USENIX Security2017Top-tier venue
Constant-Time Callees with Variable-Time Callers
Cesar Pereida García, Billy Bob Brumley
Abstract
Side-channel attacks are a serious threat to security-critical software. To mitigate remote timing and cache-timing attacks, many ubiquitous cryptography software libraries feature constant-time implementations of cryptographic primitives. In this work, we disclose a vulnerability in OpenSSL 1.0.1u that recovers ECDSA private keys for the standardized elliptic curve P-256 despite the library featuring both constant-time curve operations and modular inversion with microarchitecture attack mitigations. Exploiting this defect, we target the errant modular inversion code path with a cache-timing and improved performance degradation attack, recovering the inversion state sequence. We propose a new approach of extracting a variable number of nonce bits from these sequences, and improve upon the best theoretical result to recover private keys in a lattice attack with as few as 50 signatures and corresponding traces. As far as we are aware, this is the first timing attack against OpenSSL ECDSA that does not target scalar multiplication, the first side-channel attack on cryptosystems leveraging P-256 constant-time scalar multiplication and furthermore, we extend our attack to TLS and SSH protocols, both linked to OpenSSL for P-256 ECDSA signing.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6391e500-3275-49e2-97ca-40bbe879b5d8Cited by top-tier papers28
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García et al.S&P 2019 · 240 citations
- To BLISS-B or not to be: Attacking strongSwan's Implementation of Post-Quantum SignaturesPeter Pessl, Leon Groot Bruinderink, Yuval YaromCCS 2017 · 88 citations
- DATA - Differential Address Trace Analysis: Finding Address-based Side-Channels in BinariesSamuel Weiser, Andreas Zankl, Raphael Spreitzer, Katja Miller et al.USENIX Security 2018 · 77 citations
- May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519Daniel Genkin, Luke Valenta, Yuval YaromCCS 2017 · 75 citations
Related papers
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 93 citations
- Big Numbers - Big Troubles: Systematically Analyzing Nonce Leakage in (EC)DSA ImplementationsSamuel Weiser, David Schrammel, Lukas Bodner, Raphael SpreitzerUSENIX Security 2020
- Attacking OpenSSL Implementation of ECDSA with a Few SignaturesShuqin Fan, Wenbo Wang, Qingfeng ChengCCS 2016 · 44 citations
- Déjà Vu: Side-Channel Analysis of Mozilla's NSSSohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García et al.CCS 2020 · 4 citations
- Jolt: Recovering TLS Signing Keys via Rowhammer FaultsKoksal Mus, Yarkin Doröz, M. Caner Tol, Kristi Rahman et al.S&P 2023
