Re: One-sided authentication for small micros?

From: Andrew Swallow (am.swallow_at_eatspam.btinternet.com)
Date: 10/15/03


Date: Wed, 15 Oct 2003 14:52:39 +0000 (UTC)


"Paul Rubin" <http://phr.cx@NOSPAM.invalid> wrote in message
news:7x4qybxfi1.fsf@ruckus.brouhaha.com...
[snip]
>
> I don't know what a CAN data link is (card area network?). Are you
> concerned about some attacker poking probes into contacts on a PC
> board? If yes, your random numbers etc. have to be generated on-chip.
> For example, a simple protocol could be to just have the slave encrypt
> a timestamp with a block cipher and let the master decrypt and check
> the timestamp, but if the attacker can manipulate the real time clock,
> then again, old authentication codes can be re-used.
>
> It might help if you say more about the circuit and the application.

CAN is a packet switching protocol used in environments
with levels of noise interference such as factories and
the engine compartments of motor vehicles. Some types
of microprocessor come with built in CAN hardware.

Putting money through a CAN link is quite unusual. Sounds
like there are two machines, one of which the general public
can get access to. Will there ever be 3 or more machines
on the network? For example a controller and say 2 coffee
machines. Are all the messages 1 to 1 or does the
controller send a single message to all machines?

Are you restricting the encryption to the payload? The header,
retransmissions and error corrections to be performed in
plain text?

Does the equipment have say RS232 ports that the
repair man can use to down load the new key variables
into the equipment? Sufficient battery backed ram to
hold 16 bytes? Or possibly 128 bytes?

A method of resynchronising the cryptos if one of
the machines is switches off will also be needed.

Andrew Swallow



Relevant Pages

  • Re: Can find Vista box, cant share folders or printers.
    ... When I click 'Network' on the laptop the ... I've disabled Norton and Windows firewall entirely to make sure that's not ... public folder sharing - on ... start by running the Network Setup Wizard on all machines (see ...
    (microsoft.public.windows.vista.networking_sharing)
  • Re: XP to Vista -- only halfway there
    ... concerning networks that combine Vista and XP machines. ... I am setting up an inhouse network that links together three machines, ... by 1) a misconfigured firewall or overlooked firewall (including stateful ...
    (microsoft.public.windows.vista.networking_sharing)
  • Re: Audacity and Gentoo
    ... can only pick up radio 4 when using the TV aerial to ... I freak if my machines disagree by more than about 50 ... > ADSL cable, 2 power cables, one network ...
    (uk.comp.os.linux)
  • Re: Active Directory Setup Advice
    ... A domain is really an entity with a single security remit. ... seen as on the same network it will be like one big network. ... Under one domain all machines have to be unique in naming scheme. ... sub domains you can have same names under different domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: install
    ... You just need to set up your network correctly. ... start by running the Network Setup Wizard on all machines (see ... Problems sharing files between computers on a network are generally caused ... by 1) a misconfigured firewall or overlooked firewall (including a stateful ...
    (microsoft.public.windows.vista.installation_setup)

Quantcast