★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/cryptography_article-2336.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Cryptography 1/18/2001 22:21

Initial Cryptanalysis of the RSA SecurID Algorithm

@stake
Posted By: Dave Wreski
1/18/2001

This short paper will examine several discovered statistical irregularities in functions used within the SecurID algorithm: the time computation and final conversion routines. Where and how these irregularities can be mitigated by usage and policy are explored. We are planning for the release of a more thorough analysis in the near future. This paper does not present methods of determining the secret component by viewing previously generated or successive tokencodes.

Recently, I.C. Wiener published a reverse engineering effort of the RSA SecurID algorithm. There were few speculations on the security ramifications of the algorithm in I.C. Wiener's posting, so this note is an effort to touch upon areas of concern. We have verified that I.C. Wiener's released version of the proprietary algorithm is accurate by comparing it with our own prior reverse engineering of the same algorithm.

Due to the time sensitivity imposed by the public release of RSA's proprietary algorithm, we felt it necessary to release this brief to help people better understand and work toward reducing the risks to which they might currently be exposed. The risk profile of token devices changes when they are implemented in an uncontrolled environment, such as the Internet, and the research in this paper aims to educate and to help manage those risks. The primary concern is the possiblity to generate a complete cycle of tokencode outputs given a known secret, which is equivilent to the cloning of a token device.


Click here to go to this article.

SafeWeb's Triangle Boy enters CIA civil service
Feb 17

Tatu Ylonen Comments on SSH Trademark
Feb 16

Jay Beale: Education Is Primary Defense for Secure Machines
Feb 16

Online vandals smoke New York Times site
Feb 16

Network Solutions sells its database
Feb 16

Intrusion detection rules drafted
Feb 16

Monitoring Unix Logins
Feb 16

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000