Government ID, Smart Cards, Identification and Authentication

Cryptography Research to hold workshop on securing devices using Elliptic Curve Cryptography (ECC)

Wednesday, February 6, 2008

Cryptography Research, Inc. (CRI) will hold a three-day workshop on how to evaluate the security of Elliptic Curve Cryptography (ECC) platforms against power analysis. ECC is used to protect secret information exchanged in smart cards, electronic passports, mobile communication systems and other devices. Simple Power Analysis (SPA) and Differential Power Analysis (DPA) are techniques that can expose these devices to tampering and fraud by revealing keys and other secret information stored on a chip. The workshop takes place on March 10-12 at CRI’s San Francisco office. The primary audience for the workshop includes developers and architects of secure embedded systems, as well as evaluators and individuals designing testing requirements for tamper-resistant products.


Cryptography Research to Lead Workshop on Securing Devices Using Elliptic Curve Cryptography (ECC) Against Power Analysis Attack

SAN FRANCISCO, CA – Cryptography Research, Inc. (CRI) today announced that it will hold a three-day workshop on how to evaluate the security of Elliptic Curve Cryptography (ECC) platforms against power analysis. ECC is used to protect secret information exchanged in smart cards, electronic passports, mobile communication systems and other devices. Simple Power Analysis (SPA) and Differential Power Analysis (DPA) are techniques that can expose these devices to tampering and fraud by revealing keys and other secret information stored on a chip. The workshop takes place on March 10-12 at CRI’s San Francisco office.

“Many companies are implementing Elliptic Curve Cryptography in their products for efficiency reasons and because of ECC’s position in the National Security Agency’s Suite B standards,” said Ken Warren, smart card business manager at CRI. “This workshop will help participants understand and evaluate the security of ECC implementations in products against power analysis vulnerabilities.”

In the workshop, demonstrations will show how the Cryptography Research DPA Workstation(TM) can be used to analyze ECC implementations. Attendees will also conduct hands-on tutorials using the DPA Workstation software to analyze smart cards performing common ECC algorithms.

DPA was discovered at CRI by Paul Kocher, Joshua Jaffe and Benjamin Jun, who demonstrated that power consumption measurements of smart cards and other devices could be analyzed to find secret keys. Vulnerable devices can be exploited by attackers to counterfeit digital cash, duplicate ID cards, manufacture forged consumables, pirate digital content or mount other attacks. Countermeasures to SPA and DPA are necessary to secure tamper-resistant devices, and are required for United States government products under the draft FIPS 140-3 standard.

The primary audience for the workshop includes developers and architects of secure embedded systems, as well as evaluators and individuals designing testing requirements for tamper-resistant products. Technical staff interested in designing and testing tamper-resistant systems for consumer products, financial systems, anti-piracy/conditional access systems or government/defense applications are also encouraged to attend.

The full agenda and registration form for the ECC Power Analysis Workshop can be found online at www.cryptography.com/dpa_eccworkshop.html.

For more information please contact Ken Warren at ken@cryptography.com.

About Cryptography Research, Inc.

Cryptography Research, Inc. provides technology to solve complex security problems. In addition to security evaluation and applied engineering work, the company is actively involved in long-term research and technology licensing in areas including content protection, tamper resistance, network security and financial services. Security systems designed by Cryptography Research engineers protect more than $100 billion of commerce annually for wireless, telecommunications, financial, digital television, entertainment and Internet industries. For additional information please visit www.cryptography.com[end] 

Turkcell, Turkey’s largest mobile operator, has announced the launch of its Cep-T Cüzdan NFC mobile wallet application on BlackBerry Bold 9900 smart phones.

Turkcell subscribers with NFC-enabled Bold 9900s can now use the mobile wallet service to make contactless payments at any MasterCard PayPass-enabled point of sale across Turkey, as well as abroad.

read more »

FIME is joining forces with Thales IT Security Evaluation Facility (ITSEF), a provider of information systems and secure communication in defense, security and transportation markets, to provide a new testing and certification service.

read more »

The Federal Trade Commission (FTC) has announced that it will hold a workshop on April 26 to examine the use of mobile payments and how this emerging technology impacts consumers.

read more »

Using smart phones for online banking and shopping has been promoted as the next big thing, but adoption has been slow, partly due to the fact that smart phones have security issues. Scientific American reports that this might change with the development of quantum cryptography.

read more »

Entrust is introducing Elliptic Curve Cryptography (ECC) certificate trials aiming to streamline security protocols. The elliptic curve certificates will provide the same level of security as other products but offer enhanced performance.

read more »

Visa Europe has announced that NFC-enabled smart phones from Samsung, LG and Research In Motion have been certified for use with Visa payWave, Visa’s mobile application for payments at the point-of-sale.

read more »