[108670] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: fyi: Adi Shamir's microprocessor bug attack

daemon@ATHENA.MIT.EDU (Christian Paquin)
Wed Nov 21 23:15:15 2007

Date: Wed, 21 Nov 2007 15:23:53 -0500
From: Christian Paquin <paquin@credentica.com>
To: cryptography@metzdowd.com
In-Reply-To: <20071117192508.911C7E7C2DD@networking.stanford.edu>

' =JeffH ' wrote:
> From: John Young <cryptome@earthlink.net>
> [...]
> Research Announcement: Microprocessor Bugs Can Be Security Disasters
> [...]
> A similar attack can be applied to any security scheme based on
> discrete logs modulo a prime, and to any security scheme based on
> elliptic curves (in which we can also exploit division bugs)

Does somebody know if, in case of a discrete log scheme, this would 
result in an attack using one chosen message (like for RSA), or would 
the attack be similar to the one described by Boneh, DeMillo and Lipton 
for Schnorr's identification protocol and require O(n log n) executions?

  - Christian

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post