Indiscreet Logs: Diffie-Hellman Backdoors in TLS
Kristen Dorey, Nicholas Chang-Fong, Aleksander Essex
摘要
Software implementations of discrete logarithm based cryptosystems over finite fields typically make the assumption that any domain parameters they encounter define cyclic groups for which the discrete logarithm problem is assumed to be hard. In this paper we explore this trust assumption and examine situations where it may not be justified. In particular we focus on groups for which the order is unknown and not easily determined, and explore the scenario in which the modulus is trapdoored to make computing discrete logarithms efficient for an entity with knowledge of the trapdoor, while simultaneously leaving its very existence as matter of speculation to everyone else. We conducted an investigation of discrete logarithm domain parameters in use across the Internet and discovered a multitude of instances of groups of unknown order in use in TLS and STARTTLS spanning numerous countries, organizations, and implementations. Although our disclosures resulted in a number of organizations taking down their suspicious parameters, none were able or willing to rule out the possibility that their parameters were trapdoors, and obtaining conclusive evidence in each case could be as hard as factoring an RSA modulus, highlighting a key feature of this attack method-deniability. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)Robert Merget, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky 等USENIX Security 2021 · 被引用 36 次
- Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web EcosystemStefano Calzavara, Riccardo Focardi, Matús Nemec, Alvise Rabitti 等S&P 2019 · 被引用 24 次
- Passive SSH Key Compromise via LatticesKeegan Ryan, Kaiwen He, George Arnold Sullivan, Nadia HeningerCCS 2023 · 被引用 8 次
- We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session TicketsSven Hebrok, Simon Nachtigall, Marcel Maehren, Nurullah Erinola 等USENIX Security 2023
- Exploring the Unknown DTLS Universe: Analysis of the DTLS Server Ecosystem on the InternetNurullah Erinola, Marcel Maehren, Robert Merget, Juraj Somorovsky 等USENIX Security 2023
它引用的顶会 Paper2
相关 Paper
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 被引用 128 次
- Prime and Prejudice: Primality Testing Under Adversarial ConditionsMartin R. Albrecht, Jake Massimo, Kenneth G. Paterson, Juraj SomorovskyCCS 2018 · 被引用 21 次
- The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSECElias Heftrig, Haya Schulmann, Niklas Vogel, Michael WaidnerCCS 2024 · 被引用 4 次
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 被引用 93 次
- Return Of Bleichenbacher's Oracle Threat (ROBOT)Hanno Böck, Juraj Somorovsky, Craig YoungUSENIX Security 2018 · 被引用 69 次
