complex.
[0034] However, to optimize the charging and discharging cycles of the batteries (and avoid a drop in their capacity), these batteries have been made intelligent by adding turnkey components to the terminals (i.e. with their own data processing means, of the microcontroller type) dedicated to controlling the remaining charge level (called SoC, "State of charge"), called "fuel gauge", by analogy with vehicle fuel gauges. In French, the term "battery gauge" will be used, even if the term "fuel gauge" is the one commonly used by those skilled in the art even in French.
[0035] With reference to [Fig.l], in a conventional manner, data processing means 11 (for example a processor), the battery 15 and the battery gauge 16 are shown in a terminal 1. It can be seen that the battery gauge 16 is mounted so that: - Gauge 16 is connected to the terminals of battery 15; - The means 11 (and generally the components of terminal 1) are powered via gauge 16; - Data is exchanged between gauge 15 and the data processing means via a computer bus (such as I2C).
[0036] The gauge 16 is configured to continuously acquire descriptive data of the state of the battery 15 (generally current, voltage at its terminals, remaining charge level and often temperature) and communicate this information to the data processing means 11 via said bus. All of this data can be measured and / or calculated, in this respect the gauge 15 can use any known technique for deducing the battery capacity such as based on the measurement of the voltage (by estimating the internal resistance and applying the discharge curve), or on the measurement of the incoming and outgoing charge by modeling the self-discharge as a function of the temperature (technique known as the “Coulomb counter”).
[0037] In a particularly efficient manner, the battery gauge 16 can also combine the two techniques: the voltage measurement is carried out when the battery 15 is not subjected to a charge; and the current measurement is carried out when the battery 15 receives or delivers energy.
[0038] Thus, the battery voltage is used to update its current state of charge based on the curve of its voltage versus its remaining capacity. Then, when a load is applied to it, the Coulomb counter method is used to measure the energy entering and leaving the system. Using both voltage measurements and that of the loads, the maximum capacity of the battery can be estimated. The internal resistance of the battery can also be calculated using the measured current, and the two battery voltages with and without load. Thus, with the capacity maximum capacity of the battery and its internal resistance, an accurate value of the remaining capacity can be obtained.
[0039] On terminals 1 equipped with an operating system (OS), the latter can choose whether or not to leave the information sent by the battery gauge 16 (descriptive data of the state of the battery 15) accessible to applications. For example, on an Android environment, this data can be actively relayed at the request of an application, without permission required.
[0040] The inventors have found that this functionality represents a security risk, likely to open the field to a new side-channel attack. Indeed, each application is in fact granted read rights (since the requests are relayed by the OS) but also write rights (since by triggering a more or less intensive use of various components, the application de facto influences the metric measured by these sensors)!
[0041] Tests have shown that by using a deliberately developed malicious application, the attacker was able to recover a PIN code entered by a user, despite the software isolation between applications offered by the operating system.
[0042] In [Fig.2], the top peaks represent the interception of touches on the numeric keypad based on data from the battery gauge 16. It should be noted that most phones, in their factory configuration, activate the vibrator with each touch, making malicious detection even easier.
[0043] Once we have collected this data, we can carry out a temporal analysis. Indeed, knowing the layout of the keyboard, we can exploit the constraints it implies, and the distance between all the keys. A simple script gives, for a series of durations between touches, the set of possible PIN codes, which can even be reduced by using gyroscopic data with simple postulates (example: we know that a right-handed person will make a characteristic movement to touch the 1 on the keyboard with their thumb, because it is the key furthest from the latter).
[0044] It will be understood that the present new attack by auxiliary channel using the descriptive data of the state of the battery 15 provided by the gauge 16 has little to do with the known attacks by analysis of the consumption of the data processing means 11: - The new attack does not seek to distinguish processor operations, but directly to detect particular user actions by their impact on the battery; - The new attack theoretically allows one or more probable codes to be obtained directly, and not just to know whether an entered code is correct or not.
[0045] Method
[0046] The present invention relates to a method for protecting a terminal 1 against the new auxiliary channel attack which has just been described, which would exploit the data from the battery gauge 16.
[0047] With reference to [Fig.3], terminal 1 comprises as such: - data processing means 11, - generally data storage means 12 (a battery), an interface 13 such as a touch screen capable of displaying a virtual keyboard and / or a physical keyboard - a battery 15, powering at least the data processing means 11 (and in practice the entire terminal 1 - it is noted that the terminal 1 can generally be connected to the mains to recharge the battery 15, but in practice the terminal is always powered by the battery 15, and thus the terminal 1 is said to be “battery-powered”); - a battery gauge 16 providing the data processing means 11 with descriptive data on the state of the battery 15, it is recalled that this data may be a voltage at the terminals of the battery 15 (in V), a current (in A) and / or a remaining charge of the battery 15 (in Ah).
[0048] Terminal 1 is typically a mobile terminal such as a smartphone, a touchscreen tablet, but also an EFT, or any battery-powered peripheral.
[0049] Furthermore, the terminal 1 comprises at least one “energy-consuming component” 11, 12, 13, 14, also powered by the battery. By energy-consuming component, we mean a component having, when activated, a significant consumption, that is to say having on the battery 15 an impact detectable by the battery gauge 16. To reformulate further, the consumption (in mAh, or rather pAh) of an activation of said energy-consuming component is greater than a predefined detection threshold.
[0050] Said energy-consuming component 11, 12, 13, 14 may be the processing means 11, the data storage means 12, the interface 13, but also a vibrator 14 of the terminal 1. This is typically in a virtual keyboard context in which the data processing means 11 are configured to activate said vibrator 14 each time a character is entered on the interface 13 (i.e. each time the virtual keyboard is touched). Indeed, this allows “haptic feedback” in which the user has the sensation of using a real keyboard. Alternatively, the energy-consuming component could be a speaker, an antenna, a camera, a flash, a GPS chip, etc.
[0051] Note that the terminal 1 can be connected for example via a network 10 such as the Internet to a server 2 centralizing the fight against the attack by auxiliary channel.
[0052] With reference to [Fig.4], the present method, implemented by the data processing means 11 of the terminal 1, mainly comprises a step (b), implemented when said terminal 1 is likely to undergo said channel attack auxiliary, for controlling at least one energy-consuming component 11, 12, 13, 14 of the terminal 1 so as to modify the descriptive data of the state of the battery 15 provided by the battery gauge 16.
[0053] The criterion “when said terminal 1 is likely to be subject to said attack by auxiliary channel” typically corresponds to: - either to an identified attack context, for example server 2 can warn terminal 1 that it has detected suspicious activity; - either sensitive use of terminal 1, in particular entering a code on interface 13, for example to implement a transaction, access personal data, etc.
[0054] We take the example of this last case, and then the method begins with a step (a) of requesting entry of the code on the interface 13, and said control of the energy-consuming component 11, 12, 13, 14 of the terminal 1 so as to modify the descriptive data of the state of the battery 15 provided by the battery gauge 16 is implemented during the entry of said code by a user on said interface 13 (i.e. in this case “When said terminal 1 is likely to undergo said attack” = “during the entry of the code”). It is noted that if the data processing means 11 are configured to activate said vibrator 14 each time a character is entered on the interface 13, it is supposed to have an activation of the vibrator 14 each time a character of the code is entered, which makes the attack by auxiliary channel easy since it is an energy-consuming component.
[0055] By control of the energy-consuming component 11, 12, 13, 14, we mean an “unpredictable” use of this component which will modify its consumption and therefore disturb the descriptive data of the state of the battery 15. To reformulate, the battery gauge 16 will continue to send back the descriptive data of the state of the battery 15, but these will have been “scrambled” by the energy-consuming component and made unusable for the attack by auxiliary channel, which will therefore fail.
[0056] In particular, the energy component is controlled: - either to be activated at least once artificially (i.e. it is activated for nothing, at a time when it should not have been activated, to create parasitic consumption), - either to be temporarily deactivated (i.e. it is not activated, at a time when it should have been, to create parasitic under-consumption).
[0057] Note that preferably, the control of this component is such that the general operation of the terminal 1, and therefore the user experience, are not disrupted. In addition, it is preferably random to prevent an attacker from being able to predict the disruption and take it into account.
[0058] In the preferred example of entering a code, the vibrator 14 is controlled as follows: - either to be activated artificially outside of an entry of a character of said code on the interface 13 (i.e. it creates a parasitic consumption and simulates a non-existent key entry), note that another energy-consuming component 11, 12, 13 can be used instead of the vibrator 14 to create said parasitic consumption, - either to not be activated when entering at least one character of said code on the interface 13 (i.e. it hides an actual key entry).
[0059] Preferably, we have at least, on entering the code: - legitimate activation of vibrator 14 (when entering a character of the code); - a dummy activation of vibrator 14 (without entering any character of the code) - a lack of legitimate activation of vibrator 14 (when entering a character of the code).
[0060] Alternatively to the vibrator 14, the following controls of energy-consuming components can be provided: - the implementation of a dummy operation on the data processing means 11; - a dummy memory write (especially if the means 12 is a hard disk); - a dummy display (or no display) on interface 13; - a sound emission from the loudspeaker at a high volume but at a frequency inaudible or almost as low as 5Hz.
[0061] Diagnostic or provocation modes
[0062] In another embodiment, an attempt is made to prevent the side channel attack, either by checking to what extent the terminal 1 is vulnerable, or by directly encouraging the attacker to act to flush it out (active defense technique known as honeypot).
[0063] To do this, step (b) simulates the implementation of a target process on the terminal 1 by controlling the energy-consuming component 11, 12, 13, 14 so as to obtain the same consumption profile (the same descriptive data of the state of the battery 15) as that which would be had on said target process.
[0064] Typically, the target process is the entry of a code on an interface 13 of the terminal 1, so that said entry of the code is simulated, for example by activating the vibrator 14 so as to reproduce the sequence that would be obtained when entering a decoy code.
[0065] We can then see if it is easy to find the decoy code from the descriptive data of the state of the battery 15 modified (by the activation of the vibrator 14) provided by the battery gauge 16 (which would betray a vulnerability - we can simply alert the user, or put in place various checks (responses to requests, how often, with what precision, etc.) in order to obtain a balance sheet of the risks incurred, and these results can be presented to the user or used by a sensitive software solution to better assess its environment), or even implement a step (c) of detection of whether said attack is attempted on the basis of the descriptive data of the state of the battery 15 modified following step (b).
[0066] This way of proceeding opens up the possibility of trapping an attacker, by looking if there is an attempt to use the decoy code later, one can determine that the system is under attack, or under active surveillance, and act accordingly.
[0067] In this respect, the method may comprise a step (d) of implementing a response measure based on the result of step (c), which may range from simply alerting the user, to attempting to identify and neutralize the attacker, including complete software blocking (at least temporarily) of the descriptive data of the state of the battery 15 provided by the battery gauge 16 (i.e. the data processing means 11 prevent other applications from having access to it). This may temporarily harm the battery life (because the applications will no longer be able to finely optimize the energy consumption), but the risk of a real attack will be eliminated.
[0068] Terminal
[0069] According to a second aspect, the invention relates to the terminal 1 for implementing the method according to the first aspect.
[0070] Thus, this terminal 1 comprises, as explained, data processing means 11, at least one energy-consuming component 11, 12, 13, 14 (typically a vibrator 14), a battery 15 and a battery gauge 16 providing the data processing means 11 with descriptive data of the state of the battery 15. It may further comprise data storage means 12, an interface 13, etc.
[0071] The data processing means 11 are configured to implement steps aimed at protecting the terminal 1 against an attack by a side channel using said descriptive data of the state of the battery 15, these steps consisting of: - When said terminal 1 is likely to be subject to such an attack by auxiliary channel using said descriptive data of the state of the battery 15 (for example when entering a code on the interface 13), control said energy-consuming component 11, 12, 13, 14 so as to modify the descriptive data of the state of the battery 15 provided by the battery gauge 16; - If necessary, detect whether said attack is attempted on the basis of the descriptive data of the state of the modified battery 15; or even implement a response measure depending on the result of the detection.
[0072] Computer program product
[0073] According to a fourth and a fifth aspect, the invention relates to a computer program product comprising code instructions for the execution (on the data processing means 11 of the terminal 1) of a method according to the first aspect of protecting the terminal 1 against a side channel attack using said descriptive data of the state of the battery 15 provided by the battery gauge 16, as well as storage means readable by computer equipment (for example the data storage means 12 of the terminal) on which this computer program product is found.
Claims
Claims
1. Method for protecting a terminal (1) comprising data processing means (11), a battery (15) and a battery gauge (16) providing the data processing means (11) with data descriptive of the state of the battery (15), against a side channel attack using said data descriptive of the state of the battery (15), the method being characterized in that it comprises the implementation by the data processing means (11) of steps of: a. When said terminal (1) is likely to be subject to said attack, simulation of the implementation of a target process on the terminal (1) by controlling at least one energy-consuming component (11, 12, 13, 14) of the terminal (1) so as to modify the descriptive data of the state of the battery (15) provided by the battery gauge (16) and obtain the same descriptive data of the state of the battery (15) as those that would be available for said target process; b.detecting whether said attack is attempted based on the modified battery state descriptive data (15).
2. The method of claim 1, wherein said energy-consuming component is a vibrator (14).
3. Method according to one of claims 1 and 3, comprising a step (a) of requesting entry of a code on an interface (13) of the terminal (1), step (b) being implemented during the entry of said code by a user on said interface (13).
4. Method according to claims 2 and 3 in combination, wherein the data processing means (11) are configured to activate said vibrator (14) each time a character of said code is entered on the interface (13).
5. Method according to one of claims 1 to 4, wherein in step (b), said energy-consuming component (11, 12, 13, 14) of the terminal (1) is controlled either to be activated at least once in a dummy manner, or to be temporarily deactivated.
6. A method according to claims 4 and 5 in combination, wherein in step (b), either said vibrator (14) or another energy-consuming component
7.
8.
9.
10.
11. (11, 12, 13) of the terminal (1) is controlled to be activated in a dummy manner outside of an entry of a character of said code on the interface (13), or said vibrator (14) is controlled not to be activated when at least one character of said code is entered on the interface (13). Method according to one of claims 1 to 6, in which the target process is the entry of a code on an interface (13) of the terminal (1). Method according to one of claims 1 to 7, comprising a step (d) of implementing a response measure depending on the result of step (c). Method according to claim 8, wherein said response measure comprises a software blocking of the descriptive data of the state of the battery (15) provided by the battery gauge (16). Terminal (1) comprising data processing means (11), at least one energy-consuming component (11, 12, 13, 14), a battery (15) and a battery gauge (16) providing the data processing means (11) with data descriptive of the state of the battery (15), the data processing means (11) being configured to: - When said terminal (1) is likely to be subject to a side channel attack using said descriptive data of the state of the battery (15), simulating the implementation of a target process on the terminal (1) by controlling said energy-consuming component (11, 12, 13, 14) so as to modify the descriptive data of the state of the battery (15) provided by the battery gauge (16) and obtain the same descriptive data of the state of the battery (15) as that which would be available for said target process; - Detect whether said attack is attempted based on the modified battery state descriptive data (15). Computer program product comprising code instructions for executing a method according to one of claims 1 to 9 for protecting a terminal (1) comprising data processing means (11), a battery (15) and a battery gauge (16) providing the data processing means (11) with data descriptive of the state of the battery (15), against a side channel attack using said data descriptive of the state of the battery (15), when said program is executed on a computer.
12. Storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for the execution of a method according to one of claims 1 to 9 for protecting a terminal (1) comprising data processing means (11), a battery (15) and a battery gauge (16) providing the data processing means (11) with data descriptive of the state of the battery (15), against a side channel attack using said data descriptive of the state of the battery (15).