Cryptanalysis of Curl-P and Other Attacks on the IOTA Cryptocurrency

Cryptanalysis of Curl-P and Other Attacks on the IOTA Cryptocurrency
复制标题

针对 IOTA 加密货币的 Curl-P 和其他攻击的密码分析

DOI:
10.46586/tosc.v2020.i3.367-391
复制
发表时间:
2020
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Tadge Dryja
Tadge Dryja
中科院分区:
--
文献类型:
--
作者:
E. Heilman;Neha Narula;Garrett Tanzer;James Lovejoy;Michael Colavita;M. Virza;Tadge Dryja

文献摘要

被引文献

相似文献

我们提出了对 IOTA 区块链中以前使用的密码学的攻击,包括在某些条件下伪造签名的能力。我们对 IOTA 的加密哈希函数 Curl-P-27 开发了实用的攻击,使我们能够快速生成短的冲突消息。即使对于相同长度的消息,这些冲突也会发生。利用 Curl-P-27 中的这些弱点,我们突破了前 IOTA 签名方案 (ISS) 的 EUCMA 安全性。最后,我们表明,在选择消息设置中,我们可以伪造有效支出交易的签名和多重签名(在 IOTA 中称为捆绑包)。
We present attacks on the cryptography formerly used in the IOTA blockchain, including under certain conditions the ability to forge signatures. We developed practical attacks on IOTA’s cryptographic hash function Curl-P-27, allowing us to quickly generate short colliding messages. These collisions work even for messages of the same length. Exploiting these weaknesses in Curl-P-27, we broke the EUCMA security of the former IOTA Signature Scheme (ISS). Finally, we show that in a chosen-message setting we could forge signatures and multi-signatures of valid spending transactions (called bundles in IOTA).