UCSD-led team simulates HSM operations without extracting keys

UCSD-led team simulates HSM operations without extracting keys

N
News Editor
2026-09-28 21:24:36
A research team led by the University of California, San Diego said it was able to simulate the operation of a hardware security module, or HSM, without extracting the cryptographic keys stored inside the device. The method targeted a weakness in the RSA signing process rather than breaking into the module to pull out secret material. According to the report, the attack worked by sending a large number of carefully crafted signing requests to the HSM and then examining side-channel signals such as response timing. Using that information, the researchers were ultimately able to forge valid digital signatures. The finding points to a potential security risk for crypto exchanges, custody providers, and blockchain networks that rely on HSMs for key management and transaction signing. The researchers said the result shows that even physically isolated hardware can still face remote attack risk, and that stronger defensive measures may be needed across the industry. The item was cited by Techub and attributed to Decrypt.

A research team led by the University of California, San Diego (UCSD) said it successfully simulated the operation of a hardware security module, or HSM, without extracting the cryptographic keys stored inside the device.

The method targeted RSA signing

The attack exploited a weakness in the RSA signing process. Researchers sent a large number of carefully crafted signing requests to the HSM and analyzed side-channel information, including response timing. They were ultimately able to forge valid digital signatures.

Potential implications for crypto infrastructure

The researchers said the finding presents a potential security threat to cryptocurrency exchanges, custody services, and blockchain networks that depend on HSMs for key management and transaction signing. It also shows that even physically isolated hardware may still be exposed to remote attack risk, which the team said warrants closer attention and stronger protections.

The item was published by Techub and attributed to Decrypt.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.