Post-quantum crypto cracked in an hour with one core of an ancient Xeon
- Reference: 1659509946
- News link: https://www.theregister.co.uk/2022/08/03/nist_quantum_resistant_crypto_cracked/
- Source link:
The [1]Supersingular Isogeny Key Encapsulation (SIKE) algorithm was [2]chosen by NIST just last month as a candidate for standardization, meaning it advanced to an extra round of testing en route to adoption.
Within SIKE lies a public key encryption algorithm and a key encapsulated mechanism, each instantiated with four parameter sets: SIKEp434, SIKEp503, SIKEp610 and SIKEp751.
[3]
Microsoft – whose research team played a role in the algorithm's development along with multiple universities, Amazon, Infosec Global and Texas Instruments – set up a $50,000 [4]bounty for anyone who could crack it.
[5]
[6]
Belgian boffins Wouter Castryck and Thomas Decru claim to have done just that.
"Ran on a single core, the appended Magma code breaks the Microsoft SIKE challenges $IKEp182 and $IKEp217 in about 4 minutes and 6 minutes, respectively. A run on the SIKEp434 parameters, previously believed to meet NIST's quantum security level 1, took about 62 minutes, again on a single core," wrote Castryck and Decru, of Katholieke Universiteit Leuven (KU Leuven ) in a a [7]preliminary article [PDF] announcing their discovery.
[8]
The authors made their code public, as well as the details of their processor: an [9]Intel Xeon CPU E5-2630v2 at 2.60GHz . That bit of kit was launched in Q3 2013, used Intel's Ivy Bridge architecture and a 22nm manufacturing process. The chip offered six cores – not that five of them were in any way encumbered by this challenge.
[10]Actual quantum computers don't exist yet. The cryptography to defeat them may already be here
[11]Warning: China planning to swipe a bunch of data soon so quantum computers can decrypt it later
[12]IBM puts NIST’s quantum-resistant crypto to work in Z16 mainframe
[13]NSA: We 'don't know when or even if' a quantum computer will ever be able to break today's public-key encryption
Quantum-resistant encryption research is a hot topic because it is felt that quantum computers are almost certain to become prevalent and sufficiently powerful to crack existing encryption algorithms. It is therefore prudent to prepare crypto that can survive future attacks, so that data encrypted today remains safe tomorrow, and digital communications can remain secure.
Thus, bounties for testing its limits abound.
Microsoft [14]described the algorithm as using arithmetic operations on elliptic curves defined over finite fields and compute maps, also called isogenies, between the curves.
Finding such an isogeny was thought to be sufficiently difficult to provide reasonable security – a belief now shattered by nine-year-old tech.
[15]
Alongside the vintage processor, Castryck and Decru used a key recovery attack on the Supersingular Isogeny Diffie–Hellman key exchange protocol (SIDH) that was based on Ernest Kani's "glue-and-split" theorem.
"The attack exploits the fact that SIDH has auxiliary points and that the degree of the secret isogeny is known. The auxiliary points in SIDH have always been an annoyance and a potential weakness, and they have been exploited for fault attacks, the GPST adaptive attack, torsion point attacks, etc." argued University of Auckland mathematician Stephen Galbraith in his [16]cryptography blog.
The math gets cerebral, and Galbraith suggests if you really want to understand it, you need to study Richelot isogenies and abelian surfaces.
Damn. Another missed opportunity during lockdown.
But we digress. For those who already have a rich background in elliptic curve cryptography and want a quick immersion, there are [17]several Twitter threads that [18]analyze the achievement at greater depth.
Some [19]professionals in the arena propose that not all is lost with SIKE.
SIKE co-creator David Jao [20]reportedly believes the NIST submitted version of SIKE used a single step to generate the key, and a possible more resilient variant could be constructed with two steps.
That possibility lies still in a yet undiscovered portion of the intersection of mathematics and computer science. In the meantime, cryptography experts are shaken.
"There is no doubt that this result will reduce confidence in isogenies. The sudden appearance of an attack this powerful shows that the field is not yet mature," commented Galbraith.
Security researcher Kenneth White [21]tweeted his awe and noted "In 10-20 yrs (or 50, or never) we *might* have practical quantum computers, so let's roll out replacement PQ crypto now. Which could be trivially broken today, on a laptop."
But as Kevin Reed, CISO of cybersecurity firm Acronis, put it in a [22]LinkedIn post : "It's still better than if it was discovered after it is standardized." ®
Get our [23]Tech Resources
[1] https://sike.org/
[2] https://www.theregister.com/2022/07/05/nist_quantum_resistant_algorithms/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YupHV31didhn56Vudx3-wAAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.microsoft.com/en-us/msrc/sike-cryptographic-challenge
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YupHV31didhn56Vudx3-wAAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YupHV31didhn56Vudx3-wAAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://eprint.iacr.org/2022/975.pdf
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YupHV31didhn56Vudx3-wAAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://ark.intel.com/content/www/us/en/ark/products/75790/intel-xeon-processor-e52630-v2-15m-cache-2-60-ghz.html
[10] https://www.theregister.com/2022/07/05/nist_quantum_resistant_algorithms/
[11] https://www.theregister.com/2021/11/29/china_quantum_ai_offensive/
[12] https://www.theregister.com/2022/07/27/z16_ibm_post_quantum_crypto/
[13] https://www.theregister.com/2021/09/01/nsa_quantum_computing_faq/
[14] https://www.microsoft.com/en-us/research/project/sike/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YupHV31didhn56Vudx3-wAAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/
[17] https://twitter.com/oudomphe/status/1553819064803463175
[18] https://twitter.com/kutasp/status/1553600601317072898
[19] https://twitter.com/FouotsaB/status/1553419400090456064
[20] https://arstechnica.com/information-technology/2022/08/sike-once-a-post-quantum-encryption-contender-is-koed-in-nist-smackdown/
[21] https://twitter.com/kennwhite/status/1554470699007447041
[22] https://www.linkedin.com/posts/kevin-reed-4a2c6162_an-efficient-key-recovery-attack-on-sidh-activity-6960140495587094528-y61W/?utm_source=linkedin_share&utm_medium=android_app
[23] https://whitepapers.theregister.com/
So these people have managed to break a shiny new extra special crypto using maths the likes of which the wiki pages read as undecipherable gibberish...
...and they only get a lousy fifty grand?
Clearly NIST has approximately zero confidence in their creation. And, clearly, with good reason.
Though, to be honest, this level of pwnage is just embarrassing. Destroyed in minutes not using some imaginary quantum computer, but a near decade old machine, and it probably didn't even exercise the cooling fan. Utter devastation.
Expect much more of this for the forseeable future. This is a new discipline in its infancy, and the real lessons will only get learned the hard way.
Ancient?
Stuff circa 2013 is ancient? New stone (silicon) age perhaps? I'm still using a 2010 Dell laptop most days. Admittedly, not for cryptographic research.
...the rest of you... keep banging the rocks together.
Re: Ancient?
I have a pair of i7-3770s sitting in my pile of recently retired computers. I don't know how the Ivy Bridge i7 compares with the Xeon version for single core performance, but either way, I could definitely use one of them to crack this in a few minutes.
Now imagine how quick this would be on an Alder Lake, or even an A14.
Re: Ancient?
From time to time I've looked at what the pay-back time would be to replace my server - mostly in terms of power savings. Previously I've decided that I probably won't last long enough. With current energy prices and lower component costs (if we can get them), I'm now not so sure.
Time for some more spreadsheet arithmetic on my prehistoric laptop.
Re: Ancient?
Ancient? 8^D
My ca. 2011 Sun Ultra24 workstation running on a Quad Core Q9550 and 8.0Gb RAM does just fine, thank you.
Does Devuan Linux 5.10 and a headless Devuan Chimaera VM for PiHole/Unbound duties.
Got it 2nd. hand/newish for a song in late 2015: upgraded CPU/RAM, threw in a SAS-II board and 4xHDD and was off to the races.
It's been seven years with no issues (save the utter crap Sun BIOS) and I don't see myself changing rig anytime soon.
But if for some reason I was forced to do it, it will probably be just the mainboard/CPU/RAM as the box is top notch even by today's standards.
O.
Counter to standard practice
I thought the basic idea was
1. Identify the broken algorithm
2. Develop exploit
3. Wait til it gets implemented and widely adopted
4. Use it to exfiltrate lots of secrets
5. Someone else who can't keep their trap shut publishes (1.)
6. Repeat
They seem to have skipped a few steps.
Oh well
At least they can afford a better computer now.
Cheaters!
The algorithm was supposed to resist decryption by *quantum* computers.
Nobody said anything about an old Pentium.
Re: Cheaters!
Or a short length of rubber hose.
Re: Cheaters!
I'm pretty sure it's supposed to be a $5 wrench.
Re: Cheaters!
Quality rubber hose is only £0.49 for an adequate length.
It makes a difference if you're planning an attack at scale.
Just say no...
...to the post quantum cryptography snake oil salesman. Don't replace proven algorithms that could be broken by some fantasy quantum computer which doesn't yet and will probably never exist, with what has now been demonstrated to be vastly inferior alternatives.