| 数据搜索系统,热门电子元器件搜索 |
|
HCS370IP 数据表(PDF) 20 Page - Microchip Technology |
|
|
|||||||||||||||||||||||||||||
HCS370IP 数据表(HTML) 20 Page - Microchip Technology |
|
20 / 36 page ![]() HCS370 DS41111D-page 20 Preliminary 2002 Microchip Technology Inc. FIGURE 7-3: SYNCHRONIZATION WINDOW 7.4 Security Considerations The strength of this security is based on keeping a secret inside the transmitter that can be verified by encrypted transmissions to a trained receiver. The transmitter’s secret is the manufacturer’s key, not the encryption algorithm. If that key is compromised then a smart transceiver can capture any serial number, cre- ate a valid code word, and trick all receivers trained with that serial number. The key cannot be read from the EEPROM without costly die probing but it can be calculated by brute force decryption attacks on trans- mitted code words. The cost for these attacks should exceed what you would want to protect. To protect the security of other receivers with the same manufacturer’s code, you need to use the random seed for secure learn. It is a second secret that is unique for each transmitter. Its transmission on a special button press combination can be disabled if the receiver has another way to find it, or limited to the first 127 trans- missions for the receiver to learn it. This way, it is very unlikely to ever be captured. Now if a manufacturer’s key is compromised, clone transmitters can be created, but without the unique seed they have to be relearned by the receiver. In the same way if the transmissions are decrypted by brute force on a computer, the ran- dom seed hides the manufacturer’s key and prevents more than one transmitter from being compromised. The length of the code word at these baud rates makes brute force attacks that guess the hopping code take years. To make the receiver less susceptible to this attack, make sure that you test all the bits in the decrypted code for the correct value. Do not just test low counter bits for sync and the bit for the button input of interest. The main benefit of hopping codes is to prevent the retransmission of captured code words. This works very well for code words that the receiver decodes. Its weakness is if a code is captured when the receiver misses it, the code may trick the receiver once if it is used before the next valid transmission. To make the receiver more secure it could increment the counter on questionable code word receptions. To make the trans- mitter more secure, it could use separate buttons for lock and unlock functions. Another way would be to require two different buttons in sequence to gain access. There are more ways to make KEELOQ systems more secure, but they all have trade offs. You need to find a balance between security, design effort, and usability, particularly in failure modes. For example, if a button sticks or kids play with it, the counter should not end up in the blocked code window rendering the transmitter useless or requiring retraining. Blocked Entire Window rotates to eliminate use of previously used codes Single Operation Window Window (32K Codes) (16 Codes) Double Operation (resynchronization) Window (32K Codes) Stored Synchronization Counter Value |
|
链接网址 |
| ALLDATASHEET是否为您带来帮助? [ DONATE ] |
关于 Alldatasheet | 广告服务 | 联系我们 | 隐私政策 | 数据表链接 | 链接交换 | 制造商名单 All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |