Lest We Remember: Cold-Boot Attacks on Encryption Keys.

Contrary to widespread assumption, dynamic RAM (DRAM), the main memory in most modern computers, retains its contents for several seconds after power is lost, even at room temperature and even if removed from a motherboard. Although DRAM becomes less reliable when it is not refreshed, it is not imme...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 52; no. 5; pp. 91 - 99
Autores principales: Halderman, J. Alex, Schoen, Seth D., Heninger, Nadia, Clarkson, William, Paul, William, Calandrino, Joseph A., Feldman, Ariel J., Appelbaum, Jacob, Felten, Edward W.
Formato: Artículo
Publicado: Association for Computing Machinery May2009
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=39363012&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 39363012
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: May2009
      vid: 52
      iid: 5
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        39363012
        10.1145/1506409.1506429
      ppf: 91
      ppct: 8
      formats:
      tig:
        atl: Lest We Remember: Cold-Boot Attacks on Encryption Keys.
      aug:
        au:
          Halderman, J. Alex
          Schoen, Seth D.
          Heninger, Nadia
          Clarkson, William
          Paul, William
          Calandrino, Joseph A.
          Feldman, Ariel J.
          Appelbaum, Jacob
          Felten, Edward W.
        affil:
          University of Michigan.
          Electronic Frontier Foundation.
          Princeton University.
          Wind River Systems.
          The Tor Project.
      su:
        Dynamic random access memory
        Computer security software
        Random access memory
        Computer programming
        Cryptography
        Laptop computer security measures
      sug:
        subj:
          Dynamic random access memory
          Computer security software
          Random access memory
          Computer programming
          Cryptography
          Laptop computer security measures
      ab: Contrary to widespread assumption, dynamic RAM (DRAM), the main memory in most modern computers, retains its contents for several seconds after power is lost, even at room temperature and even if removed from a motherboard. Although DRAM becomes less reliable when it is not refreshed, it is not immediately erased, and its contents persist sufficiently for malicious (or forensic) acquisition of usable full-system memory images. We show that this phenomenon limits the ability of an operating system to protect cryptographic key material from an attacker with physical access to a machine. It poses a particular threat to laptop users who rely on disk encryption: we demonstrate that it could be used to compromise several popular disk encryption products without the need for any special devices or materials. We experimentally characterize the extent and predictability of memory retention and report that remanence times can be increased dramatically with simple cooling techniques. We offer new algorithms for finding cryptographic keys in memory images and for correcting errors caused by bit decay. Though we discuss several strategies for mitigating these risks, we know of no simple remedy that would eliminate them.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2009
    holdings:
      @attributes:
        islocal: N