{"id":38635,"date":"2019-10-31T22:24:58","date_gmt":"2019-10-31T19:24:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa\/"},"modified":"2019-10-31T22:24:58","modified_gmt":"2019-10-31T19:24:58","slug":"novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","title":{"rendered":"Nowa technika ataku przez zewn\u0119trzne kana\u0142y, umo\u017cliwiaj\u0105ca odzyskiwanie kluczy ECDSA","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Badacze z Uniwersytetu Masaryka <noindex><a rel=\"nofollow\" href=\"https:\/\/seclists.org\/oss-sec\/2019\/q4\/3\">ujawnili<\/a><\/noindex> informacje o <noindex><a rel=\"nofollow\" href=\"https:\/\/minerva.crocs.fi.muni.cz\/\">lukach<\/a><\/noindex> w r\u00f3\u017cnych implementacjach algorytmu tworzenia podpisu cyfrowego ECDSA\/EdDSA, umo\u017cliwiaj\u0105cych odzyskanie warto\u015bci klucza prywatnego na podstawie analizy wyciek\u00f3w informacji o poszczeg\u00f3lnych bitach, ujawniaj\u0105cych si\u0119 podczas stosowania metod analizy poprzez zewn\u0119trzne kana\u0142y. Luki te otrzyma\u0142y kryptonim Minerva. <\/p>\n<p>Najbardziej znane projekty, kt\u00f3rych dotyczy proponowana metoda ataku, to OpenJDK\/OracleJDK (CVE-2019-2894) oraz biblioteka <noindex><a rel=\"nofollow\" href=\"https:\/\/git.gnupg.org\/cgi-bin\/gitweb.cgi?p=libgcrypt.git\">Libgcrypt<\/a><\/noindex> (CVE-2019-13627), u\u017cywana w GnuPG. Problem dotyczy tak\u017ce <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/matrixssl\/matrixssl\/\">MatrixSSL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/weidai11\/cryptopp\/\">Crypto++<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/wolfSSL\/wolfssl\/\">wolfCrypt<\/a><\/noindex>,   <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/indutny\/elliptic\/\">elliptic<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kjur\/jsrsasign\">jsrsasign<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/warner\/python-ecdsa\">python-ecdsa<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/DavidEGrayson\/ruby_ecdsa\">ruby_ecdsa<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/AntonKueltz\/fastecdsa\">fastecdsa<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/esxgx\/easy-ecc\/\">easy-ecc<\/a><\/noindex> oraz kart smart Athena IDProtect. Nie zosta\u0142y przetestowane, ale jako potencjalnie wra\u017cliwe wskazano r\u00f3wnie\u017c karty Valid S\/A IDflex V, SafeNet eToken 4300 i TecSec Armored Card, kt\u00f3re wykorzystuj\u0105 standardowy modu\u0142 ECDSA. <\/p>\n<p>Problem ju\u017c zosta\u0142 rozwi\u0105zany w wydaniach libgcrypt 1.8.5 i wolfCrypt 4.1.0, pozosta\u0142e projekty jeszcze nie wyda\u0142y aktualizacji. Mo\u017cna \u015bledzi\u0107 napraw\u0119 luki w pakiecie libgcrypt w dystrybucjach na tych stronach: <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-13627\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-13627.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-13627\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-13627\">openSUSE\/SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/\">FreeBSD<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/CVE-2019-13627\">Arch<\/a><\/noindex>.<\/p>\n<p>Podatno\u015bci <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/crocs-muni\/ECTester\/blob\/master\/docs\/LIBS.md\">niepodatne<\/a><\/noindex> OpenSSL, Botan, mbedTLS i BoringSSL. Jeszcze nie zosta\u0142y przetestowane Mozilla NSS, LibreSSL, Nettle, BearSSL, cryptlib, OpenSSL w trybie FIPS, Microsoft .NET crypto,<br \/>\nlibkcapi z j\u0105dra Linuksa, Sodium i GnuTLS.<\/p>\n<p>Problem jest spowodowany mo\u017cliwo\u015bci\u0105 okre\u015blenia warto\u015bci poszczeg\u00f3lnych bit\u00f3w podczas wykonywania mno\u017cenia przez skalar w operacjach z krzyw\u0105 eliptyczn\u0105. Aby wydoby\u0107 informacje o bitach, stosowane s\u0105 po\u015brednie metody, takie jak ocena op\u00f3\u017anienia przy wykonywaniu oblicze\u0144. Do ataku wymagany jest dost\u0119p nieuprzywilejowany do hosta, na kt\u00f3rym odbywa si\u0119 generacja podpisu cyfrowego (nie <noindex><a rel=\"nofollow\" href=\"https:\/\/minerva.crocs.fi.muni.cz\/#remote\">wyklucza<\/a><\/noindex> atak zdalny, ale jest on znacznie utrudniony i wymaga du\u017cej ilo\u015bci danych do analizy, dlatego mo\u017cna go uzna\u0107 za ma\u0142o prawdopodobny). Aby pobra\u0107 <noindex><a rel=\"nofollow\" href=\"https:\/\/minerva.crocs.fi.muni.cz\/#poc\">dost\u0119pne<\/a><\/noindex> narz\u0119dzie u\u017cywane do ataku.<\/p>\n<p>Mimo niewielkiego rozmiaru wycieku, dla ECDSA wystarczy zdefiniowa\u0107 nawet kilka bit\u00f3w informacji o wektorze inicjalizacji (nonce), aby przeprowadzi\u0107 atak na sekwencyjne odzyskiwanie ca\u0142ego klucza prywatnego. Wed\u0142ug autor\u00f3w metody, do pomy\u015blnego odzyskania klucza wystarczy analiza od kilkuset do kilku tysi\u0119cy podpis\u00f3w cyfrowych, wygenerowanych dla wiadomo\u015bci znanych atakuj\u0105cemu. Na przyk\u0142ad, aby okre\u015bli\u0107 klucz prywatny u\u017cywany w karcie smart Athena IDProtect opartej na chipie Inside Secure AT90SC, przy u\u017cyciu krzywej eliptycznej secp256r1 przeanalizowano 11 tysi\u0119cy podpis\u00f3w cyfrowych. Ca\u0142kowity czas ataku wyni\u00f3s\u0142 30 minut.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>\u0179r\u00f3d\u0142o: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51609\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c. \u041c\u0430\u0441\u0430\u0440\u0438\u043a\u0430 \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0430 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u0438 ECDSA\/EdDSA, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0443\u0442\u0435\u0447\u0435\u043a \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0439 \u043e\u0431 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0431\u0438\u0442\u0430\u0445, \u0432\u0441\u043f\u043b\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u043f\u0440\u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u043c\u0435\u0442\u043e\u0434\u043e\u0432 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0438 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Minerva. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\u043c\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438, \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f OpenJDK\/OracleJDK (CVE-2019-2894) \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38635","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043a\u043b\u044e\u0447\u0438 ECDSA | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Nowa technika ataku przez kana\u0142y boczne, umo\u017cliwiaj\u0105ca odzyskiwanie kluczy ECDSA | ProHoster","description":"Naukowcy z uniwersytetu im.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0430\u0442\u0430\u043a\u0438 \u043f\u043e \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u043c \u043a\u0430\u043d\u0430\u043b\u0430\u043c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u043a\u043b\u044e\u0447\u0438 ECDSA | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438\u043c.","og:url":"https:\/\/prohoster.info\/pl\/blog\/news\/novaya-tehnika-ataki-po-storonnim-kanalam-pozvolyayushhaya-vosstanovit-klyuchi-ecdsa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:58+00:00","article:modified_time":"2019-10-31T19:24:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38635","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:51:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:06:23","updated":"2026-01-23 22:51:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/38635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=38635"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/38635\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=38635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=38635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=38635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}