Infineon Says Has Fixed Encryption Flaw Found by Researchers

Advertisement
By Reuters | Updated: 17 October 2017 10:19 IST
Highlights
  • Infineon said it's aware of the security breaches in the identity cards
  • The vulnerability exposed cards to a 'factorization' attack
  • The flaw left 750,000 digital identity cards vulnerable to attack
Infineon Says Has Fixed Encryption Flaw Found by Researchers

Germany's Infineon Technologies said it was aware of, and had taken action to correct a flaw in the encryption used for secure products such as identity cards that was revealed by researchers on Monday.

The vulnerability exposes smartcards, security tokens and other secure hardware chips made by Infineon to a so-called "factorization" attack, the Centre for Research on Cryptography and Security said.

It would be feasible for a hacker to compute the private part of an encryption "key" using only the key's public part, the researchers, led by Petr Svenda of the Masaryk University in the Czech Republic, found.

Infineon, which makes chips used in the auto industry, power management and smartcard systems, said the researchers had informed the company of the flaw in February.

Advertisement

"Infineon thoroughly investigated the newly developed methods and reacted immediately," a company spokesman said.

The flaw left 750,000 digital identity cards issued by Estonia vulnerable to attack, the government of the east European country that has been a pioneer of e-government said last month.

Advertisement

On Monday the Estonian authorities said they were taking preventative measures to prevent the exploitation of the possible vulnerability.

Microsoft Corp included an update of the firmware that runs on Infineon's so-called Trusted Platform Modules to address the security flaw in a release of "patches", or software fixes, rolled out on Oct. 10.

Advertisement

The flaw resided in the crypto-library used by Infineon, within an algorithm that is used to generate large prime numbers which are then paired.

Infineon used a simplified system for generating these prime numbers called "Fast Prime" that had been officially certified. No mathematical weaknesses were found during the certification process, the company said.

Under a worst-case scenario, however, it would cost just $76 for a hacker to crack a 1024-bit encryption key and about $40,000 for a 2048-bit key using the C4 version of the Amazon Web Services cloud computing platform, the researchers reckon.

"In close cooperation with the research team, our customers and the German certification body, the software function has been updated," the Infineon spokesman said.

"(It) is currently in the process of being certified and rolled out, including the production of new software devices that use the new software function." The company was not aware of the flaw being successfully exploited by hackers.

© Thomson Reuters 2017

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Could Unveil a Compact Flagship Tablet Alongside the OnePlus 15T
  2. Vivo Y50m 5G, Vivo Y50 5G With 6,000mAh Battery Launched: All Details
  3. Oppo K13 Turbo, K13 Turbo Pro With Inbuilt Fan, 7,000mAh Battery Launched
  4. Redmi Note 15 Pro+, iQOO Z10 Specifications Tipped Ahead of Debut
  5. Akai Soul Series Soundbars With Up to 160W Output Launched in India
  6. Redmi Turbo 5 Launch and Specifications Tipped: All Details
  1. Samsung Galaxy Z Fold 8 Might Not Feature Upgraded Titanium Backplate Included With Galaxy Z Fold 7: Report
  2. Samsung Galaxy Tab A11 LTE Version Reportedly Surfaces on FCC, IMEI Certification Websites
  3. Asus Vivobook 14 Launched in India With Snapdragon X Processor, 14-Inch LCD Screen: Price, Specifications
  4. Meta Says It Won't Sign EU’s GPAI Code of Practice Due to ‘Legal Uncertainties’
  5. OnePlus Teases Launch of New Tablet in India on July 23; OnePlus Pad Lite Expected to Debut
  6. Redmi Note 15 Pro+, iQOO Z10 Tipped to Feature Snapdragon Chipsets, 1.5K Resolution Displays
  7. Ubisoft's Upcoming Launches Include a New Ghost Recon Game, CEO Says
  8. Samsung Galaxy Watch 8, Watch 8 Classic Now Available for Pre-Order in India
  9. Vodafone Idea (Vi) Rolls Out Additional Benefits With Rs. 199, Rs. 179 Prepaid Plans: Report
  10. Netflix Reportedly Used AI-Generated Scene in The Eternaut Show to Cut Production Costs
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.