LadderLeak: Breaking ECDSA with Less than One Bit of Nonce Leakage
Diego F. Aranha, Felipe Rodrigues Novaes, Akira Takahashi, Mehdi Tibouchi, Yuval Yarom
摘要
Although it is one of the most popular signature schemes today, ECDSA presents a number of implementation pitfalls, in particular due to the very sensitive nature of the random value (known as the nonce) generated as part of the signing algorithm. It is known that any small amount of nonce exposure or nonce bias can in principle lead to a full key recovery: the key recovery is then a particular instance of Boneh and Venkatesan's hidden number problem (HNP). That observation has been practically exploited in many attacks in the literature, taking advantage of implementation defects or side-channel vulnerabilities in various concrete ECDSA implementations. However, most of the attacks so far have relied on at least 2 bits of nonce bias (except for the special case of curves at the 80-bit security level, for which attacks against 1-bit biases are known, albeit with a very high number of required signatures). In this paper, we uncover LadderLeak, a novel class of side-channel vulnerabilities in implementations of the Montgomery ladder used in ECDSA scalar multiplication. The vulnerability is in particular present in several recent versions of OpenSSL. However, it leaks less than 1 bit of information about the nonce, in the sense that it reveals the most significant bit of the nonce, but with probability <1. Exploiting such a mild leakage would be intractable using techniques present in the literature so far. However, we present a number of theoretical improvements of the Fourier analysis approach to solving the HNP (an approach originally due to Bleichenbacher), and this lets us practically break LadderLeak-vulnerable ECDSA implementations instantiated over the sect163r1 and NIST P-192 elliptic curves. In so doing, we achieve several significant computational records in practical attacks against the HNP.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper22
- The Provable Security of Ed25519: Theory and PracticeJacqueline Brendel, Cas Cremers, Dennis Jackson, Mang ZhaoS&P 2021 · 被引用 78 次
- Prime+Scope: Overcoming the Observer Effect for High-Precision Cache Contention AttacksAntoon Purnal, Furkan Turan, Ingrid VerbauwhedeCCS 2021 · 被引用 55 次
- Constantine: Automatic Side-Channel Resistance Using Efficient Control and Data Flow LinearizationPietro Borrello, Daniele Cono D'Elia, Leonardo Querzoni, Cristiano GiuffridaCCS 2021 · 被引用 43 次
- Threshold Schnorr with Stateless Deterministic Signing from Standard AssumptionsFrançois Garillot, Yashvanth Kondi, Payman Mohassel, Valeria NikolaenkoCRYPTO 2021 · 被引用 39 次
- Last-Level Cache Side-Channel Attacks Are Feasible in the Modern Public CloudZirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep TorrellasASPLOS 2024 · 被引用 20 次
它引用的顶会 Paper10
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García 等S&P 2019 · 被引用 240 次
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer 等CCS 2016 · 被引用 196 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
相关 Paper
- A Little LESS Secure - Side-Channel Attacks Exploiting Randomness LeakageDina Hesse, Elisabeth Krahmer, Yi-Fu Lai, Jonas MeersCRYPTO 2026
- Attacking OpenSSL Implementation of ECDSA with a Few SignaturesShuqin Fan, Wenbo Wang, Qingfeng ChengCCS 2016 · 被引用 44 次
- Big Numbers - Big Troubles: Systematically Analyzing Nonce Leakage in (EC)DSA ImplementationsSamuel Weiser, David Schrammel, Lukas Bodner, Raphael SpreitzerUSENIX Security 2020
- May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519Daniel Genkin, Luke Valenta, Yuval YaromCCS 2017 · 被引用 75 次
- Constant-Time Callees with Variable-Time CallersCesar Pereida García, Billy Bob BrumleyUSENIX Security 2017 · 被引用 63 次
