An Attack on TON's ADNL Secure Channel Protocol
Aviv Frenkel, Dmitry Kogan
摘要
We present an attack on the Abstract Datagram Network Layer (ADNL) protocol used in The Open Network (TON), currently the 10th largest blockchain by market capitalization. In its TCP variant, ADNL secures communication between clients and specialized nodes called liteservers, which provide access to blockchain data. We identify two crypto-graphic design flaws in this protocol: a handshake that permits session-key replay and a non-standard integrity mechanism whose security critically depends on message confidentiality. We transform these vulnerabilities into an efficient plaintext-recovery attack by exploiting two ADNL communication patterns, allowing message reordering across replayed sessions. We then develop a plaintext model for this scenario and construct an efficient algorithm that recovers the keystream using a fraction of known plaintexts and a handful of replays. We implement our attack and show that an attacker intercepting the communication between a TON liteserver and a widely deployed ADNL client can recover the keystream used to encrypt server responses by performing eight connection replays to the server. This allows the decryption of sensitive data, such as account balances and user activity patterns. Additionally, the attacker can modify server responses to manipulate blockchain information displayed to the client, including account balances and asset prices.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper1
相关 Paper
- Enhancing the Open Network: Definition and Automated Detection of Smart Contract DefectsHao Song, Teng Li, Jiachi Chen, Ting Chen 等ICSE 2025 · 被引用 5 次
- Four Attacks and a Proof for TelegramMartin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors StepanovsS&P 2022 · 被引用 40 次
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 被引用 93 次
- Eclipse Attacks on Monero's Peer-to-Peer NetworkRuisheng Shi, Zhiyuan Peng, Lina Lan, Yulian Ge 等NDSS 2025
- Removing Secrets from Android's TLSJaeho Lee, Dan S. WallachNDSS 2018 · 被引用 10 次
