Title: LadderLeak: Breaking ECDSA With Less Than One Bit Of Nonce Leakage
Nonce\n Leakage\n When: Friday\, Aug 7\, 11:00 - 11:59 PDT\n Where:
Crypto & Privacy Vlg\n Speakers:Akira Takahashi\,F.Â Novaes\,M.Â Tibouc
SpeakerBio:Akira Takahashi
Akira Takahashi is currently a PhD student at Cryptography and Security
ira Takahashi is currently a PhD student at Cryptography and\n Security
also worked as a software developer at Richie Oy, Finland. His
research interests cover implementation attack on public key
cryptographic algorithms and construction of efficient secure
two-/multi-party computation protocols. He has given talks about his
research projects in different top-tier conferences, including
Eurocrypt [3], Euro S&P, and CHES [4].
tier conferences\, including\n Eurocrypt [3]\, Euro S&P\, and CHES [4].\
n\n SpeakerBio:F.Â Novaes\n No BIO available\n\n SpeakerBio:M.Â Tibo
uchi\n No BIO available\n\n SpeakerBio:Y.Â Yarom\n No BIO available\
SpeakerBio:Diego F. Aranha
Diego F. Aranha is an Associate Professor of Computer Science at
Aarhus University, Denmark. His professional experience is in
Cryptography and Computer Security, with a special interest in the
efficient implementation of cryptographic algorithms and security
analysis of real-world systems. He received the Google Latin America
Research Award for research on privacy twice, and the MIT TechReview's
Innovators Under 35 Brazil Award for his work in electronic voting. He
has given talks about his research in more than 100 occasions in 10
different countries, including BlackHat Asia [1] and DEF CON Voting Village [2].
Description:
Although it is one of the most popular signature schemes today, ECDSA
presents a number of implementation pitfalls, in particular due to the
very sensitive nature of the random value (known as the nonce)
generated as part of the signing algorithm. It is known that any small
amount of nonce exposure or nonce bias can in principle lead to a full
key recovery: the key recovery is then a particular instance of Boneh
and Venkatesan's hidden number problem (HNP). That observation has
been practically exploited in many attacks in the literature, taking
advantage of implementation defects or side-channel vulnerabilities in
various concrete ECDSA implementations. However, most of the attacks
so far have relied on at least 2 bits of nonce bias (except for the
special case of curves at the 80-bit security level, for which attacks
against 1-bit biases are known, albeit with a very high number of required signatures).
known\, albeit with a very high number of\n required signatures).\n\n
In this paper, we uncover LadderLeak, a novel class of side-channel
vulnerabilities in implementations of the Montgomery ladder used in\n E
present in several recent versions of OpenSSL. However, it leaks less
than 1 bit of information about the nonce, in the sense that it
reveals the most significant bit of the nonce, but with probability
<1. Exploiting such a mild leakage would be intractable using
techniques present in the literature so far. However, we present a
number of theoretical improvements of the Fourier analysis approach to
solving the HNP (an approach originally due to Bleichenbacher), and
this lets us practically break LadderLeak-vulnerable ECDSA
implementations instantiated over the sect163r1 and NIST P-192
elliptic curves. In so doing, we achieve several significant
computational records in practical attacks against the HNP.
st the HNP.\n\n\n Crypto & Privacy Village activities will be streamed t
o YouTube and\n Twitch.\n\n ------------------------------------------
---------------------------\n\n Twitch: [1]https://twitch.tv/cryptovilla
ge\n\n YouTube: [2]https://www.youtube.com/channel/UCGWMS6k9rg9uOf3FmYdj
wwQ\n\n '\n\n 1. https://twitch.tv/cryptovillage\n 2. https://www.yo
utube.com/channel/UCGWMS6k9rg9uOf3FmYdjwwQ\n\n\n
SUMMARY:LadderLeak: Breaking ECDSA With Less Than One Bit Of Nonce Leakage
