Intel's HDCP DRM Scheme Defeated by a Single Sub-$300 FPGA
November 28, 2011 10:25 AM
comment(s) - last by
Researchers say pirates will likely use easier routes to crack the scheme, but that espionage risk is possible
Intel Corp. (
) has enjoyed a profitable ride off its
High-bandwidth Digital Content Protection (HDCP) hardware
, which sits inside nearly every TV/computer monitor with HDMI or DVI input. The HDMI/DVI chips with HDCP functionality open a secure encrypted channel from a source (e.g. a Blu-ray player) to a computer monitor or TV.
I. Defeating HDCP Was Easy
other content protection schemes were defeated
, HDCP hung strong. But in 2010, the
master key leaked for HDCP
giving the world the first hope of cracking the scheme. But Intel reassured its partners that they had nothing to worry about -- they laughed that unless would-be hardware hackers "made a computer chip" the scheme would be safe.
The only thing they forgot about was the growing amount of cheap reprogrammable chips known as field programmable gate arrays (FPGAs), which allow you to quickly make and test chip designs in software.
Using an ATLYS board manufactured by a company named Digilent, researchers at the
(RUB) -- a college in the town of Bochum, located roughly 2 hr. and 15 min. northwest of Frankfurt -- were able to carry out a-man-in-the-middle attack, with the FPGA posing as a legitimate interface chip and going undetected.
Prof. Dr.-Ing. Tim Güneysu, the principal investigator and senior author of the work
[press release], "We developed an independent hardware solution instead, based on a cheap FPGA board. We were able to tap the HDCP encrypted data streams, decipher them and send the digital content to an unprotected screen via a corresponding HDMI 1.3-compatible receiver."
The ATLYS board cost only 200€ (~$267). The board comes with a Xilinx, Inc. (
) Spartan-6 series FPGA, DRAM, HDMI interfaces, and a serial RS232 port. Most of the work on the project was carried out by final-year student Benno Lomb.
The little board that slew HDCP 1.x. [Image Source: RUB]
Dr.-Ing. Güneysu summarizes Intel's claims of invulnerability as foolish arrogance. He states, "[O]ur intention was to fundamentally investigate the safety of the HDCP system and to financially assess the actual cost for the complete knockout. The fact that we have achieved our goal in a degree thesis and with material costs of approximately 200 Euro definitely does not speak for the safety of the current HDCP system."
II. The Current Dangers -- Piracy, Not so Much, Espionage Maybe.
The work will be presented at the international security conference
in Cancun, Mexico, which is being held between Nov. 30 (Wed.) and Dec. 2 (Fri.).
It is unknown whether the team will publish their FPGA code, which could allow pirates and hardware hackers to buy FPGAs and defeat the protection. However, they insist that their goal was not to promote piracy. They say there's other far simpler ways of defeating HDCP available to pirates.
In October 2008 Intel
HDCP 2.0, which provides additional protection against this kind of attack. The hardware is currently on HDCP 2.1. But legacy systems abound and remain vulnerable to the HDCP 1.x capable attacks. The researchers say this could pose a security threat to the military or government agencies.
This article is over a month old, voting and posting comments is disabled
11/29/2011 6:21:16 AM
This isn't relevant for bluray discs - they can be copied and decrypted with a free program like imgburn. This HDCP crack is a win for people who want to record stuff from their cable box's HDMI out, or for people who have a TV with HDMI in but no HDCP support.
12/1/2011 12:21:16 PM
It would be useful for more than just recording from a cable box though. If a mass produced version of a board that could do this was released for an affordable price, I'd buy one just so I didn't have to deal with the HDCP errors that I sometimes get trying to show legit media on my HDTV that does support HDCP- cable PPV is the worst culprit, but I get the same errors occassionally with other cable content too.
"I modded down, down, down, and the flames went higher." -- Sven Olsen
High-Def. DRM Master Key Crack Confirmed by Intel
September 17, 2010, 11:48 AM
AnyDVD HD Defeats HD DVD Copy Protection
February 19, 2007, 11:37 AM
First Real HDCP NVIDIA Cards
June 7, 2006, 3:32 PM
Microsoft Channels LittleBigPlanet and Minecraft With "Project Spark" Beta
December 4, 2013, 9:14 AM
Software Firm Apptricity Receives $50 Million in U.S. Army Piracy Lawsuit
November 29, 2013, 11:42 AM
EA and Tiger Woods Part ways, EA Sports Offers First Look at Next Gen Golf Game
October 29, 2013, 9:27 AM
Quick Note: Trial Versions of iWork, Aperture Updated for Free by Mac App Store
October 24, 2013, 12:53 PM
Crytek "Warface" Opens New Era of AAA In-Browser FPS Gaming
October 22, 2013, 3:00 PM
Microsoft Rolls Out Windows 8.1
October 17, 2013, 11:52 AM
Most Popular Articles
NSA Snares Americans' Porn Viewing Histories in Effort to Target Muslims
December 1, 2013, 9:00 PM
Coalition of 20+ Tech Firms Backs MRAM as Potential DRAM, NAND Replacement
November 29, 2013, 11:59 PM
Dow Chemical to NYC City Council: You Don't Even Know What Styrofoam is!
December 2, 2013, 8:30 PM
Fed Up With Cheating OEMs, Microsoft Trolls Chromebooks in New Ad
November 27, 2013, 4:09 PM
OCZ Goes Bankrupt, SSD Assets are Targeted by Toshiba
December 1, 2013, 9:58 PM
Latest Blog Posts
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
Is The Period Becoming an Expression of Anger?
Nov 26, 2013, 2:02 PM
NSA and Congress -- You Will Never Kill the Constitution, It's an Idea
Nov 10, 2013, 2:00 PM
AT&T Explores $100B+ USD Deal to Acquire Vodafone's European Operations
Nov 4, 2013, 7:34 AM
U.S. Army Developing Cyber, Electronic War Arsenal
Oct 31, 2013, 4:49 PM
More Blog Posts
Copyright 2013 DailyTech LLC. -
Terms, Conditions & Privacy Information