Attacking Deterministic Signature Schemes Using Fault Attacks
Attacking Deterministic Signature Schemes Using Fault Attacks
复制标题
使用故障攻击来攻击确定性签名方案
DOI:
10.1109/eurosp.2018.00031
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Paul Rösler
中科院分区:
文献类型:
--
作者:
D. Poddebniak;Juraj Somorovsky;Sebastian Schinzel;M. Lochter;Paul Rösler
Many digital signature schemes rely on random numbers that are unique and non-predictable per signature. Failures of random number generators may have catastrophic effects such as compromising private signature keys. In recent years, many widely-used cryptographic technologies adopted deterministic signature schemes because they are presumed to be safer to implement. In this paper, we analyze the security of deterministic ECDSA and EdDSA signature schemes and show that the elimination of random number generators in these schemes enables new kinds of fault attacks. We formalize these attacks and introduce practical attack scenarios against EdDSA using the Rowhammer fault attack. EdDSA is used in many widely used protocols such as TLS, SSH, and IPSec, and we show that these protocols are not vulnerable to our attack. We formalize the necessary requirements of protocols using these deterministic signature schemes to be vulnerable, and discuss mitigation strategies and their effect on fault attacks against deterministic signature schemes.
DOI:
--
发表时间:
2016
期刊:
--
影响因子:
--
作者:
Yuan Xiao;Xiaokuan Zhang;Yinqian Zhang;R. Teodorescu
通讯作者:
Yuan Xiao;Xiaokuan Zhang;Yinqian Zhang;R. Teodorescu