Re: a question RE: PKCS1 known cyphertext attack

New Message Reply About this list Date view Thread view Subject view Author view

bram (bram@gawth.com)
Tue, 30 Jun 1998 15:34:58 -0700 (PDT)


On Tue, 30 Jun 1998, Joshua Hill wrote:

> How is this adaptive attack performed. (what relationship gives a
> good chance of the new r_i also being a "good" guess?)

It unfortunately takes some poking to find the actual technical paper.
It's at:

http://www.rsa.com/rsalabs/pkcs1/bulletin7.html

Information can be inferred by throwing random things at the decrypter and
noting which ones don't spew out error messages. Very clever. Fortunately
it can be stopped just by checking for all possible error conditions
(which should have been done to begin with anyway) and giving the same
error message regardless of what the error is (and taking the same amount
of time for all of them.)

A very clever attack.

-Bram


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:19:16 ADT