演講公告
新聞標題: ( 2024-09-26 )
演講主題:RSA Signature Forgery Attacks Against Weak Implementations
主講人:Sze Yiu Chau 教授(香港中文大學)
演講日期:2024年10月1日14:00 –15:00
演講地點:(光復校區) 科學一館213室
摘要內容:
Abstract
RSA signature is a cornerstone of network security, widely used by different systems and applications as the means of achieving cryptographic authentication guarantees. In this talk, we will revisit the problem of verifying RSA signatures. Using different techniques, our recent research revealed many instances of unwarranted leniency in implementations of RSA signature verifiers. Critically, our findings suggest that many systems are susceptible to variants of the Bleichenbacher-style RSA signature forgery attack. We will look at how this attack, enabled by weak implementations, can nullify the security guarantees promised by the underlying cryptography, and discuss how this threat can be mitigated in practice.相關檔案:Talk_1131001.pdf
