rsa
16 stories and discussions about rsa, aggregated from every source we track.
<p>Alternate title: Nearly SNFS-Speed Signature Forgery Sans Factoring N (NSNFSSSFSFN)</p> <p><strong>Abstract.</strong> The security of RSA is generally understood to be based on the complexity of factoring, and key size parameters are extrapolated from the general number field sieve (GNFS). However, this may not accurately represent RSA security in practical scenarios.</p> <p>An under-appreciated 2007 algorithm of Joux, Naccache, and Thom´e allows an attacker to forge RSA signatures after temporary access to a raw RSA signing/decryption oracle in time close to the <em>special</em> number field sieve (SNFS) without factoring the key. We implement and run this algorithm for 1024-bit RSA. In total, the attack took 1380 CPU core-years over five calendar months, and made 232 oracle queries. Most of this time is precomputation; after the precomputation the attacker can forge any signature of choice, offline, in 180 core-years.</p> <p>We carried out our attack using a hardware security module (HSM) as the signing oracle, thus demonstrating the ability to impersonate the HSM through black-box API interactions, without exfiltrating the key. Blind RSA schemes also provide such a signing oracle.</p> <p>Extrapolating our empirical running times to larger key sizes, we conclude that the concrete security of RSA with a signing oracle should be 15 to 30 bits lower than the factoring-based security estimates for the 1024-bit to 4096-bit RSA parameters that are common in practice. Even 4096-bit RSA does not appear to meet a 128-bit security level in this attack model. This highlights a gap in current RSA-type security assumptions, and gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition.</p>
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
Nearly SNFS-Speed Signature Forgery Sans Factoring N - ucsd-hacc/NSNFSSSFSFN
Obscure Factorization Algorithm Powering RSA Factorization in CADO-NFS
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
Nearly SNFS-Speed Signature Forgery Sans Factoring N - ucsd-hacc/NSNFSSSFSFN
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
The world has known for decades that the RSA cryptosystem ’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold. The finding poses little to no practical threat in the immediate term, except possibly in a few edge cases. Even applying the attack against the deprecated use of 1024-bit keys, the method requires more computation than just about anybody—short of nation-states or companies with massive resources—can achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise because it introduces signature forgery, a new way to break RSA keys without factoring. Equally important, this novel method reduces the required computing resources by orders of magnitude. Read full article Comments