Search arXiv⌕ Search

arXiv subjects

Leonardo Teodoro

Publications and source records attributed to Leonardo Teodoro.

3 recordsLinked to original sources

Fast Frame Rate Estimation in Electromagnetic Side-Channel Attacks on Public Systems

Frame refresh rate estimation is a fundamental step in identifying compromising harmonic frequencies in electromagnetic side-channel attacks. Methods based on discrete linear autocorrelation (DLA) are robust across different scenarios and require a computational complexity of $O(N\log N)$ for a signal containing $N$ samples. This work proposes reducing this complexity to $O(N)$ by exploiting prior knowledge of the target system's display resolution, as is available for certain models of the Brazilian electronic voting machine. Experiments using software-defined radios show that the proposed method preserves the accuracy of the conventional approach in the evaluated scenarios.

eess.SP↗

Do Electromagnetic Side-Channel Attacks Threaten Electronic Polling Stations? Scenarios and Recommendations

This paper investigates the threat to ballot secrecy in the Brazilian electronic voting machine (UEB) posed by electromagnetic side-channel attacks, also known as TEMPEST attacks. In these attacks, screen content can be reconstructed remotely by intercepting electromagnetic emanations associated with the target device's video signal. This work is motivated by a recent ruling by a Brazilian electoral court concerning an attempt to violate ballot secrecy using electronic equipment. Based on publicly available information about the electoral system, attack scenarios against polling stations are proposed. Experiments using software-defined radio show that the effectiveness of TEMPEST attacks strongly depends on the lack of oversight resulting from public unawareness of the threat. Finally, awareness guidelines are proposed for voters, poll workers, and party representatives to mitigate attack risks within a polling station.

cs.CR↗

Pre-Characterization of Electromagnetic Side-Channel Leakage Using Publicly Available Information: A Case Study on E-Voting Interfaces

In this work, we study the interface of the Brazilian e-Voting Machine (BVM) in the context of electromagnetic side-channel threats commonly referred to as TEMPEST attacks. In a TEMPEST attack against video displays, an eavesdropper uses Software-Defined Radios (SDRs) to recover sensitive information by intercepting electromagnetic emanations generated during video signal transmission. We emulate the BVM using a VGA monitor by leveraging publicly available information disclosed by the electoral authority, including technical specifications, operational rules of the system, and the official BVM interface. Based on this setup, we investigate whether the BVM interface gives rise to a distinctive spectral signature observable through its unintended electromagnetic emissions. Our findings show that design characteristics relevant to a nationwide electoral process -- such as high image contrast, minimal on-screen information, and the prohibition of other electronic devices within the polling station -- result in a simple and highly distinctive spectral signature that can be observed even through a wall in our experiments. Although our experiments do not involve actual BVM hardware, the results raise concerns regarding the system's susceptibility to TEMPEST attacks and highlight the need for further research on protective countermeasures. In this context, our findings may support the design of automatic jammers capable of adaptively targeting compromising frequencies. To the best of our knowledge, this is the first study investigating TEMPEST attacks in the context of an electronic voting system officially adopted by a country.

cs.CR↗