Big Numbers - Big Troubles: Systematically Analyzing Nonce Leakage in (EC)DSA Implementations
Samuel Weiser, David Schrammel, Lukas Bodner, Raphael Spreitzer
摘要
Side-channel attacks exploiting (EC)DSA nonce leakage easily lead to full key recovery. Although (EC)DSA implementations have already been hardened against side-channel leakage using the constant-time paradigm, the long-standing cat-andmouse-game of attacks and patches continues. In particular, current code review is prone to miss less obvious side channels hidden deeply in the call stack. To solve this problem, a systematic study of nonce leakage is necessary. We present a systematic analysis of nonce leakage in cryptographic implementations. In particular, we expand DATA, an open-source side-channel analysis framework, to detect nonce leakage. Our analysis identified multiple unknown nonce leakage vulnerabilities across all essential computation steps involving nonces. Among others, we uncover inherent problems in Bignumber implementations that break claimed constant-time guarantees of (EC)DSA implementations if secrets are close to a word boundary. We found that lazy resizing of Bignumbers in OpenSSL and LibreSSL yields a highly accurate and easily exploitable side channel, which has been acknowledged with two CVEs. Surprisingly, we also found a tiny but expressive leakage in the constant-time scalar multiplication of OpenSSL and BoringSSL. Moreover, in the process of reporting and patching, we identified newly introduced leakage with the support of our tool, thus preventing another attack-patch cycle. We open-source our tool, together with an intuitive graphical user interface we developed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos 等S&P 2021 · 被引用 162 次
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt 等S&P 2022 · 被引用 61 次
- LadderLeak: Breaking ECDSA with Less than One Bit of Nonce LeakageDiego F. Aranha, Felipe Rodrigues Novaes, Akira Takahashi, Mehdi Tibouchi 等CCS 2020 · 被引用 58 次
- A Side Journey To TitanThomas Roche, Victor Lomné, Camille Mutschler, Laurent ImbertUSENIX Security 2021 · 被引用 49 次
- On Bounded Distance Decoding with Predicate: Breaking the "Lattice Barrier" for the Hidden Number ProblemMartin R. Albrecht, Nadia HeningerEUROCRYPT 2021 · 被引用 31 次
它引用的顶会 Paper6
- CacheD: Identifying Cache-Based Timing Channels in Production SoftwareShuai Wang, Pei Wang, Xiao Liu, Danfeng Zhang 等USENIX Security 2017 · 被引用 130 次
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 被引用 93 次
- DATA - Differential Address Trace Analysis: Finding Address-based Side-Channels in BinariesSamuel Weiser, Andreas Zankl, Raphael Spreitzer, Katja Miller 等USENIX Security 2018 · 被引用 77 次
- Constant-Time Callees with Variable-Time CallersCesar Pereida García, Billy Bob BrumleyUSENIX Security 2017 · 被引用 63 次
- Identifying Cache-Based Side Channels through Secret-Augmented Abstract InterpretationShuai Wang, Yuyan Bao, Xiao Liu, Pei Wang 等USENIX Security 2019 · 被引用 57 次
相关 Paper
- Déjà Vu: Side-Channel Analysis of Mozilla's NSSSohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García 等CCS 2020 · 被引用 4 次
- With Great Power Come Great Side Channels: Statistical Timing Side-Channel Analyses with Bounded Type-1 ErrorsMartin Dunsche, Marcel Maehren, Nurullah Erinola, Robert Merget 等USENIX Security 2024 · 被引用 5 次
- Cache Refinement Type for Side-Channel Detection of Cryptographic SoftwareKe Jiang, Yuyan Bao, Shuai Wang, Zhibo Liu 等CCS 2022 · 被引用 7 次
- A Systematic Evaluation of Automated Tools for Side-Channel Vulnerabilities Detection in Cryptographic LibrariesAntoine Geimer, Mathéo Vergnolle, Frédéric Recoules, Lesly-Ann Daniel 等CCS 2023 · 被引用 12 次
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt 等USENIX Security 2024 · 被引用 15 次
