ื˜ื›ื ื™ืงืช ืชืงื™ืคื” ื—ื“ืฉื” ืฉืœ ืขืจื•ืฅ ืฆื“ ืœืฉื—ื–ื•ืจ ืžืคืชื—ื•ืช ECDSA

ื—ื•ืงืจื™ื ืžื”ืื•ื ื™ื‘ืจืกื™ื˜ื”. ืžืกืจื™ืง ื—ึธืฉื‚ื•ึผืฃ ืžื™ื“ืข ืขืœ ืคื’ื™ืขื•ืช ื‘ื™ื™ืฉื•ืžื™ื ืฉื•ื ื™ื ืฉืœ ืืœื’ื•ืจื™ืชื ื™ืฆื™ืจืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ECDSA/EdDSA, ื”ืžืืคืฉืจ ืœืฉื—ื–ืจ ืืช ื”ืขืจืš ืฉืœ ืžืคืชื— ืคืจื˜ื™ ืขืœ ืกืžืš ื ื™ืชื•ื— ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ื‘ื™ื˜ื™ื ื‘ื•ื“ื“ื™ื ืฉืฆืฆื™ื ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ื•ืช ื ื™ืชื•ื— ืฉืœ ืฆื“ ืฉืœื™ืฉื™. ื”ืคื’ื™ืขื•ื™ื•ืช ืงื™ื‘ืœื• ืืช ืฉื ื”ืงื•ื“ Minerva.

ื”ืคืจื•ื™ืงื˜ื™ื ื”ื™ื“ื•ืขื™ื ื‘ื™ื•ืชืจ ืฉืžื•ืฉืคืขื™ื ืžืฉื™ื˜ืช ื”ื”ืชืงืคื” ื”ืžื•ืฆืขืช ื”ื OpenJDK/OracleJDK (CVE-2019-2894) ื•ื”ืกืคืจื™ื™ื” libgcrypt (CVE-2019-13627) ื‘ืฉื™ืžื•ืฉ ื‘-GnuPG. ื’ื ืจื’ื™ืฉ ืœื‘ืขื™ื” MatrixSSL, Crypto ++, wolfCrypt, ืึถืœึดื™ืคึผึฐื˜ึดื™, jsrsasign, python-ecdsa, ruby_ecdsa, fastecdsa, ืงืœ-ecc ื•ื›ืจื˜ื™ืกื™ื ื—ื›ืžื™ื ืฉืœ Athena IDProtect. ืœื ื ื‘ื“ืง, ืื‘ืœ ื›ืจื˜ื™ืกื™ S/A ื—ื•ืงื™ื™ื IDflex V, SafeNet eToken 4300 ื•-TecSec Armored Card, ื”ืžืฉืชืžืฉื™ื ื‘ืžื•ื“ื•ืœ ECDSA ืกื˜ื ื“ืจื˜ื™, ืžื•ื›ืจื–ื™ื ื’ื ื”ื ื›ื‘ืขืœื™ ืคื•ื˜ื ืฆื™ืืœ ืคื’ื™ืข.

ื”ื‘ืขื™ื” ื›ื‘ืจ ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจื•ืช ืฉืœ libgcrypt 1.8.5 ื•-wolfCrypt 4.1.0, ื”ืคืจื•ื™ืงื˜ื™ื ื”ื ื•ืชืจื™ื ืขื“ื™ื™ืŸ ืœื ื™ืฆืจื• ืขื“ื›ื•ื ื™ื. ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื”ืชื™ืงื•ืŸ ืฉืœ ื”ืคื’ื™ืขื•ืช ื‘ื—ื‘ื™ืœืช libgcrypt ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ืืœื”: ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, ืคื“ื•ืจื”, openSUSE / SUSE, FreeBSD, ืงืฉืช.

ืคื’ื™ืขื•ื™ื•ืช ืœื ืจื’ื™ืฉื™ื OpenSSL, Botan, mbedTLS ื•-BoringSSL. ืขื“ื™ื™ืŸ ืœื ื ื‘ื“ืง Mozilla NSS, LibreSSL, Nettle, BearSSL, cryptlib, OpenSSL ื‘ืžืฆื‘ FIPS, Microsoft .NET crypto,
libkcapi ืžืงืจื ืœ Linux, Sodium ื•-GnuTLS.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื”ื™ื›ื•ืœืช ืœืงื‘ื•ืข ืืช ื”ืขืจื›ื™ื ืฉืœ ื‘ื™ื˜ื™ื ื‘ื•ื“ื“ื™ื ื‘ืžื”ืœืš ื”ื›ืคืœื” ืกืงืœืจื™ืช ื‘ืคืขื•ืœื•ืช ืขืงื•ืžื” ืืœื™ืคื˜ื™ืช. ืฉื™ื˜ื•ืช ืขืงื™ืคื•ืช, ื›ืžื• ื”ืขืจื›ืช ื”ืฉื”ื™ื” ื—ื™ืฉื•ื‘ื™ืช, ืžืฉืžืฉื•ืช ืœื—ื™ืœื•ืฅ ืžื™ื“ืข ืกื™ื‘ื™ื•ืช. ื”ืชืงืคื” ืžื—ื™ื™ื‘ืช ื’ื™ืฉื” ืœืœื ื”ืจืฉืื•ืช ืœืžืืจื— ืฉืขืœื™ื• ื ื•ืฆืจืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช (ืœื ืœื ื ื›ืœืœื• ื•ื”ืชืงืคื” ืžืจื—ื•ืง, ืื‘ืœ ื”ื™ื ืžืกื•ื‘ื›ืช ืžืื•ื“ ื•ื“ื•ืจืฉืช ื›ืžื•ืช ื’ื“ื•ืœื” ืฉืœ ื ืชื•ื ื™ื ืœื ื™ืชื•ื—, ื›ืš ืฉื”ื™ื ื™ื›ื•ืœื” ืœื”ื™ื—ืฉื‘ ื›ื‘ืœืชื™ ืกื‘ื™ืจื”). ืœื˜ืขื™ื ื” ื–ืžื™ืŸ ื›ืœื™ื ืฉืฉื™ืžืฉื• ืœื”ืชืงืคื”.

ืœืžืจื•ืช ื”ื’ื•ื“ืœ ื”ืœื ืžืฉืžืขื•ืชื™ ืฉืœ ื”ื“ืœื™ืคื”, ืขื‘ื•ืจ ECDSA ื“ื™ ื‘ื–ื™ื”ื•ื™ ืืคื™ืœื• ืฉืœ ื›ืžื” ื‘ื™ื˜ื™ื ืขื ืžื™ื“ืข ืขืœ ื•ืงื˜ื•ืจ ื”ืืชื—ื•ืœ (nonce) ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื” ื›ื“ื™ ืœืฉื—ื–ืจ ื‘ืจืฆืฃ ืืช ื›ืœ ื”ืžืคืชื— ื”ืคืจื˜ื™. ืœื˜ืขื ืช ืžื—ื‘ืจื™ ื”ืฉื™ื˜ื”, ื›ื“ื™ ืœืฉื—ื–ืจ ืžืคืชื— ื‘ื”ืฆืœื—ื”, ื“ื™ ื‘ื ื™ืชื•ื— ืฉืœ ื›ืžื” ืžืื•ืช ืขื“ ื›ืžื” ืืœืคื™ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืฉื ื•ืฆืจื• ืœื”ื•ื“ืขื•ืช ื”ืžื•ื›ืจื•ืช ืœืชื•ืงืฃ. ืœื“ื•ื’ืžื”, ื ื•ืชื—ื• 90 ืืœืฃ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื‘ืืžืฆืขื•ืช ื”ืขืงื•ืžื” ื”ืืœื™ืคื˜ื™ืช secp256r1 ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืžืคืชื— ื”ืคืจื˜ื™ ื”ืžืฉืžืฉ ื‘ื›ืจื˜ื™ืก ื”ื—ื›ื Athena IDProtect ื”ืžื‘ื•ืกืก ืขืœ ืฉื‘ื‘ Inside Secure AT11SC. ื–ืžืŸ ื”ื”ืชืงืคื” ื”ื›ื•ืœืœ ื”ื™ื” 30 ื“ืงื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”