International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 09 June 2013

Elke De Mulder, Michael Hutter, Mark E. Marson, Peter Pearson
ePrint Report ePrint Report
In this paper we describe an attack against nonce leaks in 384-bit ECDSA using an FFT-based attack due to Bleichenbacher. The signatures were computed by a modern smart card. We extracted the low-order bits of each nonce using a template-based power analysis attack against the modular inversion of the nonce. We also developed a BKZ-based method for the range reduction phase of the attack, as it was impractical to collect enough signatures for the collision searches originally used by Bleichenbacher. We confirmed our attack by extracting the entire signing key using a 5-bit nonce leak from 4000 signatures.

Expand

Additional news items may be found on the IACR news page.