arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

注入与泄漏:利用电磁注入和硬件非线性主动诱导侧信道泄漏

Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity

Haoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang, Yan Long

arXiv 2609.04785首次发表:更新:

发表机构

The Hong Kong University of Science and Technology (Guangzhou); The Hong Kong Polytechnic University(香港科技大学(广州); 香港理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出注入诱导电磁侧信道框架,利用硬件非线性的电磁注入放大侧信道泄漏,设计InjectEave攻击实现远距离窃听,还分析了相关安全挑战与缓解措施。

AI 中文摘要

电磁(EM)侧信道泄漏与注入通常被视为不同的物理现象,分别威胁数据的保密性与完整性。本研究探讨如何利用电磁注入放大原本难以实现的侧信道泄漏。我们提出一种名为注入诱导电磁侧信道的新框架,以实现集成式闭环电磁安全分析。理论建模与实验测量表明,非线性硬件组件(如普遍存在的放大器、模数转换器和电源转换器)可将秘密电信号调制到注入的电磁载波上,从而将低频秘密信号上转换为可测量的电磁发射。通过调整注入频率与幅度,攻击者可主动塑造所得泄漏的有效频谱与熵。我们设计了InjectEave攻击,使用可获取的射频设备,在最远30米处窃听通过有线和无线耳机播放的音频,以及穿墙场景下的音频;同时表征了其他低频秘密的注入诱导电磁泄漏,如智能家居设备的功耗和模拟传感器输入。案例研究进一步证明,所提技术可实现对固网电话通话的闭环窃听与操控。最后,我们分析了更广泛的安全挑战及缓解措施。

英文摘要

Electromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively. This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage. We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30 m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs. Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.

CommentsWebsite: https://injecteave.github.io/

Journal refProceedings of the 35th USENIX Security Symposium (USENIX Security 26), pp. 2485-2504, 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑