CRYPTO August 2012
Efficient Padding Oracle Attacks On Cryptographic Hardware
- r The Million Message Attack in 15 000 Messages
Graham Steel joint work with R. Bardou, R. Focardi, Y. Kawamoto,
- L. Simionato, J.-K. Tsay
Efficient Padding Oracle Attacks On Cryptographic Hardware or The - - PowerPoint PPT Presentation
Efficient Padding Oracle Attacks On Cryptographic Hardware or The Million Message Attack in 15 000 Messages Graham Steel joint work with R. Bardou, R. Focardi, Y. Kawamoto, L. Simionato, J.-K. Tsay CRYPTO August 2012 BLUF (Bottom Line Up
CRYPTO August 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
n
n
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
1 mod n is PKCS conforming.
i mod n is PKCS conforming.
n 2B+rin b
a
i mod n is PKCS conforming.
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012
◮ (obvious?) you don’t need to implement
◮ Pay close attention to floor/ceiling bounds in original
Graham Steel - Efficient Padding Oracle Attacks on Cryptographic Hardware 15 June 2012