Summary

  • Researchers from UC San Diego and France's INRIA successfully forged RSA signatures using a 1,024-bit key within a hardware security module, which is typically employed to secure cryptocurrency keys, without the need to extract the key.
  • Both Bitcoin and Ethereum utilize elliptic-curve digital signatures like ECDSA, hence this research is limited to RSA signatures.
  • The attack required approximately 2^32 signing requests (around 4 billion) and 1,380 CPU core-years, with the authors asserting that it does not currently threaten most modern RSA systems that employ padding.

Researchers from UC San Diego and France's Institute for Research in Computer Science have managed to mimic the operations of a hardware security module—an anti-tampering device that safely stores private keys and signs requests—without needing to extract the key. They outlined their findings in a paper submitted to the IACR Cryptology ePrint Archive on September 20.

However, cryptocurrency holders need not worry; this does not imply a vulnerability for Bitcoin or Ethereum. Bitcoin employs an elliptic curve digital signature algorithm (ECDSA), which also supports Schnorr signatures. Ethereum and many major blockchain platforms use similar systems. The focus of this research is on Rivest-Shamir-Adleman (RSA) cryptography, which is a distinct signature method.

Myriad: How high will Bitcoin go? Click to make your prediction.

This finding serves as a critical evaluation of key protection methods. Institutional custody providers, according to BitGo, utilize hardware security modules to ensure that keys remain secured within the device. In this case, the key did not leave the device, yet the researchers were still able to create forged signatures.

To conduct their experiment, they disabled the hardware security module's FIPS mode, which is a certified security setting, allowing it to sign arbitrary numbers. They then employed a test key of their own design.

They requested signatures for about 4 billion chosen numbers and analyzed the results. Imagine a vault that never opens but will stamp any blank paper you can slide underneath; if you ask enough times, you might figure out how to replicate the stamp.

Understanding Digital Signatures

Whenever a transaction is confirmed, the wallet signs it using the private key, creating a digital signature that verifies the key holder's approval and ensures the message remains unaltered during transmission.

RSA, developed in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir (the "S" in RSA), is one method of generating that proof.

The fundamental principle behind RSA is that while multiplying two large prime numbers is straightforward, factoring the resulting product is significantly challenging. The authors note that RSA's security is generally predicated on this difficulty, although breaking RSA has not been proven equivalent to factoring. Their method did not involve any actual factorization.

Who Might Be Impacted?

Standard RSA signing incorporates padding—a process that scrambles and formats data, such as PKCS#1 v1.5 or PSS—before any mathematical operations. The authors contend that their attack does not pose an immediate risk to most current RSA implementations due to this padding. The paper is a preprint and not yet peer-reviewed.

Some systems intentionally provide an oracle. RSA-based blind signatures allow a server to sign documents without viewing them, which is a mechanism used in a variant of Privacy Pass. Cloudflare has indicated that Apple utilizes a version of Privacy Pass that allows users to validate they have completed a check, like a CAPTCHA, without disclosing their identity.

Blind signatures have a historical basis in cryptography, with David Chaum using the technique when he founded DigiCash in 1989.

Quantum Threats Remain the Greater Concern

Headlines claiming "RSA is broken" are not new. In January 2023, researchers in China reported a quantum approach that threatened RSA but only factored a 48-bit number, which experts dismissed as insignificant. This current demonstration, however, involves an actual 1,024-bit key, albeit with a caveat regarding the oracle.

The authors suggest that their findings provide classical evidence for the necessity of transitioning away from RSA in preparation for the era of quantum computing and the development of quantum-resistant encryption.

For Bitcoin, the quantum threat lies in elliptic-curve signatures. Researchers at Caltech estimated that between 10,000 to 20,000 qubits—the quantum equivalent of bits—might be sufficient to execute Shor's algorithm, which poses a risk to these signatures.

Google has set 2029 as the target year to complete its transition to post-quantum cryptography.

Daily Debrief Newsletter

Stay updated with the latest news stories, along with original features, podcasts, videos, and more.