Title: Karsten Nohl
1??????? ???????
4-NAND ???????
_at_ Pacsec 2009
2????????????????????????????
?????
?????? ???
??????
???????
?????? ???
??????/ HDL ???
??? (Degate)
?????
3????????????????3??????
??????????
??????
??? ??????
???????
?????
??????
4?? ????????????????????
- ??????????????
- ????
- ????(Fuming nitric acid)
5????
???(Silicon on Insulator)
??????
Karsten Nohl Reverse-Engineering Silicon
5
????????
6???????????????
- ????? ???
- ??? ?????????????????
7???? ????????????????????????
8???????????????
- ????????
- ?? 500?
- 100???????
- ???1000???? ???
- ??????
- ???????????
- ???????????
- 10,000????
9????????????3D?????
10????????????????????????????
????????(FIB, ?????)??? ??????????
1mm
11???????????????
- 100µm????????????????
- ???????? hugin
- ??????????????
12??????(Image Stitching)???????????
Image Stitching degate.zfch.de/Pacsec2009/
13????????????????????????
- ??????????????
- ??????????????????
- ???????????? (Degate??????????)
14????????????????????
15??????????????2?????????
2-NAND Mifare
2-NAND Legic
2-NAND DECT
16???????????????????Web?
www.siliconzoo.org
- ???????????
- ???????????????????????????????????
- Zoo ??????????????????????????????????!!
17??????????????????????
- Mifare Crypto-1 ?? 1500 ??
- Legic Legic Prime ?? 2000 ??
- ?????????? ??????????
- ???? (Degate ?????????)
18?????????????????????
- TODO Matlab tool screenshot
- ??????????????????????????????????????
- MATLAB??????? Degate ????
19?? Degate ?????????
degate.zfch.de
- ?? Martin Schobert ltnitram_at_berlin.ccc.degt
- GPL?????????????????
20?????????????????????????????
???????
????
??????
??????
????????
?????
????
21GateViewer ??????????????????
GateViewer degate.zfch.de/Pacsec2009/
22??????????????
23??????? Legic Prime
??????Legic Prime?????????????
24??????????????????????????
- ?????????????????????
- NXP Mifare Crypto-1
- NXP Hitag2
- Legic Prime
- ??????????
- DECT DSC
- Atmel CryptoMemory CryptoRF
???Oyster Cards???? ????????????
25?? ?????????????
- ??????? ????????????????????
- ?????????????????????????????
- ??????????????????????????????
?????????????????
26???????????????
- silicon disassember?????????????????
- ?????
- ???????? (Reprap/Makerbot??????????)
- Degate ???
- ??????????? (??????????????????)
- ???????? (??????)
????????????????????????????????????????
27?????
Degate degate.zfch.de Silicon Zoo
siliconzoo.org Image Stitching,
degate.zfch.de/Pacsec2009/ GateViewer, Slides
Karsten Nohl ltnohl_at_virginia.edugt Starbug
ltstarbug_at_ccc.degt
Many Thanks to Martin Schobert, Christin
Schulz, Stefan Skillen, Daniel Wittekind , Sven
Kaden??? !
28??(???)
29????
RFID CHIP
RFID ???
Nohl and Starbug used acetone to peel the plastic
off the card's millimeter-square chip. Once they
isolated the chip, they embedded it in a block of
plastic and sanded it down layer by layer to
examine its construction. Nohl compares this to
looking at the structure of a building floor by
floor.
Nohl? Starbug? ?????????????1mm???????????????????
??????????????????????????????????????????????????
????
??????? Charlie Card
30?????
Mifare (NXP???????)http//www.nxp.com/
ISO/IEC14443(Type-A)?????????????
Legic (LEGIC Identsystems) http//www.legic.com/ I
SO/IEC14443(Type-A)?????????????
DECT http//www.dect.org/ ETSI(????????)?????????
??????????
31?????
- Oyster Card???????????IC???
- ????????????????YouTube????
- Charlie Card ???????????IC???
- ?????????????????????
- Mifare Type-A???IC???
- Oyster Card, Charlie Card ?Mifare Classic
???????? - Crypto-1 Mifare Classic ?????
- ???????????
32????
- any Reprap/Makerbot folks here? ?????????????
- ?? ??????????????????????????
- ReprapReplicating Rapid-prototyper
????????????????????????????????(http//reprap.or
g/bin/view/Main/WebHome) - Makerbot ??????????3D????(http//www.makerbot.co
m/) - Retro comp. fans? ????????
- ?? comp.?????????????(component)??
- EE geeks? ??????
- ?? EE???????????????????????
- ??????????