Abstract
This paper analyzes the cost of breaking ECC under the following assumptions: (1) ECC is using a standardized elliptic curve that was actually chosen by an attacker; (2) the attacker is aware of a vulnerability in some curves that are not publicly known to be vulnerable. This cost includes the cost of exploiting the vulnerability, but also the initial cost of computing a curve suitable for sabotaging the standard. This initial cost depends heavily upon the acceptability criteria used by the public to decide whether to allow a curve as a standard, and (in most cases) also upon the chance of a curve being vulnerable. This paper shows the importance of accurately modeling the actual acceptability criteria: i.e., figuring out what the public can be fooled into accepting. For example, this paper shows that plausible models of the “Brainpool acceptability criteria” allow the attacker to target a onein- a-million vulnerability and that plausible models of the “Microsoft NUMS criteria” allow the attacker to target a one-in-a-hundred-thousand vulnerability.
Original language | English |
---|---|
Title of host publication | Security Standardisation Research |
Subtitle of host publication | Second International Conference, SSR 2015, Tokyo, Japan, December 15-16, 2015, Proceedings |
Editors | L. Chen, S. Matsuo |
Place of Publication | Berlin |
Publisher | Springer |
Pages | 109-139 |
Number of pages | 31 |
ISBN (Print) | 9783319271514 |
DOIs | |
Publication status | Published - 2015 |
Event | 2nd International Conference on Security Standardisation Research (SSR 2015), December 15-16, 2015, Tokyo, Japan - Tokyo, Japan Duration: 15 Dec 2015 → 16 Dec 2015 http://ssr2015.com/ |
Publication series
Name | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
---|---|
Volume | 9497 |
ISSN (Print) | 03029743 |
ISSN (Electronic) | 16113349 |
Conference
Conference | 2nd International Conference on Security Standardisation Research (SSR 2015), December 15-16, 2015, Tokyo, Japan |
---|---|
Abbreviated title | SSR 2015 |
Country/Territory | Japan |
City | Tokyo |
Period | 15/12/15 → 16/12/15 |
Internet address |
Keywords
- ANSI X9
- Brainpool
- Elliptic-curve cryptography
- Microsoft NUMS
- Minimal curves
- NIST
- Nothing-up-mysleeve numbers
- SECG
- Verifiably pseudorandom curves
- Verifiably random curves