Severe vulnerability found in RSA encryption

Αναδημοσιεύσεις άρθρων και συζητήσεις με θέμα την τεχνολογία.
Post Reply
User avatar
enum21
Venus Former Team Member
Posts: 5436
Joined: Mon Feb 16, 2009 9:06 pm
Academic status: Alumnus/a
Gender:
Location: Underworld

Severe vulnerability found in RSA encryption

Post by enum21 » Sun Mar 07, 2010 1:16 pm

The most widely used software encryption technique has a major weakness, University of Michigan computer scientists have discovered.

RSA authentication is used pretty much everywhere, from home laptops and smartphones to banks and retail systems.

But the scientists found they could foil the security system by varying the voltage supply to the holder of the SSL private key - the consumer's device in the case of copy protection and the retailer or bank in the case of internet communication.

It's unlikely that a hacker could use this approach on a large institution, the researchers say. The findings are more likely to worry media companies and mobile device manufacturers - and their customers.

"The RSA algorithm gives security under the assumption that as long as the private key is private, you can't break in unless you guess it. We've shown that that's not true," said Valeria Bertacco, an associate professor in the Department of Electrical Engineering and Computer Science.

By tweaking the voltage with a home-made device, the U-M researchers were able to extract the private key in about 100 hours.

Varying the electric current essentially stresses out the computer and causes it to make small mistakes in its communications with other clients. These faults reveal small pieces of the private key. Once the researchers caused enough faults, they were able to reconstruct the key offline.

No tamper evidence is left.

But the researchers say they've identified a solution - a common cryptographic technique called 'salting' that randomly changes the order of the digits every time the key is requested.

"We've demonstrated that a fault-based attack on the RSA algorithm is possible," said Professor Todd Austin said. "Hopefully, this will cause manufacturers to make a few small changes to their implementation of the algorithm. RSA is a good algorithm and I think, ultimately, it will survive this type of attack."
Πηγή

:shock: μέσα σε 100 ώρες..
Μα πως γίνεται να μην αφήνει ίχνη? :smt017

Και η λύση "salting" τι ακριβώς κάνει ώστε να θεωρείται ο αλγόριθμος σωστός :?:
redlabel
Wow! Terabyte level
Wow! Terabyte level
Posts: 2057
Joined: Tue Jun 27, 2006 12:32 pm
Academic status: Professor
Gender:

Re: Severe vulnerability found in RSA encryption

Post by redlabel » Sun Mar 07, 2010 9:10 pm

Ουσιαστικά, εντελώς ανούσιο εύρημα. Το προβάλλουν πιο πολύ για τη διαφήμισή τους, παρά για τη σημασία του.

Δ. Γκρ.
Post Reply

Return to “Τεχνολογικά Νέα”