The Hidden Number Problem with Small Unknown Multipliers: Cryptanalyzing MEGA in Six Queries and Other Applications

The Hidden Number Problem with Small Unknown Multipliers: Cryptanalyzing MEGA in Six Queries and Other Applications
复制标题

DOI:
10.1007/978-3-031-31368-4_6
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
N. Heninger;Keegan Ryan
N. Heninger;Keegan Ryan
中科院分区:
其他
文献类型:
--
作者:
N. Heninger;Keegan Ryan

文献摘要

被引文献

相似文献

在最近的工作中,Backendal、Haller和Paterson在云存储提供商MEGA中发现了几个可利用的漏洞。他们演示了RSA密钥恢复攻击,其中恶意服务器可以在512次客户端登录尝试后恢复客户端的RSA私钥。我们展示了如何利用MEGA协议漏洞所揭示的额外信息来进行攻击,只需要六个客户端登录即可恢复密钥。我们的优化攻击结合了几种密码分析技术。特别是,我们制定并给出一个解决方案的一个变种的隐藏数问题的小未知乘数,这可能是独立的利益。我们表明,我们的格结构,这个问题可以用来给隐式分解问题的五月和Ritzenhofen的改进结果。
In recent work, Backendal, Haller, and Paterson identified several exploitable vulnerabilities in the cloud storage provider MEGA. They demonstrated an RSA key recovery attack in which a malicious server could recover a client’s private RSA key after 512 client login attempts. We show how to exploit additional information revealed by MEGA’s protocol vulnerabilities to give an attack that requires only six client logins to recover the secret key.Our optimized attack combines several cryptanalytic techniques. In particular, we formulate and give a solution to a variant of the hidden number problem with small unknown multipliers, which may be of independent interest. We show that our lattice construction for this problem can be used to give improved results for the implicit factorization problem of May and Ritzenhofen.