{"id":38148,"date":"2019-10-31T22:21:56","date_gmt":"2019-10-31T19:21:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj\/"},"modified":"2019-10-31T22:21:56","modified_gmt":"2019-10-31T19:21:56","slug":"obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj","title":{"rendered":"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Over the last decade, attackers have applied not only methods of extracting secrets or performing other unauthorized actions, but also unintentional data leakage and manipulation of program execution through side channels. <\/p>\n<p>Traditional attack methods can be costly in terms of expertise, time, and computing power. Side-channel attacks, on the other hand, can be easier to implement and non-destructive, as they exploit or control physical properties available during normal operation. <\/p>\n<p>By using statistical methods to process side-channel measurements or introducing faults into the chip's closed channels, an attacker can gain access to its secrets within a few hours.<\/p>\n<p><img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/5491f086b156ab016e65f4942f470680.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nOver 5 billion smart cards are manufactured annually, and new embedded cryptographic technologies are emerging in the markets, increasing the need to ensure safety for both businesses and individuals. <\/p>\n<p>In the Netherlands, Riscure has developed the Inspector system, which provides research laboratories and manufacturers with new, highly effective threat detection tools for ensuring security. <\/p>\n<p>The Riscure Inspector system supports various side-channel analysis (SCA) methods, such as power analysis (SPA\/DPA), synchronization, radio frequency, as well as electromagnetic analysis (EMA) and fault injection (FI) attacks, such as voltage glitches, clock glitches, and laser manipulation. The system's built-in functions support numerous cryptographic algorithms, application protocols, interfaces, and measuring instruments. <\/p>\n<p>The system allows you to extend and implement new methods and your own applications for vulnerability detection.<\/p>\n<h5>The Inspector SCA side-channel analysis system includes:<\/h5>\n<p><\/p>\n<ul>\n<li> Power measurement tracer Power Tracer;<\/li>\n<li> Electromagnetic probing setup EM Probe Station;<\/li>\n<li> Trigger generator icWaves;<\/li>\n<li> CleanWave filter;<\/li>\n<li> Current measurement probe Current Probe.<\/li>\n<\/ul>\n<p><\/p>\n<h5>Among the main benefits, the following stand out:<\/h5>\n<p><\/p>\n<ul>\n<li>This is a unified integrated tool for side-channel analysis and testing by introducing faults.<\/li>\n<li>Inspector meets the testing requirements for side channels certified by EMVco and CMVP against common criteria.<\/li>\n<li>It is an open environment that includes the source code of modules, allowing for the modification of existing methods and the inclusion of new testing methods that can be developed by the user for Inspector.<\/li>\n<li>Stable and integrated hardware and software includes high-speed data collection across millions of traces.<\/li>\n<li>A six-month software release cycle keeps users abreast of the latest field testing methods for side channels.<\/li>\n<\/ul>\n<p><\/p>\n<h5>Inspector is available in various versions on a single platform:<\/h5>\n<p><\/p>\n<ul>\n<li><b>Inspector SCA<\/b> offers all the necessary options for conducting side-channel analysis DPA and EMA.<\/li>\n<li><b>Inspector FI <\/b>provides comprehensive fault injection functionality (attack perturbation) as well as differential fault analysis (DFA).<\/li>\n<li><b>Inspector Core and SP<\/b> (signal processing) offers the core functionality of SCA implemented as individual modules to provide an affordable software package for data collection or subsequent processing.<\/li>\n<\/ul>\n<p><\/p>\n<h2>Inspector SCA<\/h2>\n<p>\nOnce measurement results are obtained, a variety of signal processing methods become available to generate multiple traces with high signal levels and low noise levels. Signal processing functions have been developed to take into account subtle differences between the signal processing of electromagnetic traces, power consumption traces, and RF traces. Powerful graphical visualization tools in Inspector allow users to perform temporal analysis or trace verification, for example, for SPA vulnerability assessment. <\/p>\n<p><img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/5fe7724312eb8f2845228b30daa756fd.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Performing DPA in ECC implementation<br \/>\n<\/i><br \/>\nFor many security implementations considered resilient to SPA nowadays, the main focus during testing typically revolves around differential testing methods (i.e., DPA\/CPA). For this purpose, Inspector offers a wide range of configurable methods concerning a large number of cryptographic algorithms and widely used algorithms such as (3)DES, AES, RSA, and ECC.<\/p>\n<p><img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/1066b611152458069a115225e1fee9d3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>EM radiation of the chip for determining the best placement during DEMA implementation<br \/>\n<\/i><\/p>\n<h5>Key Features<\/h5>\n<p><\/p>\n<ul>\n<li>This solution combines the analysis of power consumption (SPA\/DPA\/CPA), electromagnetic (SEMA\/DEMA\/EMA-RF), and non-contact testing methods (RFA).<\/li>\n<li>The speed of data collection is significantly enhanced by the close integration of the oscilloscope with Inspector.<\/li>\n<li>Advanced alignment techniques are used to prevent clock pulse jitter and randomization.<\/li>\n<li>The user can configure cryptanalysis modules supporting primary attacks and high-order attacks on all major algorithms such as (3)DES, AES, RSA, and ECC.<\/li>\n<li>Extended support for area-specific algorithms is employed, including SEED, MISTY1, DSA, and Camellia.<\/li>\n<\/ul>\n<p><\/p>\n<h5>Hardware<\/h5>\n<p>\nIn addition to the PC workstation, Inspector SCA uses hardware optimized for side-channel data and signal acquisition:<\/p>\n<ul>\n<li> Power Tracer for SPA \/ DPA \/ CPA on smart cards<\/li>\n<li> EM Probe station for SEMA \/ DEMA \/ EMA RF<\/li>\n<li> Current Probe for SPA \/ DPA \/ CPA on embedded devices<\/li>\n<li> CleanWave filter with Micropross MP300 TCL1\/2 for RFA and RF EMA<\/li>\n<li> IVI-compatible oscilloscope<\/li>\n<\/ul>\n<p>\nThe evaluated objects often require measurements, switching, and control of hardware necessary for performing SCA. The flexible hardware manager of the Inspector tool, an open development environment, and extensive interface options provide a solid foundation for high-quality measurements using the user's equipment.<\/p>\n<p><img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/c23c919276492330cb3afbee753ed1d5.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Inspector SCA<br \/>\n<\/i><br \/>\nLead security engineer Joh John Connor speaks about the system:<br \/>\n\u201cInspector has fundamentally changed the way we assess the resilience of our products to differential <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%90%D1%82%D0%B0%D0%BA%D0%B0_%D0%BF%D0%BE_%D1%8D%D0%BD%D0%B5%D1%80%D0%B3%D0%BE%D0%BF%D0%BE%D1%82%D1%80%D0%B5%D0%B1%D0%BB%D0%B5%D0%BD%D0%B8%D1%8E\">power consumption attacks <\/a><\/noindex> DPA. Its strength lies in integrating collection and analysis processes, allowing us to quickly assess the effectiveness of new cryptographic hardware projects. Moreover, its superior graphical interface enables the user to visualize power signature data from collected discrete measurements individually or simultaneously \u2014 invaluable when preparing DPA data during an attack \u2014 while its powerful analytical libraries support the most commonly used commercial encryption algorithms. Timely software and technology updates, backed by Riscure, help us maintain the security of our products.<\/p>\n<h2>Inspector FI<\/h2>\n<p>\nInspector FI \u2013 Fault Injection \u2013 offers a wide range of features to perform fault injection testing on smart card and embedded device technologies. Supported testing methods include clock glitches, voltage faults, and optical attacks using laser equipment. Fault injection attacks \u2013 also known as perturbation attacks \u2013 alter the behavior of a chip, causing a usable failure. <\/p>\n<p>With Inspector FI, users can test whether a key can be extracted by inducing failures in the chip's cryptographic operations, bypassing checks such as authentication or lifecycle status, or altering the program execution flow on the chip.<\/p>\n<h5>Extensive configurable options<\/h5>\n<p>\nInspector FI incorporates a large number of user-configurable parameters for software-controlled switches and perturbations, such as peak pulses of varying durations, pulse repetition, and voltage level changes. The software presents results by showing expected behavior, card resets, and unexpected behavior, along with detailed logging. DFA attack modules are available for major encryption algorithms. By using the 'master', users can also create a custom perturbation program with the API.<\/p>\n<h5>Key Features<\/h5>\n<p><\/p>\n<ul>\n<li> Non-parallel and easily reproducible accuracy and synchronization for all hardware fault injection devices (glitching).<\/li>\n<li> Attack design scenarios using a powerful command system and integrated IDE Inspector.<\/li>\n<li> Extensive configuration options in Inspector for automated failure injection testing.<\/li>\n<li> Laser equipment for multi-glitching with both front and back sides of the board, custom-made for failure injection testing.<\/li>\n<li> DFA modules for implementations of popular encryption algorithms, including RSA, AES, and 3DES.<\/li>\n<li> Upgrading to a multi-point laser allows targeting the chip in multiple locations simultaneously.<\/li>\n<li> Operation-dependent synchronization using the icWaves trigger generator can prevent countermeasures from being applied, avoiding sample loss.<\/li>\n<\/ul>\n<p><\/p>\n<h5>Hardware<\/h5>\n<p>\nInspector FI can be used with the following hardware components to conduct attacks:<\/p>\n<ul>\n<li> VC Glitcher with an additional glitch amplifier.<\/li>\n<li> Diode laser station with additional multi-point upgrade.<\/li>\n<li> PicoScope 5203 or IVI-compatible oscilloscope.<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/8deff9e61e8127a8af08c580fa7bda92.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Inspector FI with VC Glitcher failure generator, icWaves trigger generator, Glitch Amplifier, and Laser Station.<\/i><\/p>\n<p>The VC Glitcher generator forms the core architecture of the Inspector's failure injection system. Utilizing ultra-fast FPGA technology, it can generate glitches lasting just two nanoseconds. The hardware features a user-friendly programming interface. The user-generated glitch program is uploaded to the FPGA before testing. The VC Glitcher includes an integrated circuit for voltage glitching and clock pulse glitches, as well as a channel output for controlling the laser station.<\/p>\n<p>The diode laser station consists of a special set of powerful diode lasers with custom optics that are quickly and flexibly controlled by the VC Glitcher. The equipment elevates optical testing to a new level, providing effective multiple glitches, precise power consumption control, and fast and predictable response for pulse switching. <\/p>\n<p>With the upgrade of the diode laser station to a multi-point version, multiple areas on the chip can be tested using different synchronization and power voltage parameters.<\/p>\n<h5>Signal-based launching using the pulse generator trigger icWaves<\/h5>\n<p>\nClock jitter, random interruptions in the process, and data-dependent process duration require flexible failure switching and side-channel data collection. The icWaves Inspector system generator creates a trigger pulse in response to real-time deviations from the specified model based on the chip's power or EM signal. The device includes a special narrowband filter to ensure model matching even in noisy signals. <\/p>\n<p>The reference trace used for matching to the model within the FPGA-based device can be modified using the signal processing features of Inspector. The smart card that detected the introduction of a fault can initiate a protection mechanism to remove secret data or block the card. The icWaves component can also be used to initiate a shutdown of the card whenever power consumption or EM profile deviates from standard operation.<\/p>\n<p><img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/48b5bb15548de5517a20a80e8ce237b0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Laser Station (LS) with multipoint access option,<br \/>\nwith microscope and coordinate table<\/i><\/p>\n<h2>Integrated Development Environment (IDE)<\/h2>\n<p>\nThe Inspector development environment is designed to provide maximum flexibility to the user applying SCA and FI for any purpose.<\/p>\n<ul>\n<li> Open API: simplifies the implementation of new modules<\/li>\n<li> Source code: each module is delivered with its source code, allowing modules to be adapted to user requirements or used as a basis for creating new modules<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/f6468dc30cccfeb3897ac3e1511fd744.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Inspector FI<\/i><\/p>\n<p>Inspector combines fault injection and side-channel analysis methods in one high-performance package.<\/p>\n<p>Example of fault behavior analysis:<\/p>\n<p><img decoding=\"async\" alt=\"Vulnerability detection and resilience assessment against hacking attacks for smart cards and cryptoprocessors with embedded protection\" src=\"\/wp-content\/uploads\/2019\/09\/6e150558b3905cdd5c24e4a7d73b44f5.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe side-channel attack area is rapidly evolving, and new research results are published every year, becoming well-known or mandating certification of schemes and standards. Inspector allows users to stay informed about new developments and regular software updates that implement new methods.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/467449\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0434\u0435\u0441\u044f\u0442\u0438\u043b\u0435\u0442\u0438\u0435 \u043f\u043e\u043c\u0438\u043c\u043e \u043c\u0435\u0442\u043e\u0434\u043e\u0432 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0434\u0440\u0443\u0433\u0438\u0445 \u043d\u0435\u0441\u0430\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c\u0438 \u0441\u0442\u0430\u043b\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u043d\u0435\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0430\u044f \u0443\u0442\u0435\u0447\u043a\u0430 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u0437\u0430 \u0441\u0447\u0435\u0442 \u043f\u043e\u0431\u043e\u0447\u043d\u044b\u0445 \u043a\u0430\u043d\u0430\u043b\u043e\u0432. \u0422\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u043c\u0435\u0442\u043e\u0434\u044b \u0430\u0442\u0430\u043a\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0434\u043e\u0440\u043e\u0433\u043e\u0441\u0442\u043e\u044f\u0449\u0438\u043c\u0438 \u0441 \u0442\u043e\u0447\u043a\u0438 \u0437\u0440\u0435\u043d\u0438\u044f \u0437\u043d\u0430\u043d\u0438\u0439, \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0438 \u0432\u044b\u0447\u0438\u0441\u043b\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0439 \u043c\u043e\u0449\u043d\u043e\u0441\u0442\u0438. \u0410\u0442\u0430\u043a\u0438 \u043f\u043e \u043f\u043e\u0431\u043e\u0447\u043d\u044b\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c, \u0441 \u0434\u0440\u0443\u0433\u043e\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b, \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0431\u043e\u043b\u0435\u0435 \u043b\u0435\u0433\u043a\u043e \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c\u044b\u043c\u0438 \u0438 \u043d\u0435\u0440\u0430\u0437\u0440\u0443\u0448\u0430\u044e\u0449\u0438\u043c\u0438, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":28637,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38148","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0434\u0435\u0441\u044f\u0442\u0438\u043b\u0435\u0442\u0438\u0435 \u043f\u043e\u043c\u0438\u043c\u043e \u043c\u0435\u0442\u043e\u0434\u043e\u0432 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0434\u0440\u0443\u0433\u0438\u0445 \u043d\u0435\u0441\u0430\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c\u0438 \u0441\u0442\u0430\u043b\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u043d\u0435\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0430\u044f \u0443\u0442\u0435\u0447\u043a\u0430 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u0437\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u043e\u0446\u0435\u043d\u043a\u0438 \u0441\u0442\u043e\u0439\u043a\u043e\u0441\u0442\u0438 \u043a \u0445\u0430\u043a\u0435\u0440\u0441\u043a\u0438\u043c \u0430\u0442\u0430\u043a\u0430\u043c \u0441\u043c\u0430\u0440\u0442-\u043a\u0430\u0440\u0442 \u0438 \u043a\u0440\u0438\u043f\u0442\u043e\u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u043e\u0432 \u0441\u043e \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u043e\u0439 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0434\u0435\u0441\u044f\u0442\u0438\u043b\u0435\u0442\u0438\u0435 \u043f\u043e\u043c\u0438\u043c\u043e \u043c\u0435\u0442\u043e\u0434\u043e\u0432 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0434\u0440\u0443\u0433\u0438\u0445 \u043d\u0435\u0441\u0430\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c\u0438 \u0441\u0442\u0430\u043b\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u043d\u0435\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0430\u044f \u0443\u0442\u0435\u0447\u043a\u0430 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u0437\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:21:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:21:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Detection of vulnerabilities and assessment of resistance to hacker attacks of smart cards and cryptoprocessors with built-in protection | ProHoster","description":"Over the last decade, in addition to methods for extracting secrets or performing other unauthorized actions, attackers have begun using unintentional data leakage and manipulating program execution processes.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u043e\u0446\u0435\u043d\u043a\u0438 \u0441\u0442\u043e\u0439\u043a\u043e\u0441\u0442\u0438 \u043a \u0445\u0430\u043a\u0435\u0440\u0441\u043a\u0438\u043c \u0430\u0442\u0430\u043a\u0430\u043c \u0441\u043c\u0430\u0440\u0442-\u043a\u0430\u0440\u0442 \u0438 \u043a\u0440\u0438\u043f\u0442\u043e\u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u043e\u0432 \u0441\u043e \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u043e\u0439 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 | ProHoster","og:description":"\u0417\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0435 \u0434\u0435\u0441\u044f\u0442\u0438\u043b\u0435\u0442\u0438\u0435 \u043f\u043e\u043c\u0438\u043c\u043e \u043c\u0435\u0442\u043e\u0434\u043e\u0432 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0434\u0440\u0443\u0433\u0438\u0445 \u043d\u0435\u0441\u0430\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c\u0438 \u0441\u0442\u0430\u043b\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u043d\u0435\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0430\u044f \u0443\u0442\u0435\u0447\u043a\u0430 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c \u0437\u0430.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/obnaruzhenie-uyazvimostej-i-otsenki-stojkosti-k-hakerskim-atakam-smart-kart-i-kriptoprotsessorov-so-vstroennoj-zashhitoj","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:21:56+00:00","article:modified_time":"2019-10-31T19:21:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38148","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 20:38:22","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:14:22","updated":"2026-01-23 20:38:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38148"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38148\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/28637"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}