MS, Chrome, HP, Lenovo ¿î¿µÃ¼Á¦ »ç¿ëÀÚ ÃֽйöÀüÀ¸·Î º¸¾È ¾÷µ¥ÀÌÆ® ÇØ¾ß
[º¸¾È´º½º ±è°æ¾Ö ±âÀÚ] TPM Ĩ¼Â Á¦Ç°¿¡¼ ¾ÏÈ£±â¼ú Ãë¾àÁ¡(ROCA)ÀÌ ¹ß°ßµÅ °¢ Á¦Ç°º°·Î º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÇʼöÀûÀ¸·Î Àû¿ëÇØ¾ß ÇÑ´Ù.

[À̹ÌÁö= Infineon »çÀÌÆ® ĸó ȸé]
TPM(Trusted Platform Module)Àº RSA¿Í SHA-1 µîÀÇ ¾ÏÈ£È ±â¹ýÀ¸·Î ÆÐ½º¿öµå³ª µðÁöÅÐ ÀÎÁõ¼, ¾ÏÈ£È Å°¸¦ ÀúÀåÇØ ¸ÞÀκ¸µå ³»ºÎ¿¡¼ Çϵå¿þ¾î ÀåÄ¡µé°ú Åë½ÅÇϴ Ĩ¼Â ¸ðµâÀÌ´Ù.
À̹ø¿¡ ¹ß°ßµÈ Ãë¾àÁ¡Àº Ĩ¼Â ¾ÏÈ£È ¶óÀ̺귯¸®¿¡¼ °ø°ÝÀÚ°¡ °ø°³Å°¸¦ ¾Ë °æ¿ì, ÀμöºÐÇØ¸¦ ÅëÇØ RSA·Î ¾ÏÈ£ÈµÈ ºñ¹ÐŰÀÇ Á¤º¸ À¯ÃâÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2017-15361)ÀÌ´Ù.
ÀÌ¿Í °ü·Ã Infineon Technologies»ç´Â Ĩ¼Â Á¦Ç°(TPM)¿¡¼ ¹ß»ýÇÏ´Â ROCA(Coppersmith Return of Coppersmith Attack) Ãë¾àÁ¡À» °ø°³Çϸç, ¿µÇâ ¹Þ´Â ¹öÀü »ç¿ëÀÚ¸¦ ´ë»óÀ¸·Î ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÒ °ÍÀ» ´çºÎÇß´Ù.
º¸¾È ¾÷µ¥ÀÌÆ®°¡ °ø°³µÈ ¡âMicrosoft [2] ¡âChrome OS[3] ¡âHP[4] ¡âLenovo[5] ¿î¿µÃ¼Á¦¸¦ ¿î¿µÇϰí ÀÖÀ» °æ¿ì, ¾Æ·¡ »çÀÌÆ® ³»¿ëÀ» ÂüÁ¶ÇØ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼öÇàÇØ¾ß ÇÑ´Ù. Á»´õ ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)¿¡ ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
https://www.infineon.com/cms/en/product/promopages/tpm-update/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170012
https://sites.google.com/a/chromium.org/dev/chromium-os/tpm_firmware_update
https://support.hp.com/us-en/document/c05792935
https://support.lenovo.com/us/en/product_security/LEN-15552
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>