- cross-posted to:
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.world
Electromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively.
This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage.
We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30 m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs.
Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.
Ive only skimmed the intro, but it sounds like they are modifying the victim devices? If you can do that, why not just delete the EM shields, or install a “clipper chip”?
They are basically introducing a carrier frequency that matches a frequency the device uses. By matching those, they are able to usr the devices own harmonics to amplify and return the signal.
They show that this can be done without any effects on the hardware, no trace. And can be done through 30cm solid concrete walls at a distance.
The tests, on wired and wireless audio devices return 100% usable and intelligible information in nearly every case and every situation.
The only situation they didn’t seem to test was a victim using multiple identical devices. \ Eg. I’m a known target so i have 3 sets of headphones. 2 constantly playing random audio and 1 being the one carrying secrets.
Would they be able to differentiate between devices or would it all come back garbled? One test was transferability - the same model of device had the same vulnerable frequencies. If they ‘injected’ in a room full of the same devices, could they determine a single device?

