Victory by KO: Attacking OpenPGP Using Key Overwriting
Lara Bruseghini, Daniel Huigens, Kenneth G. Paterson
摘要
We present a set of attacks on the OpenPGP specification and implementations of it which result in full recovery of users' private keys. The attacks exploit the lack of cryptographic binding between the different fields inside an encrypted private key packet, which include the key algorithm identifier, the cleartext public parameters, and the encrypted private parameters. This allows an attacker who can overwrite certain fields in OpenPGP key packets to perform cross-algorithm attacks, causing a user's software to, for example, misinterpret an ECC private key as being a DSA key. It also allows an attacker to replace the legitimate public parameters with adversarially chosen ones, e.g. allowing them to select the DSA group. We refer to this class of attacks as Key Overwriting (KO) attacks. We provide a detailed analysis of the vulnerability of different OpenPGP libraries to KO attacks, showing in particular that in some cases additional key validation steps performed by libraries that should prevent the attacks in fact allow variant attacks. We also assess the applicability of KO attacks in the context of specific OpenPGP-based applications that reflect different threat models. Finally, we explain how KO attacks can be completely prevented (and the need for key validation obsoleted) at the OpenPGP specification level by expanding the existing proposal of using AEAD schemes for key packet protection to have all the security-relevant public fields included as Associated Data. Version (4) Creation Date Key Algorithm (ECDSA) Curve identifier 𝑂 Public point 𝑄 Public fields (fingerprinted)
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Caveat Implementor! Key Recovery Attacks on MEGAMartin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. PatersonEUROCRYPT 2023 · 被引用 8 次
- End-to-End Encrypted Cloud Storage in the Wild: A Broken EcosystemJonas Hofmann, Kien Tuong TruongCCS 2024 · 被引用 5 次
- MFKDF: Multiple Factors Knocked Down FlatMatteo Scarlata, Matilda Backendal, Miro HallerUSENIX Security 2024 · 被引用 3 次
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
它引用的顶会 Paper4
- Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration ChannelsDamian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising 等USENIX Security 2018 · 被引用 64 次
- Prime and Prejudice: Primality Testing Under Adversarial ConditionsMartin R. Albrecht, Jake Massimo, Kenneth G. Paterson, Juraj SomorovskyCCS 2018 · 被引用 21 次
- On the (In)Security of ElGamal in OpenPGPLuca De Feo, Bertram Poettering, Alessandro SorniottiCCS 2021 · 被引用 7 次
- A Performant, Misuse-Resistant API for Primality TestingJake Massimo, Kenneth G. PatersonCCS 2020
相关 Paper
- Measuring small subgroup attacks against Diffie-HellmanLuke Valenta, David Adrian, Antonio Sanso, Shaanan Cohney 等NDSS 2017 · 被引用 34 次
- May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519Daniel Genkin, Luke Valenta, Yuval YaromCCS 2017 · 被引用 75 次
- Mitigation of Attacks on Email End-to-End EncryptionJörg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Müller 等CCS 2020 · 被引用 10 次
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 被引用 57 次
- "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in EmailsJens Müller, Marcus Brinkmann, Damian Poddebniak, Hanno Böck 等USENIX Security 2019 · 被引用 34 次
