Researchers Crack 1024-bit RSA Encryption in GnuPG Crypto Library (2024)

Jul 04, 2017Mohit Kumar

Researchers Crack 1024-bit RSA Encryption in GnuPG Crypto Library (1)

Security boffins have discovered a critical vulnerability in a GnuPG cryptographic library that allowed the researchers to completely break RSA-1024 and successfully extract the secret RSA key to decrypt data.

Gnu Privacy Guard (GnuPG or GPG) is popular open source encryption software used by many operating systems from Linux and FreeBSD to Windows and macOS X.

It's the same software used by the former NSA contractor and whistleblower Edward Snowden to keep his communication secure from law enforcement.

The vulnerability, labeled CVE-2017-7526, resides in the Libgcrypt cryptographic library used by GnuPG, which is prone to local FLUSH+RELOAD side-channel attack.

Researchers Crack 1024-bit RSA Encryption in GnuPG Crypto Library (2)

A team of researchers — from Technical University of Eindhoven, the University of Illinois, the University of Pennsylvania, the University of Maryland, and the University of Adelaide — found that the "left-to-right sliding window" method used by the libgcrypt library for carrying out the mathematics of cryptography leaks significantly more information about exponent bits than for right-to-left, allowing full RSA key recovery.

"In this paper, we demonstrate a complete break of RSA-1024 as implemented in Libgcrypt. Our attack makes essential use of the fact that Libgcrypt uses the left-to-right method for computing the sliding-window expansion," the researchers wrote in the research paper.

"The pattern of squarings and multiplications in left-to-right sliding windows leaks significantly more information about the exponent than right-to-left. We show how to extend the Heninger-Shacham algorithm for partial key reconstruction to make use of this information and obtain a very efficient full key recovery for RSA-1024."

L3 Cache Side-Channel Attack requires an attacker to run arbitrary software on the hardware where the private RSA key is used.

Researchers Crack 1024-bit RSA Encryption in GnuPG Crypto Library (3)

The attack allows an attacker to extract the secret crypto key from a system by analyzing the pattern of memory utilization or the electromagnetic outputs of the device that are emitted during the decryption process.

"Thus in practice, there are easier ways to access the private keys than to mount this side-channel attack. However, on boxes with virtual machines, this attack may be used by one VM to steal private keys from another VM," Libgcrypt advisory reads.

Researchers have also provided evidence that the same side channel attack also works against RSA-2048, which require moderately more computation than RSA-1024.

The research paper titled, 'Sliding right into disaster: Left-to-right sliding windows leak,' was authored by Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Christine van Vredendaal, Tanja Lange and Yuval Yarom.

Libgcrypt has released a fix for the issue in Libgcrypt version 1.7.8. Debian and Ubuntu have already updated their library with the latest version of Libgcrypt.

So, you are strongly advised to check if your Linux distribution is running the latest version of the Libgcrypt library.


Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Researchers Crack 1024-bit RSA Encryption in GnuPG Crypto Library (2024)
Top Articles
My Company Is Being Acquired: What Happens To My Stock Options? (Part 1)
Social Media Tech Tips: Understanding Catfishing and How to Stay Safe Online 
Where are the Best Boxing Gyms in the UK? - JD Sports
Compare Foods Wilson Nc
Fat Hog Prices Today
Occupational therapist
Videos De Mexicanas Calientes
Western Razor David Angelo Net Worth
Baseball-Reference Com
Remnant Graveyard Elf
A.e.a.o.n.m.s
Cooktopcove Com
Sams Early Hours
Nutrislice Menus
Straight Talk Phones With 7 Inch Screen
Missouri Highway Patrol Crash
Mahpeople Com Login
Huntersville Town Billboards
Bekijk ons gevarieerde aanbod occasions in Oss.
Nz Herald Obituary Notices
Globle Answer March 1 2023
Kitchen Exhaust Cleaning Companies Clearwater
Sensual Massage Grand Rapids
Gunsmoke Tv Series Wiki
Delete Verizon Cloud
The Creator Showtimes Near Baxter Avenue Theatres
Korg Forums :: View topic
A Grade Ahead Reviews the Book vs. The Movie: Cloudy with a Chance of Meatballs - A Grade Ahead Blog
Max 80 Orl
Plato's Closet Mansfield Ohio
All Things Algebra Unit 3 Homework 2 Answer Key
67-72 Chevy Truck Parts Craigslist
Autozone Locations Near Me
Usf Football Wiki
Delaware judge sets Twitter, Elon Musk trial for October
World History Kazwire
Devotion Showtimes Near The Grand 16 - Pier Park
NHL training camps open with Swayman's status with the Bruins among the many questions
The Holdovers Showtimes Near Regal Huebner Oaks
Taylor University Baseball Roster
Cranston Sewer Tax
Ross Dress For Less Hiring Near Me
Below Five Store Near Me
Weekly Math Review Q2 7 Answer Key
Coroner Photos Timothy Treadwell
Shipping Container Storage Containers 40'HCs - general for sale - by dealer - craigslist
13 Fun & Best Things to Do in Hurricane, Utah
Mynord
UNC Charlotte Admission Requirements
Black Adam Showtimes Near Kerasotes Showplace 14
What Is The Gcf Of 44J5K4 And 121J2K6
라이키 유출
Latest Posts
Article information

Author: Sen. Ignacio Ratke

Last Updated:

Views: 6540

Rating: 4.6 / 5 (56 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Sen. Ignacio Ratke

Birthday: 1999-05-27

Address: Apt. 171 8116 Bailey Via, Roberthaven, GA 58289

Phone: +2585395768220

Job: Lead Liaison

Hobby: Lockpicking, LARPing, Lego building, Lapidary, Macrame, Book restoration, Bodybuilding

Introduction: My name is Sen. Ignacio Ratke, I am a adventurous, zealous, outstanding, agreeable, precious, excited, gifted person who loves writing and wants to share my knowledge and understanding with you.