Saturday, December 5, 2009

Results

We first tested the adaptive algorithm exhaustively on all possible PINs. The distribution in Figure 8 was obtained. The worst case has been reduced from 45 guesses to 24 guesses, and the average has fallen from 24 to 15 guesses. We then implemented the attacks on the IBM Common Cryptographic Architecture (version 2.41, for the IBM 4758), and successfully extracted PINs generated using the IBM 3624 method. We also checked the attacks against the API specifications for the VISA Security Module (VSM) , and found them to be effective. The VSM is the forerunner of a whole range of hardware security modules for PIN processing, and we believe that the attacks will also be effective against many of its successors.


No comments:

Post a Comment