Researchers from Tel Aviv University have managed to extract the encryption key of an air-gapped laptop placed in another room, through a wall, using nothing more than standard electronic equipment.
This team of four people used only an antenna, a few amplifiers, a software-defined wireless, and a standard Lenovo 3000 N200 laptop. The researchers did not break the computer's cover or make any other modifications to its setup.
The laptop was running the latest version of GnuPG 2 and its Libcrypto cryptographic library. GnuPG is an open-source implementation of the OpenPGP standard. The researchers targeted Libcrypt and its Elliptic Curve Diffie-Hellman (ECDH) encryption algorithm
During the test, the team sent a specific ciphertext to the laptop and then measured the electromagnetic leakage coming from the device. The initial tests were conducted in the same room, but the team was able to successfully conduct the tests from an adjacent room, through a standard 15cm thick reinforced drywall.
All the researchers had to do was send the ciphertext (a crypto-message) to the laptop 66 times and then analyze the surrounding electromagnetic field. After 3.3 seconds, they were able to recover the encryption key used by the laptop through a classic side-channel attack.
A side-channel attack occurs when a nearby attacker monitors, records, and then analyzes data from cryptographic operations. By observing the fluctuations in power usage and energy emitted during these operations, they can later piece together various elements or the entire key .
"Our attack is non-adaptive, requiring the decryption of a single, non-adaptively chosen ciphertext to extract the entire secret key," the researchers explained, referring to the fact that only specific ciphertexts can be used and not random data.
Additionally, the researchers disclosed their research to the GnuPG developers (CVE-2015-7511), who released an updated version of Libgcrypt to protect the library from this type of side-channel attack.
The entire research paper, ECDH Key-Extraction via Low-Bandwidth Electromagnetic Attacks on Computers, is available to read online.

