
Researchers develop a new protective chip that could secure your credit cards
A team of researchers from the Massachusetts Institute of Technology (MIT) has developed a new type of radio frequency identification (RFID) chip that they say is nearly impossible to hack . The chip, if introduced by credit card companies, would prevent your credit card number or key information from being stolen.
The chip prevents so-called side-channel attacks, which analyze memory access patterns or fluctuations in power usage when a device performs an encryption operation, with the aim of extracting the encrypted key.
Chiraag Juvekar, a graduate student in the electrical engineering department at the Massachusetts Institute of Technology (MIT), explained what the new RFID does,
“The idea in a side-channel attack is that a particular execution of the cryptographic algorithm only leaks a small amount of information,” he added. “So you have to run the cryptographic algorithm with the same secret multiple times to get enough material to extract a complete secret.” According to MIT, this enhanced RFID would generate random numbers, generating a new secret cryptographic key with each transaction. A central server would then use the same random number generator to keep up with the ever-changing keys.
Such a system would still be vulnerable, however, to a “power glitch” attack in which the RFID chip’s power is repeatedly cut off before its secret key changes. An attacker could then perform the same side-channel attack thousands of times, with the same key.
Two design innovations allow the MIT researchers' chip to thwart power-glitch attacks. One is a power supply that would be connected to the chip's circuitry and would be nearly impossible to disrupt, and the other is a set of "non-volatile" memory cells that can store the data the chip was working on while it was operating when it starts to lose power.
The MIT research team has collaborated with Texas Instruments to create several prototypes of the “new hack-proof” RFID. If the chip from the MIT researchers becomes commercially available ,it could mean that an identity thief wouldn’t be able to steal credit card numbers or basic card information, and high-tech burglars wouldn’t be able to remove expensive products from a warehouse and replace them with fake tags.
