双椭圆曲线确定性随机比特生成器(Dual Elliptic Curve Deterministic Random Bit Generator,Dual_EC_DRBG) ,是一种使用椭圆曲线密码学实现的密码学安全伪随机数生成器(CSPRNG)。该算法自2006年6月左右被公开,尽管受到了大量密码学家们的批评,并被认为存在潜在的后门,但直到2017年被撤销之前,Dual_EC_DRBG在七年的时间内都是NIST SP 800-90A定义的4个(现为3个)标准的CSPRNG之一。
参见
- 密码学安全伪随机数生成器
- 随机数生成器攻击
- Crypto AG:一家主要从事通信和信息安全的瑞士公司,该公司长期受美国中央情报局与德国联邦情报局的直接控制,并在其加密机中插入后门。
参考文献
外部链接
- [http://csrc.nist.gov/publications/nistpubs/800-90A/SP800-90A.pdf NIST SP 800-90A - Recommendation for Random Number Generation Using Deterministic Random Bit Generators]
- [http://projectbullrun.org/dual-ec/ Dual EC DRBG] - Collection of Dual_EC_DRBG information, by Daniel J. Bernstein, Tanja Lange, and Ruben Niederhagen.
- [http://dualec.org/ On the Practical Exploitability of Dual EC in TLS Implementations] - Key research paper by Stephen Checkoway et al.
- [https://link.springer.com/chapter/10.1007%2FBFb0052241 The prevalence of kleptographic attacks on discrete-log based cryptosystems] - Adam L. Young, Moti Yung (1997)
- United States Patent Application Publication **' on the Dual_EC_DRBG backdoor, and ways to negate the backdoor.
- [https://web.archive.org/web/20110525081912/http://www.math.ntnu.no/~kristiag/drafts/dual-ec-drbg-comments.pdf Comments on Dual-EC-DRBG/NIST SP 800-90, Draft December 2005] Kristian Gjøsteen's March 2006 paper concluding that Dual_EC_DRBG is predictable, and therefore insecure.
- [https://link.springer.com/chapter/10.1007%2F978-3-540-74143-5_26 A Security Analysis of the NIST SP 800-90 Elliptic Curve Random Number Generator] Daniel R. L. Brown and Kristian Gjøsteen's 2007 security analysis of Dual_EC_DRBG. Though at least Brown was aware of the backdoor (from his 2005 patent), the backdoor is not explicitly mentioned. Use of non-backdoored constants and a greater output bit truncation than Dual_EC_DRBG specifies are assumed.
- [http://rump2007.cr.yp.to/15-shumow.pdf On the Possibility of a Back Door in the NIST SP800-90 Dual Ec Prng] Dan Shumow and Niels Ferguson's presentation, which made the potential backdoor widely known.
- [http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html The Many Flaws of Dual_EC_DRBG] - Matthew Green's simplified explanation of how and why the backdoor works.
- [http://blog.cryptographyengineering.com/2013/12/a-few-more-notes-on-nsa-random-number.html A few more notes on NSA random number generators] - Matthew Green
- [https://gist.github.com/0xabad1dea/8101758 Sorry, RSA, I'm just not buying it] - Summary and timeline of Dual_EC_DRBG and public knowledge.
- [http://www.ietf.org/mail-archive/web/cfrg/current/msg03651.html [Cfrg] Dual_EC_DRBG ... [was RE: Requesting removal of CFRG co-chair]] A December 2013 email by Daniel R. L. Brown defending Dual_EC_DRBG and the standard process.
评论 (0)