Vše

Co hledáte?

Vše
Projekty
Výsledky výzkumu
Subjekty

Rychlé hledání

  • Projekty podpořené TA ČR
  • Významné projekty
  • Projekty s nejvyšší státní podporou
  • Aktuálně běžící projekty

Chytré vyhledávání

  • Takto najdu konkrétní +slovo
  • Takto z výsledků -slovo zcela vynechám
  • “Takto můžu najít celou frázi”

Large-Scale Security Analysis of Hardware Wallets

Identifikátory výsledku

  • Kód výsledku v IS VaVaI

    <a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14330%2F25%3A00141766" target="_blank" >RIV/00216224:14330/25:00141766 - isvavai.cz</a>

  • Výsledek na webu

    <a href="http://dx.doi.org/10.1007/978-3-032-00633-2_21" target="_blank" >http://dx.doi.org/10.1007/978-3-032-00633-2_21</a>

  • DOI - Digital Object Identifier

    <a href="http://dx.doi.org/10.1007/978-3-032-00633-2_21" target="_blank" >10.1007/978-3-032-00633-2_21</a>

Alternativní jazyky

  • Jazyk výsledku

    angličtina

  • Název v původním jazyce

    Large-Scale Security Analysis of Hardware Wallets

  • Popis výsledku v původním jazyce

    Cryptocurrency hardware wallets (HWWs) are dedicated offline devices that securely store cryptographic keys and perform internal message signing to prevent key exposure. Signing typically requires physical user interaction – such as pressing a button or using a fingerprint sensor – which provides strong protection against compromised hosts. However, this physical requirement significantly hinders independent, automated testing on real devices, often forcing reliance on software emulators or vendor claims. We introduce a low-cost, fully automated, and reproducible testing platform to address this limitation. The platform replicates essential human interactions, including physical button presses and touchscreen inputs, incorporates Optical Character Recognition (OCR) for extracting screen content, and records precise timing metadata. These capabilities enable us to perform a comprehensive evaluation of HWWs. Using this automated platform, we collected a dataset containing 3.4 million wallet recovery phrases, 3.4 million Elliptic Curve Digital Signature Algorithm (ECDSA) signatures, and the corresponding timing measurements. Data acquisition was performed on 17 hardware wallet models from 11 different vendors, using firmware versions available in 2023 and in 2025 to enable a comparative analysis. The data examination revealed several details about internal implementation characteristics, yet no significant cryptographic weaknesses were identified. This outcome is particularly interesting given the recent emergence of elliptic-curve cryptography (ECC) vulnerabilities, such as TPM-Fail, Minerva, or TPM-Scan, for example. Several factors are proposed to explain the comparatively stronger security posture observed in HWWs, including domain-specific design choices and operational constraints that may provide inherent resilience, even in the absence of formal certification processes.

  • Název v anglickém jazyce

    Large-Scale Security Analysis of Hardware Wallets

  • Popis výsledku anglicky

    Cryptocurrency hardware wallets (HWWs) are dedicated offline devices that securely store cryptographic keys and perform internal message signing to prevent key exposure. Signing typically requires physical user interaction – such as pressing a button or using a fingerprint sensor – which provides strong protection against compromised hosts. However, this physical requirement significantly hinders independent, automated testing on real devices, often forcing reliance on software emulators or vendor claims. We introduce a low-cost, fully automated, and reproducible testing platform to address this limitation. The platform replicates essential human interactions, including physical button presses and touchscreen inputs, incorporates Optical Character Recognition (OCR) for extracting screen content, and records precise timing metadata. These capabilities enable us to perform a comprehensive evaluation of HWWs. Using this automated platform, we collected a dataset containing 3.4 million wallet recovery phrases, 3.4 million Elliptic Curve Digital Signature Algorithm (ECDSA) signatures, and the corresponding timing measurements. Data acquisition was performed on 17 hardware wallet models from 11 different vendors, using firmware versions available in 2023 and in 2025 to enable a comparative analysis. The data examination revealed several details about internal implementation characteristics, yet no significant cryptographic weaknesses were identified. This outcome is particularly interesting given the recent emergence of elliptic-curve cryptography (ECC) vulnerabilities, such as TPM-Fail, Minerva, or TPM-Scan, for example. Several factors are proposed to explain the comparatively stronger security posture observed in HWWs, including domain-specific design choices and operational constraints that may provide inherent resilience, even in the absence of formal certification processes.

Klasifikace

  • Druh

    D - Stať ve sborníku

  • CEP obor

  • OECD FORD obor

    10200 - Computer and information sciences

Návaznosti výsledku

  • Projekt

  • Návaznosti

    S - Specificky vyzkum na vysokych skolach

Ostatní

  • Rok uplatnění

    2025

  • Kód důvěrnosti údajů

    S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů

Údaje specifické pro druh výsledku

  • Název statě ve sborníku

    Lecture Notes in Computer Science, LNCS 15995

  • ISBN

    9783032006325

  • ISSN

    0302-9743

  • e-ISSN

    1611-3349

  • Počet stran výsledku

    18

  • Strana od-do

    360-377

  • Název nakladatele

    Springer, Cham

  • Místo vydání

    Cham

  • Místo konání akce

    Ghent, Belgium

  • Datum konání akce

    1. 1. 2025

  • Typ akce podle státní příslušnosti

    WRD - Celosvětová akce

  • Kód UT WoS článku

    001582782000021