

Six Cryptographers Whose Work on Dual EC DRBG Were Deemed Without Merit by RSA C...
source link: http://jeffreycarr.blogspot.com/2014/02/six-cryptographers-whose-work-on-dual.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Six Cryptographers Whose Work on Dual EC DRBG Were Deemed Without Merit by RSA Chief Art Coviello
Three things about Art Coviello's keynote speech today jumped out at me:"When, last September, it became possible that concerns raised in 2007 might have merit as part of a strategy of exploitation, NIST as the relevant standards body issued new guidance to stop the use of this algorithm. We immediately acted upon that guidance, notified our customers, and took steps to remove the algorithm from use." - Art Coviello RSAC 2014 Keynote speech
- He attempted to paint NSA as the sole bad guy in the Dual EC DRBG debacle.
- He carefully avoided any mention of why RSA trusted the NSA in 2004 when the agency wasn't trusted by RSA even five years earlier.
- He believed that the published warnings of six independent and respected cryptographers in 2006 and 2007 had no merit.
Comments on Dual-EC-DRBG/NIST SP 800-90, Draft December 2005 by Kristian Gjøsteen* (March 16, 2006)
Abstract: "We analyse the Dual-EC deterministic pseudo-random bit generator (DRBG) proposed in draft of NIST SP 800-90 published December 2005. The generator consists of two parts, one that generates a sequence of points and one that extracts a bit string from the point sequence. We show that the first part is essentially cryptographically sound, while the second is not."
*Associate professor at The Norwegian University of Science and Technology, Department of Mathematical Sciences.
Cryptanalysis of the Dual Elliptic Curve Pseudorandom Generator
Berry Schoenmakers and Andrey Sidorenko
Dept. of Mathematics and Computer Science, TU Eindhoven,
P.O. Box 513, 5600 MB Eindhoven, The Netherlands.
[email protected], [email protected]
29 May 2006
"The Dual Elliptic Curve Pseudorandom Generator (DEC PRG) is proposed by Barker and Kelsey [2].
It is claimed (see Section 10.3.1 of [2]) that the pseudorandom generator is secure unless the adversary can solve the elliptic curve discrete logarithm problem (ECDLP) for the corresponding elliptic curve.
The claim is supported only by an informal discussion. No security reduction is given, that is, it is not shown that an adversary that breaks the pseudorandom generator implies a solver for the ECDLP.
Our experimental results and also empirical argument show that the DEC PRG is insecure. The attack does not imply solving the ECDLP for the corresponding elliptic curve. The attack is very efficient. It can be run on an ordinary PC. Actually, the generator is insecure because pseudorandom bits are extracted from points of the elliptic curve improperly."
On the Possibility of a Back Door in the NIST SP800-90 Dual Ec Prng by Dan Shumow and Niels Ferguson (Microsoft)
Bruce Schneier "Did NSA Put a Secret Backdoor in New Encryption Standard?" Wired, November 15, 2007.
Art Coviello failed to explain why the work of any of the above researchers didn't merit an investigation into the algorithm which the NSA wanted him to adopt two years earlier. I hope that RSA customers pay attention to Art Coviello's clumsy attempt to whitewash RSA's responsibility in this matter and find other, more trustworthy vendors to take their business to.
Recommend
-
42
Code of Merit The project creators, lead developers, core team, constitute the managing members of the project and have final say in every decision of the project, technical or otherwise, includi...
-
75
A meritocratic approach to project management and discussions.
-
10
In cryptography, the dining cryptographers problem studies how to perform a secure multi-party computation of the boolean-OR function.Davi...
-
6
Google Workers Publicly Launch UnionOn Monday, Google employees and contractors in the United States announced the creation of a labor union with the Communication Workers of America. J...
-
6
TechSuspicious package deemed safe at Google campus in Mountain ViewPublished Fri, Jan 15 20211:24 PM ESTUpdated Fri, Jan 15 20213:13 PM EST
-
15
Local One-star ratings on Google are deemed not defamatory and why that’s a problem It's crucial to have a s...
-
3
Florida condo building deemed unsafe, evacuation orderedBy REBECCA SANTANAtoday
-
10
Merit Circle宣布完成1亿美元公募融资 • 19 小时前 碳链价值APP讯,官方消息,Merit Circle宣布在公平启动拍卖平台Copper通过Balancer Labs Liqu...
-
8
Offbeat Bloke breaking his back on 'commute' from bed to desk deemed a workplace accidentThank...
-
5
cryptographyCryptographers Achieve Perfect Secrecy With Imperfect DevicesFor the first time, experiments demonstrate the possibility of sharing...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK