Prime and Prejudice

Prime and Prejudice
复制标题

最初与偏见

DOI:
10.1145/3243734.3243787
复制
发表时间:
2018
期刊:
--
影响因子:
--
通讯作者:
Albrecht M
Albrecht M
中科院分区:
--
文献类型:
--
作者:
Albrecht M

文献摘要

参考文献

被引文献

相似文献

这项工作提供了对抗性条件下的素数测试的系统分析,其中被测试的素数不是随机生成的,而是由可能的恶意方提供的。这种情况可能出现在服务器向对等端提供Diffie-Hellman参数的安全消息传递协议中,或者在像TLS这样的安全通信协议中,开发人员可以插入这样的数字,以便以后能够被动地监视客户机-服务器数据。我们研究了广泛的加密库,并评估了它们在这种对抗性设置中的性能。作为我们研究结果的例子,我们能够通过OpenSSL的素数测试在其默认配置中构建2048位的合数,其概率为(1/16)素数;广告的性能是(2-80)。我们还可以构造1024位的组合,当配置了推荐的最小轮数时,它总是通过GNU GMP中的素数测试例程。而且,对于许多库(Cryptlib、LibTomCrypt、JavaScript Big number、WolfSSL),我们可以构建总能通过提供的素数测试的复合库。我们探讨了应用程序中这些安全故障的含义,重点是恶意Diffie-Hellman参数的构造。我们表明,除非进行仔细的素数测试,否则对手可以提供表面上看起来安全的参数(p,q,g),但其中g生成的q阶子群中的离散对数问题很容易。最后,我们向用户和开发人员提出建议。特别是,我们推广了Baillie-PSW素数测试,该测试既有效又被推测在对抗设置中对高达几千位的数字具有鲁棒性。
This work provides a systematic analysis of primality testing under adversarial conditions, where the numbers being tested for primality are not generated randomly, but instead provided by a possibly malicious party. Such a situation can arise in secure messaging protocols where a server supplies Diffie-Hellman parameters to the peers, or in a secure communications protocol like TLS where a developer can insert such a number to be able to later passively spy on client-server data. We study a broad range of cryptographic libraries and assess their performance in this adversarial setting. As examples of our findings, we are able to construct 2048-bit composites that are declared prime with probability (1/16) by OpenSSL's primality testing in its default configuration; the advertised performance is (2-80). We can also construct 1024-bit composites that always pass the primality testing routine in GNU GMP when configured with the recommended minimum number of rounds. And, for a number of libraries (Cryptlib, LibTomCrypt, JavaScript Big Number, WolfSSL), we can construct composites that always pass the supplied primality tests. We explore the implications of these security failures in applications, focusing on the construction of malicious Diffie-Hellman parameters. We show that, unless careful primality testing is performed, an adversary can supply parameters (p,q,g) which on the surface look secure, but where the discrete logarithm problem in the subgroup of order q generated by g is easy. We close by making recommendations for users and developers. In particular, we promote the Baillie-PSW primality test which is both efficient and conjectured to be robust even in the adversarial setting for numbers up to a few thousand bits.
DOI: 10.1037/0022-3514.81.5.842
发表时间: 2001-11
影响因子: 7.6
作者:
Brian S. Lowery;Curtis D. Hardin;S. Sinclair
通讯作者: Brian S. Lowery;Curtis D. Hardin;S. Sinclair
DOI: 10.1177/1368430207084847
发表时间: 2008-01-01
影响因子: 4.4
作者:
Hofmann, Wilhelm;Gschwendner, Tobias;Schmitt, Manfred
通讯作者: Schmitt, Manfred
DOI: 10.1111/j.1744-6570.2006.00079.x
发表时间: 2006
影响因子: 5.5
作者:
Patrick F. McKay;Derek R. Avery
通讯作者: Derek R. Avery
拓宽刻板印象和偏见的视角:魅力城市的视角
DOI: 10.1017/iop.2016.53
发表时间: 2016
期刊: Industrial and Organizational Psychology
影响因子: --
作者:
Sally D. Farley;Rebecca J. Thompson
通讯作者: Rebecca J. Thompson
年龄、种族和隐性偏见
DOI: --
发表时间: 2009
期刊: Psychology Science
影响因子: --
作者:
B. Stewart;William von Hippel;G. Radvansky
通讯作者: G. Radvansky