Attacks and Defenses for Single-Stage Residue Number System PRNGs

Attacks and Defenses for Single-Stage Residue Number System PRNGs
复制标题

DOI:
10.3390/iot2030020
复制
发表时间:
2021-06
期刊:
IoT
影响因子:
--
通讯作者:
A. Vennos;Kiernan B. George;Alan J. Michaels
A. Vennos;Kiernan B. George;Alan J. Michaels
中科院分区:
--
文献类型:
--
作者:
A. Vennos;Kiernan B. George;Alan J. Michaels

文献摘要

相似文献

本文探讨了一个单阶段的剩余数系统(RNS)的伪随机数发生器(PRNG),它以前已被证明提供极高质量的输出时,通过可用的RNG统计测试套件或使用香农和单阶段Kolmogorov熵度量进行评估的安全性。相比之下,而不是盲目地执行单级RNS PRNG的输出上的统计分析,本文提供了白色盒和黑盒分析,便于反向工程的基础RNS数生成算法,以获得残留物,或等效的密钥,RNS算法。我们开发和展示了一个条件熵分析,允许提取的关键给定的先验知识的状态转换以及逆向工程的RNS PRNG算法和参数(但不是关键)的问题中,乘法RNS特性太大,以获得先验的状态转换。然后,我们讨论了多种防御和干扰的RNS系统,欺骗原来的攻击算法,包括故意的噪声注入和跳码。我们提出了一个修改的算法,占故意噪声,但迅速增加搜索空间和复杂性。最后,我们讨论了内存需求和攻击者和防御者维护这些防御所需的时间。
This paper explores the security of a single-stage residue number system (RNS) pseudorandom number generator (PRNG), which has previously been shown to provide extremely high-quality outputs when evaluated through available RNG statistical test suites or in using Shannon and single-stage Kolmogorov entropy metrics. In contrast, rather than blindly performing statistical analyses on the outputs of the single-stage RNS PRNG, this paper provides both white box and black box analyses that facilitate reverse engineering of the underlying RNS number generation algorithm to obtain the residues, or equivalently key, of the RNS algorithm. We develop and demonstrate a conditional entropy analysis that permits extraction of the key given a priori knowledge of state transitions as well as reverse engineering of the RNS PRNG algorithm and parameters (but not the key) in problems where the multiplicative RNS characteristic is too large to obtain a priori state transitions. We then discuss multiple defenses and perturbations for the RNS system that fool the original attack algorithm, including deliberate noise injection and code hopping. We present a modification to the algorithm that accounts for deliberate noise, but rapidly increases the search space and complexity. Lastly, we discuss memory requirements and time required for the attacker and defender to maintain these defenses.