1 of 21

Jonathan Berger

Introduction to Cyber Security

TA 5: PKI – RSA

Based on slides of Benny Pinkas and Avishay Yanai

2 of 21

Warmup exercise

  •  

3 of 21

Reminder - Plain/Textbook RSA

  •  

4 of 21

RSA - Exercise #1

  •  

5 of 21

Plain RSA – Exercise #2

  •  

6 of 21

Plain RSA – Exercise #3

  •  

7 of 21

Reminder - Plain/Textbook RSA Signature

  •  

8 of 21

Signatures vs. MACs

Signatures

  •  

MACs

 

9 of 21

Plain RSA signatures – Exercise #4

  •  

10 of 21

Plain RSA signatures – Exercise #4.1

  •  

11 of 21

RSA Signatures – Exercise #5

  •  

12 of 21

RSA Problems in the Real World

  •  

13 of 21

RSA Problems in the Real World (cont.)

  •  

square-and-multiply

14 of 21

RSA Problems in the Real World (cont.)

  • The line in bold would cause an iteration to take more time, thus making this code suspectable to timing attacks allowing to leak the key

  • Furthermore, assume a smartcard that generates signatures
    • It was found out that during multiplication the smartcard’s power consumption is higher. By measuring the length of this period it is possible to distinguish the number of multiplication – allowing an attacker to extract the key

square-and-multiply

15 of 21

Lamport’s One-Time Signature Scheme

  •  

16 of 21

Lamport’s One-Time Signature Scheme - Example

  •  

17 of 21

Lamport’s One-Time Signature Scheme (cont.)

  •  

18 of 21

Yehuda’s One-Time Signature Scheme

  • וַיֹּאמֶר מָה הָעֵרָבוֹן אֲשֶׁר אֶתֶּן לָּךְ וַתֹּאמֶר חֹתָמְךָ וּפְתִילֶךָ וּמַטְּךָ אֲשֶׁר בְּיָדֶךָ וַיִּתֶּן לָּהּ וַיָּבֹא אֵלֶיהָ וַתַּהַר לוֹ. (בראשית ל"ח:יח)

19 of 21

20 of 21

Exercise

  •  

21 of 21

Questions?