News

Paper: principles on the Security of AES Against DPA

Posted on 28 Apr 10

June 22-25, Beijing, China

Jing Pan will present her paper "Principles on the Security of AES Against First and Second-Order Differential Power Analysis" at ACNS 2010 Beijing.

This paper shows that power leakage of some intermediate values from the more inner rounds of AES can be exploited to conduct first and/or second-order DPA attacks by employing techniques such as fixing certain plaintext/ciphertext bytes. We give five general principles on DPA vulnerability of unprotected AES implementations, and then give several general principles on DPA vulnerability of protected AES implementations.

For more information on this paper contact us via: inforequest@riscure.com.

Riscure joins Global Platform

Posted on 20 Apr 10

This week Riscure joins Global Platform as a participating member. Global Platform plays a leading role in setting standards and defining an evaluation/certification model for mobile payment solutions.
Riscure wants to actively contribute to the dialogue regarding security issues of mobile payment applications, secure elements and handsets.

“Global Platform has taken the initiative to propose an architecture that will enable Mobile Payment to emerge in a sound and cost-effective fashion”, say Marc Witteman, CTO at Riscure. “Riscure fully supports this initiative and wants to contribute to making mobile payment solutions secure and trustworthy by offering test methodology and tools”.

Challenge your Mobile Payment security

Posted on 19 Apr 10

Riscure conducts security testing on mobile payment technology. At present mobile payment is gaining momentum, however concerns on security are raised as soon as discussions start on mobile payment solutions.

As a result Riscure launched a new folder explaining how we can assist creating a secure environment for mobile payment solutions.

Do you have any questions regarding mobile payment security? You can meet us at Simposium 2010 in Rome, Italy or contact us via the contact information page.

BNR Nieuwsradio interviews Riscure

Posted on 16 Feb 10

BNR Nieuwsradio interviewed Harko Robroch and Fred de Beer about chip security testing and the features of the new Diode Laser Station.

Click here to listen to the radio fragment (in Dutch).

Standalone Inspector hardware with SDK

Posted on 16 Feb 10

Several Inspector hardware components are now also available with SDK. Riscure announces that in 2010 it starts providing the hardware components of its side channel test product with Software Development Kits (SDK). This means that customers can separately buy hardware components of the Inspector product and integrate this with their own software environment. The addition of SDKs is part of Riscure's strategy to provide a flexible and userfriendly solution for side channel testing.

Harko Robroch, Managing Director at Riscure, says: "Many side channel specialists at research institutes have built their own software environment for side channel testing and would like to extend this with our hardware components. With the SDK, they can now easily integrate our hardware with their software. This way, they can purchase exactly the component that they need most to extend their side channel testing capabilities."

From February 2010, the Diode Laser Station and the icWaves components are available with SDK. By mid 2010, the Power Tracer and EM Probe Station will also contain a SDK.

>> Read more about the Inspector product

New Diode Laser Station for optical fault attacks

Posted on 04 Feb 10

Riscure presents a new Diode Laser Station. Protecting chips against laser fault attacks is one of the main security challenges in the smart card industry. As the attacks evolve, security testing needs to meet the latest and the highest international standards to assess if a smart card is secured against laser attacks. With the Diode Laser Station advanced laser fault attacks can be carried out as it offers new features meeting the latest timing and power requests. The Diode Laser Station can both be used as a standalone device and integrated with the Inspector test tool.

Follow this link to view the Diode Laser Station datasheet.

Japanese independent administrative agency IPA selects Inspector for side channel analysis

Posted on 26 Aug 09

The Information-Technology Promotion Agency, Japan has selected Inspector for performing side channel analysis. IPA will use Inspector for performing side channel analysis of smart card products within their Common Criteria certification scheme. Furthermore, Inspector will be used for the Japan Cryptographic Module Validation Program (JCMVP), which is a Japanese certification program for cryptographic modules based on ISO/IEC 19790 which is standardized from the American FIPS-140 standard from NIST.

Besides for being a state-of-the-art side channel analysis tool, IPA has selected Inspector because of its integrated Software Development Environment allowing flexible and fast development of crypt analysis modules.

Pascal van Gimst, Director of Sales and Business development from Riscure says: “We are very proud that the Japanese independent administrative agency has selected Inspector to support their CC and JCMVP certification schemes, allowing Riscure to contribute to the success of security testing and certification in Japan.”

Riscure and Altech extend exclusive distribution agreement for Japanese market

Posted on 21 Aug 09

After a successful first year Riscure and Altech have extended their exclusive distribution agreement for the Japanese market. For the next three years Altech will be selling Riscure’s side channel test tool Inspector and Riscure’s Java Card Security Test tool JCworkBench exclusively in Japan.

Wataru Kitagawara, IC Card Division Manager from Altech, says: “We are very proud of announcing here that we have extended the distribution agreement with Riscure after the successful year in Japanese market by receiving great support from Riscure. We would hope and like to contribute to the Japanese standardization of security testing and outstanding success of IC Card industry in Japan. ”

Pascal van Gimst, Director Sales & Business Development from Riscure, says: “We are very pleased with the collaboration with Altech. Their commitment to sell our products in Japan has led to a successful start of our partnership. We are confident that together with Altech we will increase our contribution to the Japanese security industry.”

Riscure selects Veri Smart as reseller in China

Posted on 21 Jul 09

Veri Smart and Riscure join forces in China for exclusive distribution of the Inspector side channel test tool in the Chinese market. With this partnership, Riscure aims to further accelarate its deployment of the Inspector product in the Asian market. In 2009 and 2010, Veri Smart and Riscure are planning several road shows to demonstrate the product in China.

“As smart cards are widely used in China, its security problems have steadily reached the attention of more testing institutions and card providers" says James Su, Managing Director of Veri Smart Technology. "To provide the state-of-the-art security solution to the local market, Veri Smart has set up the partnership with Riscure, a leading security testing tools and solution provider, as Riscure's exclusive distributor in China. We hope through this tight cooperation, we can develop not only the commercial market, but also the technology communications between famous local security research institutes and Riscure, to build the image of Riscure and awareness of the advanced security solutions , as well support the existing customers. We trust the relationship will burst out of its astonishing power and glory. "

Harko Robroch, Managing Director at Riscure comments: “We are pleased that we have found a local partner in China that has excellent relationships in the local smart card industry and that has a very responsive approach towards customer questions. The need for a local partner clearly arose after the many requests from Chinese parties that we received for our side channel test product in the past six months. We are now looking forward to accelerate the roll out of Inspector to Chinese test labs, government agencies and manufacturers in the smart card industry. This will enable them to independently test the side channel resistance of chipsets.”

About Veri Smart Technology:

The Shanghai-based firm Veri Smart is specialised in tool distribution in the smart card industry in China, dedicated in distributing the professional testing tools and solutions from European suppliers to local market, bringing the European advanced smart card technology to help local business.

About Riscure:

Riscure offers security evaluation services, security training and security test equipment to global players that manufacture or deploy secure chip technology. Riscure is based in the Netherlands and is accredited as an EMVco lab for ICC security evaluations. Riscure's side channel test product called Inspector is used by organisations in the USA, Canada, Germany, Korea, Japan, France, Great Britain, Singapore and China.

Riscure achieves EMVco accreditation

Posted on 12 Jul 09

Riscure is an EMVco accredited security evaluation laboratory, and now offers VISA, MasterCard and CPA payment card security evaluations. Since June 2009, Riscure is recognized as an EMVCo Security Evaluation Laboratory to carry out ICC evaluations in accordance with the EMVCo Requirements for Security Evaluation Laboratories.

For several years Riscure has been recognized by MasterCard to perform CAST security evaluations. With the EMVco accreditation, Riscure can also offer security evaluations of Common Payment Application cards and VISA payment cards. With VISA moving from its black-box risk review towards white-box security evaluations, the VISA and MasterCard evaluation approaches are converging, which can result in a significant cost-reduction for vendors looking for VISA and MasterCard approval. Riscure can re-use a significant part of the evaluation effort when a vendor would like to have a VISA and a MasterCard payment card with the same underlying platform evaluated simultaneously.

Pascal van Gimst, Director of Sales and Business Development at Riscure, says: “Our flexible and customer-driven approach combined with our proven expertise in white-box smart card evaluations for the payment industry makes us a very suitable evaluation partner for vendors who aim for a short time-to-market for their high-security payment cards. In addition, having already performed a large number of mobile payment security evaluations during the past years involving SIM card, mobile phone and NFC technology, we are very well equipped to evaluate mobile payment solutions for vendors that want to obtain VISA or MasterCard approval”. 

Please contact Pascal van Gimst (vangimst@riscure.com, +31 15 251 4090) to find out about our attractive offer and conditions for these security evaluations.

Sponsor of CHES 2009

Posted on 12 May 09

Riscure is proud to be sponsor of CHES 2009. At the event, we will demonstrate a full version of our Inspector side channel test platform, including the most recently added VC Glitcher and icWaves hardware components.

CHES is the Workshop on Cryptographic Hardware and Embedded Systems which is held in Lausanne, Switzerland, this year. For more information on CHES 2009 please check www.chesworkshop.org.

RISCURE appoints new Director Sales & Business Development

Posted on 01 Oct 08

Riscure has appointed Pascal van Gimst to the position of Director Sales & Business Development. Pascal will be responsible for the sales of all services and products from Riscure. This includes security review and testing services, as well as the security test tools Inspector and JCworkBench.

"With more than 15 years of experience in the smart card and security industry, Pascal is very well equipped to further develop Riscure's position in the market as a laboratory that offers innovative and thorough security testing services”, said Harko Robroch, MD of Riscure. “With the growing demand for our security test tools, Pascal will further professionalize our distribution network around the world."

Pascal holds a B.Sc. in electrical engineering and started his career in security testing in 1993 at TNO in The Netherlands. Over the past fifteen years Pascal has been involved in hundreds of security evaluations and consulting projects for the smart card industry. These projects addressed the security of secure microcontrollers, smart card operating systems and applications, payment terminals, Host Security Modules and biometric systems for the payment, telecom, government and PayTV industry. Since 2002 Pascal has been involved in security from a business point of view dealing with sales, marketing and business development. Before joining Riscure Pascal was working at Brightsight managing the IC evaluations group and taking responsibility for marketing and business development.

First Inspector User Workshop

Posted on 02 Mar 08

Riscure announced to hold its first Inspector User Workshop in June this year. This workshop will be held on an annual basis with the objective to share user experiences and to update user on the latest developments on side channel analysis. Side channel specialists from all over the world will have an opportunity to meet with each other in an informal setting.

First time training on side channel protection at Black Hat Trainings

Posted on 01 Aug 07

Riscure is pleased to announce that it will be providing the first training ever on side channel protection of chips and embedded devices at the renowned Black Hat Trainings in Las Vegas, USA. The plan is that the side channel training will be recurring on an annual basis at Black Hat USA and Black Hat Europe.

Black Hat Trainings have been running an extensive program on security training for security professionals from all over the world.

Best Paper Award at WISTP

Posted on 08 May 07

Dennis Vermoen from Riscure receives a best paper award at WISTP 07 in Greece for Reverse Engineering Java Card Applets Using Power Analysis (pdf).

Inspector launched!

Posted on 01 May 05

Riscure launched the new security tool Inspector. Inspector is the first side-channel analysis tool on the market with a graphical user interface. The CardsNowAsia magazine published an article on Inspector [0.7 MB].

Move

Posted on 01 Jul 04

As of September 1, Riscure has moved to the Radex Innovation Centre in Delft.

Comment on Piracy Equipment

Posted on 17 Jul 03

Marc Witteman of Riscure comments on Security Focus on Pay-TV piracy equipment.