The Million-Key Question: Investigating the Origins of RSA Public Keys
usenix.org
usenix.org
So this research might allow someone who didn't already know to recognize more about where a key came from.
If it will turn out, that particular library has vulnerability, one can quickly search for other vulnerable keys from large datasets like IPv4-wide TLS scans.
Isn't this incorrect? The implication would be that quantum computers could solve NP-Complete problems in polynomial time.
A quantum computer is not a Turing machine. Yes, it can solve things in polynomial time that a Turing machine cannot do. But that doesn't mean that given problem is/isn't NP hard.
That's all I'm saying... they're implying that you could reduce, say, 3SAT to factoring, which would be very very surprising.
("BQP (bounded error quantum polynomial time) is the class of decision problems solvable by a quantum computer in polynomial time, with an error probability of at most 1/3 for all instances.")
Wikipedia has it first on their "list of problems that might be NP-intermediate", i.e. problems that are in NP but not in P or NP-hard. [0]
If you will provide 5 keys all generated by the same library, the correct library should be within top three most probable sources with high (>95%) probability.
(if not, please submit feedback :))
When you look at ways to generate ECC keys, there are classes of vulnerable numbers for which you need to test.
I agree that any protocol that required you to generate curves or even base points on the fly would have similar concerns, but we generally don't use those kinds of protocols.
Still, while I'm punching here a wee bit above my weight - I should read the 186-4 again - there are some tests to verify the strength of the prime. Is it enough for a similar classification? - I don't know...
It's true that the particular curves a system supports could be a kind of fingerprint, but that's a banal observation, equally true of the ciphers they support, or the compression algorithms.
ECDH doesn't, but ECDSA does. That's why we have Curve25519 & Ed25519, respectively.
Given the thousands of employees the NSA has working on all aspects of cryptography, there must be countless examples of this type of investigation. It's integral to traffic analysis and to fingerprinting of cryptosystems.
At least I hope that the NSA does lots of stuff like this. Because if they don't, what does that leave them doing? If the NSA is simply evil and/or incompetent, that's not enough ROI for the US taxpayers.
Unfortunately, NSA work probably remains highly classified for so long that an ex employee would never be able to write about it in technical detail. But I could be wrong? Are there any Inside Baseball books out there revealing the inner workings of NSA spooks?