A previously unknown form of compromising emanations has been discovered. LED status indicators on data communication equipment, under certain conditions, are shown to carry a modulated optical signal that is significantly correlated with information being processed by the device. Physical access is not required; the attacker gains access to all data going through the device, including plaintext in the case of data encryption systems. Experiments show that it is possible to intercept data under realistic conditions at a considerable distance. Many different sorts of devices, including modems and Internet Protocol routers, were found to be vulnerable. A taxonomy of compromising optical emanations is developed, and design changes are described that will successfully block this kind of "Optical TEMPEST" attack.
翻译:一种此前未知的妥协性辐射形式已被发现。数据通信设备上的LED状态指示灯在特定条件下会携带一种调制光信号,该信号与设备正在处理的信息显著相关。攻击者无需物理接触即可获取通过设备的所有数据,包括数据加密系统中的明文。实验表明,在现实条件下,能够从相当远的距离截获数据。多种不同类型的设备(包括调制解调器和互联网协议路由器)均被发现存在脆弱性。本文建立了妥协性光学辐射的分类法,并描述了成功阻断此类“光学TEMPEST”攻击的设计改进方案。