\input zb-basic \input zb-ioport \iteman{io-port 05364483} \itemau{Dyrkolbotn, Geir Olav; Snekkenes, Einar} \itemti{A wireless covert channel on smart cards. (Short paper).} \itemso{Ning, Peng (ed.) et al., Information and communications security. 8th international conference, ICICS 2006, Raleigh, NC, USA, December 4--7, 2006. Proceedings. Berlin: Springer (ISBN 978-3-540-49496-6/pbk). Lecture Notes in Computer Science 4307, 249-259 (2006).} \itemab Summary: Microprocessor devices, such as smart cards, are used more and more to store and protect secret information. This development has its advantages, but microprocessor devices are susceptible to various attacks. Much attention has been devoted to side-channel attacks, exploiting unintentional correlation between internal secret information, such as cryptographic keys, and the various side channels. We present a wireless covert channel attack (WCCA) that intentionally correlates secret information with the electromagnetic side channel. WCCA exploits subversive code hidden on all cards during manufacture, to launch an attack, without physical access, when infected cards are used. Experiments on modern smart cards confirm that an insider with the opportunity to hide subversive code can potentially broadcast the card's internal secrets to a nearby receiver. Security features against side-channel attacks will limit the range but not prevent the attack. \itemrv{~} \itemcc{} \itemut{smart cards; EMSide-channel; subversion; wireless covert channel} \itemli{doi:10.1007/11935308\_18} \end