Researchers conduct successful MITM attack on HDCP copy protection

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
H-Security said:
Researchers at the Secure Hardware Group at Germany's Ruhr University of Bochum, led by professor Tim Güneysu, have used a man-in-the-middle (MITM) attack to crack the copy protection system used by HDMI ports with relatively little effort. HDCP (High-bandwidth Digital Content Protection) was developed by Intel and is used to carry out the encrypted transfer of video signals via DVI, HDMI, DisplayPort and other connectors.

Although an HDCP master key, which forms the core element of the encryption system, was leaked in 2010, using it to build an HDCP-capable chip is, according to Güneysu, extremely complicated and expensive. Instead, together with PhD student Benno Lomb, he developed a standalone hardware solution based on a relatively inexpensive FPGA board, specifically Digilent's Atlys board, which has a Xilinx Spartan-6 FPGA containing the requisite HDMI port and a serial RS232 communication port.

According to Güneysu, the study was never about devising a way to make illegal copies. "Our intention was rather to investigate the fundamental security of HDCP systems and to measure the actual financial outlay for a complete knockout. The fact that we were able to achieve this in the context of a PhD thesis and using materials costing just €200 is not a ringing endorsement of the security of the current HDCP system," noted Güneysu. The cost given is what students would have to pay for the board; the regular list price is $350 (£225).

The man-in-the-middle attack, in which a middleman (the Atlys FPGA board) is able to modify all communications between a Blu-ray player and a flat screen TV without being detected, is, however, of no great practical use for pirates

Read more >>
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top