A new attack technique via side channels allows for the recovery of ECDSA keys.

Researchers from Masaryk University revealed information about vulnerabilities in various implementations of the ECDSA/EdDSA digital signature algorithm that allow the recovery of the private key based on the analysis of leakage of information about individual bits that emerge during side-channel analysis. The vulnerabilities have been codenamed Minerva.

The most notable projects affected by the proposed attack method include OpenJDK/OracleJDK (CVE-2019-2894) and the library Libgcrypt (CVE-2019-13627), used in GnuPG. The following are also vulnerable MatrixSSL, Crypto++, wolfCrypt, elliptic, jsrsasign, python-ecdsa, ruby_ecdsa, fastecdsa, easy-ecc and smart cards Athena IDProtect. Cards Valid S/A IDflex V, SafeNet eToken 4300, and TecSec Armored Card are also reported as potentially vulnerable, which utilize standard ECDSA modules.

The issue has already been fixed in releases of libgcrypt 1.8.5 and wolfCrypt 4.1.0, while the other projects have yet to issue updates. Follow the vulnerability fix for the libgcrypt package in distributions on the following pages: Debian, Ubuntu, SUSE/openSUSE, Alpine, openSUSE/SUSE, FreeBSD, ALT.

Vulnerabilities as Exim is not included in their standard package repository. OpenSSL, Botan, mbedTLS, and BoringSSL. Mozilla NSS, LibreSSL, Nettle, BearSSL, cryptlib, OpenSSL in FIPS mode, Microsoft .NET crypto,
libkcapi from the Linux kernel, Sodium, and GnuTLS are still untested.

The problem arises from the ability to determine the values of individual bits during scalar multiplication in elliptic curve operations. Indirect methods such as measuring latency during computations are used to extract bit information. The attack requires unprivileged access to the host on which the digital signature generation occurs (remote attacks are not excluded, but they are significantly complicated and require large amounts of data for analysis, thus can be considered unlikely). To download the tools used for the attack. and remote attacks, but they are significantly complicated and require a large volume of data for analysis, making them consider unlikely). For loading is available the toolkit used for the attack.

Despite the minor size of the leak, for ECDSA, even a few bits of information about the initialization vector (nonce) are sufficient for performing a sequential key recovery attack. According to the method's authors, analyzing several hundred to several thousand digital signatures generated for known messages is enough to successfully recover the key. For instance, to determine the private key used in the Athena IDProtect smart card based on the Inside Secure AT90SC chip and utilizing the elliptic curve secp256r1, 11,000 digital signatures were analyzed. The total attack time was 30 minutes.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster