Practical State Recovery Attacks against Legacy RNG Implementations

Practical State Recovery Attacks against Legacy RNG Implementations
复制标题

针对传统 RNG 实施的实用状态恢复攻击

DOI:
10.1145/3243734.3243756
复制
发表时间:
2018
期刊:
CCS '18 Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Heninger, Nadia
Heninger, Nadia
中科院分区:
--
文献类型:
--
作者:
Cohney, Shaanan N.;Green, Matthew D.;Heninger, Nadia

文献摘要

参考文献

被引文献

相似文献

ANSI X9.17/X9.31伪随机数发生器设计于1985年首次标准化,在接下来的三十年中,其变体被纳入了众多密码标准。该设计使用时间戳和静态密钥块密码来产生伪随机输出。自1998年以来,人们就知道密钥必须保密,以保证输出的安全。然而,无论是FIPS 140-2标准化过程还是NIST后来对算法的描述都没有指定任何密钥生成过程。我们对数百种实现ANSI X9.31随机数生成器的产品的公开可用的FIPS 140- 2认证进行了系统研究,发现12种产品的认证文档在源代码中使用静态硬编码密钥,使实现容易受到攻击者的攻击,攻击者可以从源代码或二进制文件中学习此密钥。为了证明这种攻击的实用性,我们使用FortiOS v4开发了一种针对FortiGate VPN网关产品的完全被动解密攻击,可以在几秒钟内恢复私钥。我们使用主动扫描来测量可见互联网上此漏洞的流行程度,并在野外演示状态恢复和完全私钥恢复。我们的工作突出了验证和认证过程未能提供哪怕是适度的安全保障的程度。
The ANSI X9.17/X9.31 pseudorandom number generator design was first standardized in 1985, with variants incorporated into numerous cryptographic standards over the next three decades. The design uses timestamps together with a statically keyed block cipher to produce pseudo-random output. It has been known since 1998 that the key must remain secret in order for the output to be secure. However, neither the FIPS 140-2 standardization process nor NIST's later descriptions of the algorithm specified any process for key generation. We performed a systematic study of publicly available FIPS 140- 2 certifications for hundreds of products that implemented the ANSI X9.31 random number generator, and found twelve whose certification documents use of static, hard-coded keys in source code, leaving the implementation vulnerable to an attacker who can learn this key from the source code or binary. In order to demonstrate the practicality of such an attack, we develop a full passive decryption attack against FortiGate VPN gateway products using FortiOS v4 that recovers the private key in seconds. We measure the prevalence of this vulnerability on the visible Internet using active scans, and demonstrate state recovery and full private key recovery in the wild. Our work highlights the extent to which the validation and certification process has failed to provide even modest security guarantees.
ANSI-NIST 椭圆曲线 RNG 的安全性推测
DOI: --
发表时间: 2006
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Daniel R. L. Brown
通讯作者: Daniel R. L. Brown
DOI: --
发表时间: 2017
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Fabrice Boudot
通讯作者: Fabrice Boudot
DOI: --
发表时间: 2016
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Stephen Checkoway;Shaanan N. Cohney;Christina Garman;M. Green;N. Heninger;Jacob Maskiewicz;E. Rescorla;H. Shacham;R. Weinmann
通讯作者: R. Weinmann
基于ISAKMP(互联网安全关联和密钥管理协议)的可扩展认证方法及系统
DOI: --
发表时间: 2011
期刊:
影响因子: --
作者:
梁小萍;韦银星
通讯作者: 韦银星
如何吃掉你的熵并拥有它:受损 RNG 的最佳恢复策略
DOI: --
发表时间: 2017
期刊: Algorithmica
影响因子: 1.1
作者:
Y. Dodis;A. Shamir;Noah Stephens;Daniel Wichs
通讯作者: Daniel Wichs