Skip to content

Act II · HSMs and side channels

The machine that whispers

A hardware security module (HSM) is a sealed computer that holds secret keys and uses them inside the device, without exposing them. Locking a key in a box is only half the job, because machines also leak secrets through radio signals, power use and how long they take to answer. An HSM is built to resist being opened and to limit those leaks. This page explains how, and why a simple PIN checker can give its PIN away just by being slow.

A perfect lock in an imperfect room

At Los Alamos in the 1940s, the young physicist Richard Feynman opened the safes holding the atomic bomb designs, for fun. He didn't force them. He noticed things: combinations left at their factory settings, and the last numbers of a dial read off a safe left open while its owner talked. The locks never broke. Everything around them leaked.

The point carries over to every machine that holds a secret. A strong lock and the habits around it can fail in different ways. The rooms, the notes in the safes and the HSM in this act are illustrations, not photographs of real scenes or products.

Secrets leak through walls

In 1985, the Dutch researcher Wim van Eck showed that a computer screen could be read from a distance by picking up the radio signals it gives off. The wider problem is older and has a code name, TEMPEST. A declassified NSA history describes signals escaping through the air and along cables, and defenses such as shielding and filtering.

In the story, a visible glow stands for a signal that carries information. It isn't a literal picture of radio waves, a claim that every screen is equally easy to read, or a claim that every HSM has been tested against this kind of leak.

What's inside an HSM

The teardown follows the layers of protection inward. The metal case is the first wall. Under the lid, a fine web of wires called a tamper mesh notices if someone cuts, drills or probes. At the center is a smaller sealed box that holds the key, or, as in this act, one share of a signing key like the shares in Act I. It keeps the share in memory that needs constant power, signs inside the box, and sends out only the signature. If the mesh is triggered, the HSM cuts that power, the share disappears, and signing stops.

Real HSMs are judged against standards such as FIPS 140-3, the US government's requirements for cryptographic modules. They cover a clearly defined boundary, how the device is accessed, who can use it, how it's physically protected and how keys are handled. What a particular device actually does depends on the product and how it was certified. A dramatic cutaway isn't evidence of any certification.

How a rejected PIN can still leak

The timing test uses a PIN checker that compares a guess one digit at a time and stops at the first wrong digit. A guess with the right first digit makes it check the second digit too, and that extra step takes a little longer. So among ten guesses, each starting with a different digit, the slowest rejection reveals the first digit. Keep that digit, try 0–9 in the next position, and repeat. The checker never prints the PIN. Its timing gives it away.

The last digit is different. Every guess that reaches it is checked all the way to the end, so they all take the same time. Only the correct guess is accepted, and that confirms the PIN. The lab exaggerates the time differences so you can see them, and each bar averages eight tries. In 1996, Paul Kocher showed that the same kind of leak, in how long a calculation takes, can expose secret keys in real cryptographic software. The PIN checker is a much simpler example of that idea.

The fix: do the same work every time

The fix is to compare all four digits on every guess, whether they match or not. This is called constant-time checking. Run the same guesses again and their times look alike, because matching digits no longer change the amount of work. The correct PIN is still accepted. The leak is gone, but a PIN that has already leaked stays known.

"Constant time" means the work no longer depends on the secret. It doesn't mean every reading is identical, and it doesn't stop every kind of leak.

What you can try

Scroll through the HSM as it comes apart, layer by layer, from the outer case to the sealed box that holds the key. Then try the timing attack: find the slowest rejected guess, use it to recover a four-digit PIN, then fix the checker and test the same guesses again.

Where the model stops

The hardware is an illustration, not a teardown of a real product or a claim about any certification. Real HSMs still give off heat and radio signals; the aim is to stop those from revealing secrets. The timing bars are calculated from how many digits each guess checks, with a little added randomness. They aren't measured from an HSM or from your browser, and the lab doesn't show that code in a browser runs in constant time.

Narration transcript

The narration as spoken in Act II. The explanation above covers what the illustrations leave out.

Los Alamos, 1944.

The designs for the atomic bomb live in filing cabinets, behind combination locks.

A young physicist named Richard Feynman opened them, for fun. Not by force. By noticing.

Combinations left at factory defaults.

The last two numbers of a dial, read off a lock left open while its owner talked.

The locks never broke. Everything around them was leaking.

He left notes in the safes, so they'd know he'd been there.

The joke made the point better than any report: a perfect lock, in an imperfect room, protects nothing.

Forty years later, a Dutch researcher named Wim van Eck parked outside an office

and read the screen inside, off the faint radio glow every monitor sheds.

Through the wall. With a few hundred dollars of equipment.

That is the uncomfortable truth about machines that touch secrets. They don't leak through their doors.

They leak through their walls, as heat, as radio, as power drawn from the socket, as the tiny differences in how long things take.

So we built a machine with one obsession: whisper nothing. No warmth. No static. No rhythm in its timing.

It is sitting in a rack in a bank right now, holding keys like yours.

This is where a secret lives. We are going to cut one open.

Watch the story →

Sources