Biased Nonce Sense: Lattice Attacks Against Weak ECDSA Signatures in Cryptocurrencies

Biased Nonce Sense: Lattice Attacks Against Weak ECDSA Signatures in Cryptocurrencies
复制标题

有偏见的 Nonce 意义:针对加密货币中弱 ECDSA 签名的格子攻击

DOI:
10.1007/978-3-030-32101-7_1
复制
发表时间:
2019
期刊:
FC 2019: Financial Cryptography and Data Security
影响因子:
--
通讯作者:
Heninger, Nadia
Heninger, Nadia
中科院分区:
--
文献类型:
--
作者:
Breitner, Joachim;Heninger, Nadia

文献摘要

相似文献

在本文中,我们通过对公共区块链中包含的数字签名和互联网范围的扫描进行密码分析攻击,计算了数百个比特币私钥和数十个以太坊、Ripple、SSH 和 HTTPS 私钥。 ECDSA 签名算法需要生成每条消息的秘密随机数。如果这个随机数不是随机均匀生成的,攻击者可能会利用这种偏差来计算长期签名密钥。我们使用基于格的算法来解决隐藏数字问题,以有效地计算由于多个明显的实现漏洞而与有偏差的签名随机数一起使用的 ECDSA 私钥。
In this paper, we compute hundreds of Bitcoin private keys and dozens of Ethereum, Ripple, SSH, and HTTPS private keys by carrying out cryptanalytic attacks against digital signatures contained in public blockchains and Internet-wide scans. The ECDSA signature algorithm requires the generation of a per-message secret nonce. If this nonce is not generated uniformly at random, an attacker can potentially exploit this bias to compute the long-term signing key. We use a lattice-based algorithm for solving the hidden number problem to efficiently compute private ECDSA keys that were used with biased signature nonces due to multiple apparent implementation vulnerabilities.