Advertisement
Promo

Desktop platforms Toolkit

Hacking the 'crackers': Key Internet security issue solved

Jim Kerstetter ZDNet.co.uk

Published: 25 Aug 1998 13:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The researchers announced at the start of Crypto'98 Conference held at the University of California-Santa Barbara Monday that they have created the Cramer-Shoup "cryptosystem," which protects public key infrastructures (PKIs) against so-called deductive attacks. The algorithm was named for its creators: Victor Shoup, of IBM's Zurich Research Laboratory, and Ronald Cramer, of the Swiss Federal Institute of Technology. It closes a loophole in public key security uncovered by researchers at Bell Laboratories. The researchers found a way to break through the encryption of an SSL (Secure Sockets Layer) session without actually solving the underlying mathematical problem. Instead, the Bell researchers deduced, from error messages received from a Web server, the private key to the encrypted session. "It's sort of like a safe cracker," Palmer said. "In a non-malleable system like this, the tumblers in the safe don't make any noise."

IBM plans to give away the algorithm details -- built upon the original Diffie-Hellman public key algorithm -- at the conference. The company will also incorporate it in a future version of its Vault Registry digital certificate software.

Cramer-Shoup is not compatible with existing PKIs, and deploying it will require the reissuing of digital certificates, Palmer said. IBM researchers said creating the Cramer-Shoup cryptosystem was an effort to make sure that all of the Internet is using sound security. "This is really the time to do this because the PKIs of the world haven't been deployed yet," Palmer said.

That discovery had set off a flurry of activity by Netscape, Microsoft and Security Dynamics Technologies RSA Data unit that led to a software patch that fixed the immediate problem.

But the Bell Labs development left lingering doubts among security experts about the fundamental integrity of computer networks and suggested future attacks were possible. However, in a phone interview Friday, Bell Labs researcher Daniel Bleichenbacher said the Cramer-Shoup system had demonstrated a method that was impervious to the sort of attack he had developed and graciously accepted defeat.

Bleichenbacher said his research was complementary to that of the IBM-Swiss university team. "My paper suggested the problem,'' the Bell Labs researcher said. "I have an attack and they present a solution."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
15 out of 26 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:

















Video icon

Video

Microsoft Windows 7 Special Report Special Report

How Microsoft can make Windows 7 a success

How Microsoft can make Windows 7 a success

Comment Many businesses have given Vista a wide berth; Microsoft must focus on five areas to make sure Windows 7 doesn't suffer the same fate, argues TechRepublic's Jason Hiner

More Special Reports

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters