[108670] in cryptography@c2.net mail archive
Re: fyi: Adi Shamir's microprocessor bug attack
daemon@ATHENA.MIT.EDU (Christian Paquin)
Wed Nov 21 23:15:15 2007
Date: Wed, 21 Nov 2007 15:23:53 -0500
From: Christian Paquin <paquin@credentica.com>
To: cryptography@metzdowd.com
In-Reply-To: <20071117192508.911C7E7C2DD@networking.stanford.edu>
' =JeffH ' wrote:
> From: John Young <cryptome@earthlink.net>
> [...]
> Research Announcement: Microprocessor Bugs Can Be Security Disasters
> [...]
> A similar attack can be applied to any security scheme based on
> discrete logs modulo a prime, and to any security scheme based on
> elliptic curves (in which we can also exploit division bugs)
Does somebody know if, in case of a discrete log scheme, this would
result in an attack using one chosen message (like for RSA), or would
the attack be similar to the one described by Boneh, DeMillo and Lipton
for Schnorr's identification protocol and require O(n log n) executions?
- Christian
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com