11/18/2007

Mathy Bits

Filed under: Math — Andy @ 11:21 pm

So, it looks like there’s a surprising amount of noteworthy stuff going on in the cryptography community at the moment.

First, Bruce Schneier points out a paper from Dan Shumow and Niels Ferguson (PDF warning) (at CRYPTO 2007) that indicates it’s possible that the NSA (or the NIST, or someone) has inserted a backdoor in a newly standardized random-number generator that makes it possible to predict its output. (Actually, to know its output, if I’m understanding correctly.) That means that any randomness used for cryptography is completely useless if someone knows the secret numbers, which is at least plausible. In short, don’t use “Dual_EC_DRBG”. Or, if you absolutely have to, change the constants.

Then, Adi Shamir notes that a single unknown flaw in a math processor on a CPU could also break important parts of cryptography if someone finds out about it (and is able to preform a known-plaintext chosen-plaintext attack). Of course, he’s not saying one exists, and I’m not sure why that came out now as opposed to any other time, but it’s interesting nonetheless.

Speaking of Adi Shamir, I’m pretty thoroughly convinced that tossing the modular arithmetic into Shamir’s secret sharing algorithm the way it was intended will give proper, non-leaking results. It looks like the flaw is really just an implementation flaw in the way I was looking at the problem (and the way it was replicated on the Wikipedia). So, while it’s something to look out for if you’re actually implementing the algorithm, it’s not a major problem if you’ve got a working, proper implementation. I’ll try to update my blog post (and the affected Wikipedia article, if it still needs fixing) soon.

Andy Schmitz

10/30/2007

A Flaw in Shamir’s Secret Sharing method?

Filed under: Math — Andy @ 1:36 pm

(This post is going to be much more mathy than my standard posts, mostly because I thought about this as I was filling out college applications and decided it would be interesting to follow up on the random thought.)

(I apologize in advance for the poor quality \LaTeX renderings, but they should at least be legible)

A bunch of math follows in the full post.

(more…)

News:
News Headlines (from Google News)

Save The Internet
Apache
Valid CSS
Tableless CSS
Debian
EFF Blue Ribbon Campaign
Geek
Hacker (The Good Kind)
Illinois
Optimized with Turck MMCache
Mozilla
PHP Powered
Cost of Iraq War (US Dollars)
Cost of Iraq War (Civilian Casualties)
Valid XHTML 1.0

RSS 2.0 Feed (Main Site)
RSS 2.0 Feed (Commments)
I Use WordPress
"I ated the purple berries"
--Ralph Wiggum (from The Simpsons)
:: i will not be silenced ::

Copyright 2008, Andy Schmitz.
Page took 0.301 seconds to generate.

Powered by WordPress