【24h】

Factoring RSA Keys in the IoT Era

机译:在物联网时代分解RSA密钥

获取原文

摘要

RSA keys are at risk of compromise when using improper random number generation. Many weak keys can efficiently be discovered and subsequently compromised by finding reused prime factors in a large data set. We collect and analyze 75 million RSA certificates from the Internet, and find that 1 in 172 keys share a factor with another. In contrast, only 5 of 100 million certificates found in a sample from Certificate Transparency logs are compromised by the same technique. The discrepancy in rates of compromise is overwhelmingly due to IoT devices exposed to the Internet, which may be subject to design constraints and limited entropy. The widespread susceptibility of these IoT devices poses a potential risk to the public due to their presence in sensitive settings. We conclude that device manufacturers must ensure their devices have access to sufficient entropy and adhere to best practices in cryptography to protect consumers.
机译:使用不正确的随机数生成时,RSA密钥有遭受破坏的风险。通过在大型数据集中找到可重复使用的主要因素,可以有效地发现许多弱键,然后对其进行折衷。我们从互联网上收集并分析了7500万个RSA证书,发现172个密钥中的1个与另一个共享一个因素。相反,从“证书透明性”日志的样本中找到的1亿个证书中,只有5个受到相同技术的破坏。妥协率的差异绝大多数是由于暴露于Internet的IoT设备造成的,这些设备可能会受到设计约束和熵的限制。这些物联网设备的广泛易感性由于存在于敏感环境中而对公众构成了潜在的风险。我们得出的结论是,设备制造商必须确保其设备具有足够的熵,并遵守密码学的最佳做法以保护消费者。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号