Reconstruction of RSA keys through analysis of SSH connections to faulty servers

A group of researchers from the University of California, San Diego, has demonstrated the feasibility of reconstructing SSH server private host RSA keys using passive analysis of SSH traffic. The attack can be carried out on servers that, due to circumstances or actions by the attacker, experience failures during the digital signature computation when establishing an SSH connection. Failures can be either software-related (incorrect execution of mathematical operations, memory corruption) or hardware-related (errors with NVRAM and DRAM or failures during power interruptions).

One method of inducing failures could be RowHammer class attacks, which among other things allow for the distortion of the content of specific memory bits through intense cyclic reading of data from neighboring memory cells, either remotely or while processing JavaScript code in a browser. Another way to trigger failures could involve exploiting vulnerabilities that lead to buffer overflows and corruption of data with keys in memory.

The published study indicates that when using RSA-based digital signatures in SSH, attacks to reconstruct RSA private keys can apply to the digital signature parameters using the Lattice method (Fault Attack), particularly during software or hardware failures in the signature computation process. The essence of the method is that by comparing correct and faulty RSA digital signatures, it is possible to determine the greatest common divisor to derive one of the prime numbers used to form the key.

RSA encryption is based on the operation of exponentiation modulo a large number. The public key contains the modulus and exponent. The modulus is formed based on two random prime numbers, which are known only to the owner of the private key. The attack can be applied to RSA implementations that use the Chinese Remainder Theorem and deterministic padding schemes, such as PKCS#1 v1.5.

To carry out an attack, it is sufficient to passively monitor legitimate connections to the SSH server until a faulty digital signature is discovered in the traffic, which can be used as a source of information to reconstruct the private RSA key. After reconstructing the host's RSA key, the attacker can during a MITM attack stealthily redirect requests to a substitute host impersonating the compromised SSH server and organize the interception of the transmitted data. server of data.

As a result of studying a collection of intercepted network data, including approximately 5.2 billion records related to the use of the SSH protocol, researchers identified about 3.2 billion open host keys and digital signatures used during the SSH session negotiation. Of these, 1.2 billion (39.1%) were generated using the RSA algorithm. In 593,671 cases (0.048%), the RSA signature was corrupted and did not pass verification. For 4,962 faulty signatures, the Lattice factorization method was successfully applied to determine the private key from the known public key, ultimately allowing the reconstruction of 189 unique RSA key pairs (in many cases, the same keys and faulty devices were used to generate different corrupted signatures). It took around 26 hours of CPU time to reconstruct the keys.

Reconstruction of RSA keys through analysis of SSH connections to faulty servers

The issue only affects specific implementations of the SSH protocol primarily used in embedded devices. Examples of devices with problematic SSH implementations include products from Zyxel, Cisco, Mocana, and Hillstone Networks. OpenSSH is not vulnerable to the issue as it uses the OpenSSL (or LibreSSL) library for key generation, which has included defenses against fault analysis attacks since 2001. Moreover, in OpenSSH, the ssh-rsa digital signature scheme (based on sha1) has been deprecated since 2020 and disabled in version 8.8 (support for rsa-sha2-256 and rsa-sha2-512 schemes remains). The attack may potentially be applicable to the IPsec protocol as well, but the researchers did not have sufficient experimental data to confirm such an attack in practice.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster