Attacking Deterministic Signature Schemes Using Fault Attacks

Attacking Deterministic Signature Schemes Using Fault Attacks
复制标题

使用故障攻击来攻击确定性签名方案

DOI:
10.1109/eurosp.2018.00031
复制
发表时间:
2018
期刊:
2018 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
Paul Rösler
Paul Rösler
中科院分区:
--
文献类型:
--
作者:
D. Poddebniak;Juraj Somorovsky;Sebastian Schinzel;M. Lochter;Paul Rösler

文献摘要

参考文献

被引文献

相似文献

许多数字签名方案依赖于每个签名唯一且不可预测的随机数。随机数生成器的故障可能会产生灾难性的影响,例如泄露私人签名密钥。近年来,许多广泛使用的密码技术采用确定性签名方案,因为它们被认为是更安全的实现。在本文中,我们分析了确定性ECDSA和EdDSA签名方案的安全性,并表明,在这些计划中的随机数生成器的消除,使新的故障攻击。我们正式这些攻击,并介绍了实际的攻击方案对EdDSA使用Rowhammer故障攻击。EdDSA被用于许多广泛使用的协议,如TLS,SSH和IPSec,我们表明,这些协议是不容易受到我们的攻击。我们形式化的必要要求,使用这些确定性签名方案的协议是脆弱的,并讨论缓解策略及其对确定性签名方案的故障攻击的影响。
Many digital signature schemes rely on random numbers that are unique and non-predictable per signature. Failures of random number generators may have catastrophic effects such as compromising private signature keys. In recent years, many widely-used cryptographic technologies adopted deterministic signature schemes because they are presumed to be safer to implement. In this paper, we analyze the security of deterministic ECDSA and EdDSA signature schemes and show that the elimination of random number generators in these schemes enables new kinds of fault attacks. We formalize these attacks and introduce practical attack scenarios against EdDSA using the Rowhammer fault attack. EdDSA is used in many widely used protocols such as TLS, SSH, and IPSec, and we show that these protocols are not vulnerable to our attack. We formalize the necessary requirements of protocols using these deterministic signature schemes to be vulnerable, and discuss mitigation strategies and their effect on fault attacks against deterministic signature schemes.
DOI: --
发表时间: 2016
期刊: --
影响因子: --
作者:
Yuan Xiao;Xiaokuan Zhang;Yinqian Zhang;R. Teodorescu
通讯作者: Yuan Xiao;Xiaokuan Zhang;Yinqian Zhang;R. Teodorescu