首页> 外文期刊>Future generation computer systems >ECDSA weak randomness in Bitcoin
【24h】

ECDSA weak randomness in Bitcoin

机译:ECDSA比特币中的弱随机性

获取原文
获取原文并翻译 | 示例

摘要

Bitcoin security draws more and more attention recently. One of Bitcoin vulnerabilities is caused by ECDSA weak randomness. A random number is not cryptographically secure, which leads to private key leakage and even fund theft. This security problem has been well known in Bitcoin community and fixed by applying RFC 6979 update in 2013.In this paper, we systematically revisit the cases where random numbers are reused and evaluate them based on practical Bitcoin transactions. After analyzing Bitcoin transaction dataset from January 2009 to July 2017, we find that there are still approximately 0.48 percent of transactions involving this vulnerability, and 1331 private keys have been compromised. In addition, the transactions related to some involved addresses have a common pattern, which gives us a clue that a spam transaction attack may take advantage of ECDSA weak randomness. We also examine mainstream Bitcoin software wallets to check whether they are susceptible to ECDSA weak randomness. Even the result is quite optimistic, an example that one of the influenced addresses leaked in April 2014 is still in use again in August 2017 reflects that the severity of ECDSA weak randomness may not be paid enough attention even after its discovery and solution in 2013. (C) 2019 Elsevier B.V. All rights reserved.
机译:比特币安全最近引起了越来越多的关注。比特币漏洞之一是由ECDSA弱随机性引起的。随机数不是加密安全的,这会导致私钥泄漏甚至盗窃资金。该安全问题已在比特币社区中广为人知,并于2013年通过应用RFC 6979更新得以解决。在本文中,我们系统地回顾了重用随机数的情况,并根据实际的比特币交易对其进行了评估。在分析了2009年1月至2017年7月的比特币交易数据集之后,我们发现仍然有大约0.48%的交易涉及此漏洞,并且有1 331个私钥被泄露。此外,与某些涉及地址有关的交易具有共同的模式,这为我们提供了一个线索,即垃圾邮件交易攻击可能利用ECDSA的弱随机性。我们还检查了主流比特币软件钱包,以检查它们是否容易受到ECDSA弱随机性的影响。即使结果是相当乐观的,例如2014年4月泄漏的受影响地址之一仍在2017年8月再次使用的一个例子,这表明ECDSA弱随机性的严重性即使在2013年发现并解决后也可能没有引起足够的重视。 (C)2019 Elsevier BV保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号