Prime and Prejudice: Primality Testing Under Adversarial Conditions
Martin R. Albrecht, Jake Massimo, Kenneth G. Paterson, Juraj Somorovsky
摘要
This work provides a systematic analysis of primality testing under adversarial conditions, where the numbers being tested for primality are not generated randomly, but instead provided by a possibly malicious party. Such a situation can arise in secure messaging protocols where a server supplies Diffie-Hellman parameters to the peers, or in a secure communications protocol like TLS where a developer can insert such a number to be able to later passively spy on client-server data. We study a broad range of cryptographic libraries and assess their performance in this adversarial setting. As examples of our findings, we are able to construct 2048-bit composites that are declared prime with probability 1/16 by OpenSSL's primality testing in its default configuration; the advertised performance is 2 -80 . We can also construct 1024-bit composites that always pass the primality testing routine in GNU GMP when configured with the recommended minimum number of rounds. And, for a number of libraries (Cryptlib, LibTomCrypt, JavaScript Big Number, WolfSSL), we can construct composites that always pass the supplied primality tests. We explore the implications of these security failures in applications, focusing on the construction of malicious Diffie-Hellman parameters. We show that, unless careful primality testing is performed, an adversary can supply parameters (p, q, д) which on the surface look secure, but where the discrete logarithm problem in the subgroup of order q generated by д is easy. We close by making recommendations for users and developers. In particular, we promote the Baillie-PSW primality test which is both efficient and conjectured to be robust even in the adversarial setting for numbers up to a few thousand bits.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Victory by KO: Attacking OpenPGP Using Key OverwritingLara Bruseghini, Daniel Huigens, Kenneth G. PatersonCCS 2022 · 被引用 6 次
- A Performant, Misuse-Resistant API for Primality TestingJake Massimo, Kenneth G. PatersonCCS 2020
它引用的顶会 Paper3
- The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA ModuliMatús Nemec, Marek Sýs, Petr Svenda, Dusan Klinec 等CCS 2017 · 被引用 147 次
- A Systematic Analysis of the Juniper Dual EC IncidentStephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried 等CCS 2016 · 被引用 91 次
- Measuring small subgroup attacks against Diffie-HellmanLuke Valenta, David Adrian, Antonio Sanso, Shaanan Cohney 等NDSS 2017 · 被引用 34 次
相关 Paper
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
- On the Unnecessary Complexity of Names in X.509 and Their Impact on ImplementationsYuteng Sun, Joyanta Debnath, Wenzheng Hong, Omar Chowdhury 等FSE 2025
- HACL*: A Verified Modern Cryptographic LibraryJean Karim Zinzindohoué, Karthikeyan Bhargavan, Jonathan Protzenko, Benjamin BeurdoucheCCS 2017 · 被引用 258 次
- May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519Daniel Genkin, Luke Valenta, Yuval YaromCCS 2017 · 被引用 75 次
- Return Of Bleichenbacher's Oracle Threat (ROBOT)Hanno Böck, Juraj Somorovsky, Craig YoungUSENIX Security 2018 · 被引用 69 次
