15/09/2016 – Talk by Francesco Palmarini

Title: APDU-level attacks in PKCS#11 devices
Time: 10:00
Location: Meeting room
Type: Research Result
Speaker: Francesco Palmarini
Abstract: We describe attacks on PKCS#11 devices that we successfully mounted by interacting with the low-level APDU protocol, used to communicate with the device. They exploit proprietary implementation weaknesses which allow attackers to bypass the security enforced at the PKCS#11 level. Some of the attacks leak, as cleartext, sensitive cryptographic keys in devices that were previously considered secure. We present a new threat model for the PKCS#11 middleware and we discuss the new attacks with respect to various attackers and application configurations. All the attacks presented in this paper have been timely reported to manufacturers following a responsible disclosure process

Note: The work will presented at the 19th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2016) next week.