Cryptographic techniques authenticate users and protect information confidentiality. These tasks are performed by subsystems called Oracles.
The most popular Oracle is the RSA system based on two large primes granting secure services. In 2008, a programming error in Open-SSL of the Debian system was detected. Its biased number generator created system vulnerabilities by turning certificates predictable. This paper analyses the generic performance of a RSA cryptographic Oracle and develops a methodology to detect irregularities and anomalies in the quality of the certificates. Ten million certificates delivered by a private PKI were analyzed and found significant differences between theoretical predictions and experimental results.
Notas
Eje: Workshop de seguridad informática (WSI)
Información general
Fecha de exposición:octubre 2012
Fecha de publicación:octubre 2012
Idioma del documento:Inglés
Evento:XVIII Congreso Argentino de Ciencias de la Computación
Institución de origen:Red de Universidades con Carreras en Informática (RedUNCI)
Excepto donde se diga explícitamente, este item se publica bajo la siguiente licencia Creative Commons Attribution-NonCommercial-ShareAlike 2.5 Argentina (CC BY-NC-SA 2.5)