Cryptanalysis of Curl-P and Other Attacks on the IOTA Cryptocurrency
Cryptanalysis of Curl-P and Other Attacks on the IOTA Cryptocurrency
复制标题
针对 IOTA 加密货币的 Curl-P 和其他攻击的密码分析
DOI:
10.46586/tosc.v2020.i3.367-391
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Tadge Dryja
中科院分区:
文献类型:
--
作者:
E. Heilman;Neha Narula;Garrett Tanzer;James Lovejoy;Michael Colavita;M. Virza;Tadge Dryja
We present attacks on the cryptography formerly used in the IOTA blockchain, including under certain conditions the ability to forge signatures. We developed practical attacks on IOTA’s cryptographic hash function Curl-P-27, allowing us to quickly generate short colliding messages. These collisions work even for messages of the same length. Exploiting these weaknesses in Curl-P-27, we broke the EUCMA security of the former IOTA Signature Scheme (ISS). Finally, we show that in a chosen-message setting we could forge signatures and multi-signatures of valid spending transactions (called bundles in IOTA).