{"id":38635,"date":"2019-10-31T22:24:58","date_gmt":"2019-10-31T19:24:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa\/"},"modified":"2019-10-31T22:24:58","modified_gmt":"2019-10-31T19:24:58","slug":"novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","title":{"rendered":"Une nouvelle technique d'attaque par des canaux auxiliaires, permettant de r\u00e9cup\u00e9rer les cl\u00e9s ECDSA","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Des chercheurs de l'Universit\u00e9 Masaryk <noindex><a rel=\"nofollow\" href=\"https:\/\/seclists.org\/oss-sec\/2019\/q4\/3\">ont r\u00e9v\u00e9l\u00e9<\/a><\/noindex> informations sur <noindex><a rel=\"nofollow\" href=\"https:\/\/minerva.crocs.fi.muni.cz\/\">les vuln\u00e9rabilit\u00e9s<\/a><\/noindex> dans diverses r\u00e9alisations de l'algorithme de cr\u00e9ation de signature num\u00e9rique ECDSA\/EdDSA, permettant de r\u00e9cup\u00e9rer la valeur de la cl\u00e9 priv\u00e9e en analysant les fuites d'informations sur des bits individuels, apparaissant lors de l'application de m\u00e9thodes d'analyse par canaux lat\u00e9raux. Les vuln\u00e9rabilit\u00e9s ont re\u00e7u le nom de code Minerva. <\/p>\n<p>Les projets les plus connus concern\u00e9s par la m\u00e9thode d'attaque propos\u00e9e sont OpenJDK\/OracleJDK (CVE-2019-2894) et la biblioth\u00e8que <noindex><a rel=\"nofollow\" href=\"https:\/\/git.gnupg.org\/cgi-bin\/gitweb.cgi?p=libgcrypt.git\">Libgcrypt<\/a><\/noindex> (CVE-2019-13627), utilis\u00e9e dans GnuPG. Le probl\u00e8me touche \u00e9galement <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/matrixssl\/matrixssl\/\">MatrixSSL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/weidai11\/cryptopp\/\">Crypto++<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/wolfSSL\/wolfssl\/\">wolfCrypt<\/a><\/noindex>,   <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/indutny\/elliptic\/\">elliptic<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kjur\/jsrsasign\">jsrsasign<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/warner\/python-ecdsa\">python-ecdsa<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/DavidEGrayson\/ruby_ecdsa\">ruby_ecdsa<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/AntonKueltz\/fastecdsa\">fastecdsa<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/esxgx\/easy-ecc\/\">easy-ecc<\/a><\/noindex> et les cartes intelligentes Athena IDProtect. Non test\u00e9es, mais d\u00e9clar\u00e9es \u00e9galement comme potentiellement vuln\u00e9rables sont les cartes Valid S\/A IDflex V, SafeNet eToken 4300 et TecSec Armored Card, qui utilisent un module standard ECDSA. <\/p>\n<p>Le probl\u00e8me a d\u00e9j\u00e0 \u00e9t\u00e9 r\u00e9solu dans les versions libgcrypt 1.8.5 et wolfCrypt 4.1.0, les autres projets n'ayant pas encore publi\u00e9 de mises \u00e0 jour. Vous pouvez suivre la correction de la vuln\u00e9rabilit\u00e9 dans le package libgcrypt dans les distributions sur ces pages : <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-13627\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-13627.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-13627\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-13627\">openSUSE\/SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/\">FreeBSD<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/CVE-2019-13627\">Arch<\/a><\/noindex>.<\/p>\n<p>Vuln\u00e9rabilit\u00e9s <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/crocs-muni\/ECTester\/blob\/master\/docs\/LIBS.md\">n'est pas soumis<\/a><\/noindex> OpenSSL, Botan, mbedTLS et BoringSSL. Non encore test\u00e9s, Mozilla NSS, LibreSSL, Nettle, BearSSL, cryptlib, OpenSSL en mode FIPS, Microsoft .NET crypto,<br \/>\nlibkcapi du noyau Linux, Sodium et GnuTLS.<\/p>\n<p>Le probl\u00e8me est caus\u00e9 par la possibilit\u00e9 de d\u00e9terminer les valeurs de bits individuels lors de l'ex\u00e9cution d'une multiplication par un scalaire lors d'op\u00e9rations avec des courbes elliptiques. Pour extraire des informations sur les bits, des m\u00e9thodes indirectes sont utilis\u00e9es, telles que l'estimation du d\u00e9lai lors de l'ex\u00e9cution des calculs. Une attaque n\u00e9cessite un acc\u00e8s non privil\u00e9gi\u00e9 \u00e0 l'h\u00f4te sur lequel la g\u00e9n\u00e9ration de signature num\u00e9rique est effectu\u00e9e (une <noindex><a rel=\"nofollow\" href=\"https:\/\/minerva.crocs.fi.muni.cz\/#remote\">attaque distante n'est pas exclue, mais elle est consid\u00e9rablement compliqu\u00e9e et n\u00e9cessite une grande quantit\u00e9 de donn\u00e9es pour analyse, elle peut donc \u00eatre consid\u00e9r\u00e9e comme peu probable). Pour t\u00e9l\u00e9charger<\/a><\/noindex> les outils utilis\u00e9s pour l'attaque. <noindex><a rel=\"nofollow\" href=\"https:\/\/minerva.crocs.fi.muni.cz\/#poc\">disponible<\/a><\/noindex> outil utilis\u00e9 pour l'attaque.<\/p>\n<p>Bien que la fuite soit insignifiante, pour d\u00e9finir ECDSA, quelques bits d'information sur le vecteur d'initialisation (nonce) suffisent pour mener une attaque de r\u00e9cup\u00e9ration s\u00e9quentielle de toute la cl\u00e9 priv\u00e9e. Selon les auteurs de la m\u00e9thode, une analyse de quelques centaines \u00e0 quelques milliers de signatures num\u00e9riques, g\u00e9n\u00e9r\u00e9es pour des messages connus de l'attaquant, est suffisante pour r\u00e9cup\u00e9rer la cl\u00e9 avec succ\u00e8s. Par exemple, pour d\u00e9terminer la cl\u00e9 priv\u00e9e utilis\u00e9e sur la carte \u00e0 puce Athena IDProtect bas\u00e9e sur la puce Inside Secure AT90SC, en utilisant la courbe elliptique secp256r1, 11 000 signatures num\u00e9riques ont \u00e9t\u00e9 analys\u00e9es. Le temps total de l'attaque \u00e9tait de 30 minutes.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51609\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c. \u041c\u0430\u0441\u0430\u0440\u0438\u043a\u0430 \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0430 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u0438 ECDSA\/EdDSA, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0443\u0442\u0435\u0447\u0435\u043a \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0439 \u043e\u0431 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0431\u0438\u0442\u0430\u0445, \u0432\u0441\u043f\u043b\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u043f\u0440\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u043c\u0435\u0442\u043e\u0434\u043e\u0432 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0438 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Minerva. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\u043c\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438, \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f OpenJDK\/OracleJDK (CVE-2019-2894) \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38635","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043a\u043b\u044e\u0447\u0438 ECDSA | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Nouvelle technique d'attaque par canaux auxiliaires, permettant de r\u00e9cup\u00e9rer des cl\u00e9s ECDSA | ProHoster","description":"Les chercheurs de l'universit\u00e9","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043a\u043b\u044e\u0447\u0438 ECDSA | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:58+00:00","article:modified_time":"2019-10-31T19:24:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38635","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:51:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:06:23","updated":"2026-01-23 22:51:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=38635"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38635\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=38635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=38635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=38635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}