Return-Path: <kmigoe@nsa.gov>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
 with ESMTP id 7341A21F8A0F for <cfrg@ietfa.amsl.com>;
 Thu, 13 Dec 2012 12:19:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.598
X-Spam-Level: 
X-Spam-Status: No, score=-10.598 tagged_above=-999 required=5
 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7VkWzzBV5T2d for
 <cfrg@ietfa.amsl.com>; Thu, 13 Dec 2012 12:19:31 -0800 (PST)
Received: from nsa.gov (emvm-gh1-uea08.nsa.gov [63.239.67.9]) by
 ietfa.amsl.com (Postfix) with ESMTP id D28D821F89BE for <cfrg@irtf.org>;
 Thu, 13 Dec 2012 12:19:30 -0800 (PST)
X-TM-IMSS-Message-ID: <1928102a0003b794@nsa.gov>
Received: from MSHT-GH1-UEA02.corp.nsa.gov ([10.215.227.181]) by nsa.gov
 ([63.239.67.9]) with ESMTP (TREND IMSS SMTP Service 7.1;
 TLSv1/SSLv3 AES128-SHA (128/128)) id 1928102a0003b794 ;
 Thu, 13 Dec 2012 15:19:29 -0500
Received: from MSMR-GH1-UEA02.corp.nsa.gov (10.215.227.180) by
 MSHT-GH1-UEA02.corp.nsa.gov (10.215.227.181) with Microsoft SMTP Server (TLS)
 id 14.1.289.1; Thu, 13 Dec 2012 15:19:28 -0500
Received: from MSMR-GH1-UEA03.corp.nsa.gov ([10.215.224.3]) by
 MSMR-GH1-UEA02.corp.nsa.gov ([10.215.227.180]) with mapi id 14.01.0289.001;
 Thu, 13 Dec 2012 15:19:28 -0500
From: "Igoe, Kevin M." <kmigoe@nsa.gov>
To: 'Rene Struik' <rstruik.ext@gmail.com>
Thread-Topic: [Cfrg] Status of DragonFly
Thread-Index: Ac3YlStNhI1Pb7rLTAC7Nu690xzU7QA+m/WAAAhk1JA=
Date: Thu, 13 Dec 2012 20:19:27 +0000
Message-ID: <3C4AAD4B5304AB44A6BA85173B4675CA4AE0C72D@MSMR-GH1-UEA03.corp.nsa.gov>
References: <3C4AAD4B5304AB44A6BA85173B4675CA49672A1B@MSMR-GH1-UEA03.corp.nsa.gov>
 <50CA2873.1090509@gmail.com>
In-Reply-To: <50CA2873.1090509@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.215.254.27]
Content-Type: multipart/alternative;
 boundary="_000_3C4AAD4B5304AB44A6BA85173B4675CA4AE0C72DMSMRGH1UEA03cor_"
MIME-Version: 1.0
Cc: Dan Harkins <dharkins@arubanetworks.com>, "cfrg@irtf.org" <cfrg@irtf.org>
Subject: Re: [Cfrg] Status of DragonFly
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>,
 <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>,
 <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Dec 2012 20:19:35 -0000

--_000_3C4AAD4B5304AB44A6BA85173B4675CA4AE0C72DMSMRGH1UEA03cor_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Thanks Rene.  I agree with your analysis on my first proposed fix.  Clearly=
 this needs some more thought.
Pre-computing PE offline may well turn out to be the best option.

From: Rene Struik [mailto:rstruik.ext@gmail.com]
Sent: Thursday, December 13, 2012 2:12 PM
To: Igoe, Kevin M.
Cc: cfrg@irtf.org; Dan Harkins
Subject: Re: [Cfrg] Status of DragonFly

Hi Kevin:

I do share some of your timing attack concerns. Unless I missed something h=
ere, your suggested fix does not seem to work, however:

Suppose A and B use ECDH with as generator the point G(p):=3D pG, where p:=
=3Dkdf(..) {I use small-case p ("password") rather than capital-case X belo=
w (so as to separate scalars and elliptic curve points)}. Now, suppose A an=
d B exchange X:=3DxG(p) where p is the correct password and where Y:=3D y G=
(p'), where p' is any guess for p by B (or just takes p":=3D1). Then A (the=
 legitimate party holding password p) computes Ka:=3D (xy) G(p')=3D (xy p')=
 G and B computes Kb:=3D(yx) G(p)=3D (yxp) G. In other words, Ka:=3D p' K, =
Kb:=3D p K, where K:=3D (xy)G. So, Ka:=3D (p'/p) Kb. Now, once A sends B a =
key confirmation message, B can just cycle through the password space, comp=
ute a candidate key that A could have computed and check the validity of hi=
s guess via verification of the key confirmation message just received.

As to implementing Dragonfly, one has to be careful in case of active attac=
ks: as an example, if one uses multiple-point multiplications, one may end =
up at the point of infinity as intermediate point in the computation, thus =
forcing implementations to use exception handling routines for point additi=
on/doubling along the entire computational path (Note: if one hits the poin=
t at infinity, this exposes the password used, thus leaking the entire pass=
word in an observable way). If one does not use multiple-point multiplicati=
ons, this attack seems much harder but requires two full scalar multiplicat=
ions (rather than one scalar multiplication as, e.g., SPEKE requires).

Best regards, Rene

=3D=3D
A possible fix is to use the KDF to generate a random X, 1<X<q, where q is =
the size of the cryptographic
subgroup of the curve, and take PE =3D X*G, where G is the generator of the=
 cryptographic subgroup.  For
most cryptographic curves,  q  is very, very close to 2^n, so it is VERY un=
likely that more than 1 call to the
KDF will be needed.

On 12/13/2012 1:42 PM, Igoe, Kevin M. wrote:
I'd like the reading list's input on DragonFly (hereafter called DF), Dan H=
arkins' Password Authenticated
Key Exchange design (draft-irtf-cfrg-dragonfly-00).  I'd like to point out =
that draft-harkins-tls-pwd-03
is a proposal to use DF in  TLS that differs slightly from the CFRG draft.

Here is where I believe we stand:

1.   Confidentiality: The proof that the confidentiality of the key generat=
ed by the DF
protocol is reducible to the standard Diffie-Hellmann problem is quite stra=
ight
forward, so the resulting shared secret value is at least as secure as with=
  standard DH/ECDH.
2.   Authentication: Obviously the system can be no more secure than the pa=
ssword
being used. I believe the most viable attack is to guess a password, use th=
is password
to initiate the  DF protocol with the endpoint being attacked, and see if i=
t works.
Monitoring the system logs should easily detect such an attack.
3.   Timing: I'm particularly concerned about the method used to generate t=
he PE (password
dependent base point) in the ECDH case. Inside a while loop, several parame=
ters,
 including the identities of the two endpoints, the shared password, and a =
counter are
passed to a KDF to produce an n-bit output, where the curve is mod an n-bit=
 prime p.
The resulting n-bit value X is checked to see if 0 <=3D X < p and X^3+a*X+b=
 is a quadratic
residue mod p (an event of probability =BD).  If both these tests are passe=
d, the while
loop is exited and X is used as the x-coordinate of our PE.

The problem I see with (3) is that the number of times through the loop giv=
es an opponent a
check  on any putative value for the password.  E.g.  if their current gues=
s for the password
takes many passes through the while loop to generate the PE, but they obser=
ve that the DF response
 time is inconsistent with that, they have eliminated that guess for the pa=
ssword.

When DF is applied to TLS in as described in draft-harkins-tls-pwd-03, two =
nonces are used as
inputs to the KDF, which has two consequences:
a.   the PE MUST be computed online
b.   each DF exchange gives an independent timing check on the password.
The opponent can passively sit back, monitoring the timing of DF exchanges =
on various links until
they stumble across one where the timings match up with the timings associa=
ted with one of the
passwords they are testing. They've now are able to bypass the authenticati=
on provided by DF.

A possible fix is to use the KDF to generate a random X, 1<X<q, where q is =
the size of the cryptographic
subgroup of the curve, and take PE =3D X*G, where G is the generator of the=
 cryptographic subgroup.  For
most cryptographic curves,  q  is very, very close to 2^n, so it is VERY un=
likely that more than 1 call to the
KDF will be needed.

Another fix would be to require PE generation be done offline, which would =
eliminate any possibility of
using nonces in the DF protocol.  One could, however, mix the nonces in aft=
er the completion to the
DF based Diffie-Hellmann exchange.




----------------+--------------------------------------------------
Kevin M. Igoe   | "We can't solve problems by using the same kind
kmigoe@nsa.gov<mailto:kmigoe@nsa.gov>  | of thinking we used when we create=
d them."
                |              - Albert Einstein -
----------------+--------------------------------------------------







_______________________________________________

Cfrg mailing list

Cfrg@irtf.org<mailto:Cfrg@irtf.org>

http://www.irtf.org/mailman/listinfo/cfrg




--

email: rstruik.ext@gmail.com<mailto:rstruik.ext@gmail.com> | Skype: rstruik

cell: +1 (647) 867-5658 | US: +1 (415) 690-7363

--_000_3C4AAD4B5304AB44A6BA85173B4675CA4AE0C72DMSMRGH1UEA03cor_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";
	color:black;}
p.emailquote, li.emailquote, div.emailquote
	{mso-style-name:emailquote;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:1.0pt;
	border:none;
	padding:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;
	color:black;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1314677586;
	mso-list-template-ids:418692450;}
@list l0:level1
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1
	{mso-list-id:1909026625;
	mso-list-template-ids:-571717634;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor=3D"white" lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Thanks Rene.&nbsp; I agre=
e with your analysis on my first proposed fix. &nbsp;Clearly this needs som=
e more thought.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Pre-computing PE offline =
may well turn out to be the best option.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext">From:</span></b><spa=
n style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif=
&quot;;color:windowtext"> Rene Struik [mailto:rstruik.ext@gmail.com]
<br>
<b>Sent:</b> Thursday, December 13, 2012 2:12 PM<br>
<b>To:</b> Igoe, Kevin M.<br>
<b>Cc:</b> cfrg@irtf.org; Dan Harkins<br>
<b>Subject:</b> Re: [Cfrg] Status of DragonFly<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">Hi Kevin:<br>
<br>
I do share some of your timing attack concerns. Unless I missed something h=
ere, your suggested fix does not seem to work, however:<br>
<br>
Suppose A and B use ECDH with as generator the point G(p):=3D pG, where p:=
=3Dkdf(..) {I use small-case p (&quot;password&quot;) rather than capital-c=
ase X below (so as to separate scalars and elliptic curve points)}. Now, su=
ppose A and B exchange X:=3DxG(p) where p is the
 correct password and where Y:=3D y G(p'), where p' is any guess for p by B=
 (or just takes p&quot;:=3D1). Then A (the legitimate party holding passwor=
d p) computes Ka:=3D (xy) G(p')=3D (xy p') G and B computes Kb:=3D(yx) G(p)=
=3D (yxp) G. In other words, Ka:=3D p' K, Kb:=3D p K,
 where K:=3D (xy)G. So, Ka:=3D (p'/p) Kb. Now, once A sends B a key confirm=
ation message, B can just cycle through the password space, compute a candi=
date key that A could have computed and check the validity of his guess via=
 verification of the key confirmation
 message just received.<br>
<br>
As to implementing Dragonfly, one has to be careful in case of active attac=
ks: as an example, if one uses multiple-point multiplications, one may end =
up at the point of infinity as intermediate point in the computation, thus =
forcing implementations to use exception
 handling routines for point addition/doubling along the entire computation=
al path (Note: if one hits the point at infinity, this exposes the password=
 used, thus leaking the entire password in an observable way). If one does =
not use multiple-point multiplications,
 this attack seems much harder but requires two full scalar multiplications=
 (rather than one scalar multiplication as, e.g., SPEKE requires).<br>
<br>
Best regards, Rene<br>
<br>
=3D=3D<br>
A possible fix is to use the KDF to generate a random X, 1&lt;X&lt;q, where=
 q is the size of the cryptographic<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">subgroup of the cur=
ve, and take PE =3D X*G, where G is the generator of the cryptographic subg=
roup.&nbsp; For
<br>
most cryptographic curves,&nbsp; q&nbsp; is very, very close to 2^n, so it =
is VERY unlikely that more than 1 call to the
<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font-s=
ize:11.0pt">KDF will be needed.<br>
<br>
<o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal">On 12/13/2012 1:42 PM, Igoe, Kevin M. wrote:<o:p></o=
:p></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">I&#8217;d like the reading list&#8217;s=
 input on DragonFly (hereafter called DF), Dan Harkins&#8217; Password Auth=
enticated
<br>
Key Exchange design (draft-irtf-cfrg-dragonfly-00).&nbsp; I&#8217;d like to=
 point out that draft-harkins-tls-pwd-03
<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">is a proposal to use</span><span style=
=3D"font-size:10.0pt;font-family:&quot;Courier New&quot;">
</span><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quo=
t;sans-serif&quot;">DF in&nbsp; TLS that differs slightly from the CFRG dra=
ft.
<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">Here is where I believe we stand:<o:p><=
/o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0in;text-indent:-.25in;mso-list:l1 level1 lfo1">
<![if !supportLists]><span style=3D"font-size:11.0pt;font-family:&quot;Cali=
bri&quot;,&quot;sans-serif&quot;"><span style=3D"mso-list:Ignore">1.<span s=
tyle=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:11.0pt;font-family:=
&quot;Calibri&quot;,&quot;sans-serif&quot;">Confidentiality: The proof that=
 the confidentiality of the key generated by the DF<br>
protocol is reducible to the standard Diffie-Hellmann problem is quite stra=
ight <br>
forward, so the resulting shared secret value is at least as secure as with=
&nbsp; standard DH/ECDH.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0in;text-indent:-.25in;mso-list:l1 level1 lfo1">
<![if !supportLists]><span style=3D"font-size:11.0pt;font-family:&quot;Cali=
bri&quot;,&quot;sans-serif&quot;"><span style=3D"mso-list:Ignore">2.<span s=
tyle=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:11.0pt;font-family:=
&quot;Calibri&quot;,&quot;sans-serif&quot;">Authentication: Obviously the s=
ystem can be no more secure than the password
<br>
being used. I believe the most viable attack is to guess a password, use th=
is password
<br>
to initiate the&nbsp; DF protocol with the endpoint being attacked, and see=
 if it works.<br>
Monitoring the system logs should easily detect such an attack. <o:p></o:p>=
</span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0in;text-indent:-.25in;mso-list:l1 level1 lfo1">
<![if !supportLists]><span style=3D"font-size:11.0pt;font-family:&quot;Cali=
bri&quot;,&quot;sans-serif&quot;"><span style=3D"mso-list:Ignore">3.<span s=
tyle=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:11.0pt;font-family:=
&quot;Calibri&quot;,&quot;sans-serif&quot;">Timing: I&#8217;m particularly =
concerned about the method used to generate the PE (password
<br>
dependent base point) in the ECDH case. Inside a while loop, several parame=
ters,<br>
&nbsp;including the identities of the two endpoints, the shared password, a=
nd a counter are
<br>
passed to a KDF to produce an n-bit output, where the curve is mod an n-bit=
 prime p.
<br>
The resulting n-bit value X is checked to see if 0 &lt;=3D X &lt; p and X^3=
&#43;a*X&#43;b is a quadratic
<br>
residue mod p (an event of probability =BD).&nbsp; If both these tests are =
passed, the while
<br>
loop is exited and X is used as the x-coordinate of our PE. <br>
<br>
The problem I see with (3) is that the number of times through the loop giv=
es an opponent a
<br>
check&nbsp; on any putative value for the password.&nbsp; E.g.&nbsp; if the=
ir current guess for the password<br>
takes many passes through the while loop to generate the PE, but they obser=
ve that the DF response<br>
&nbsp;time is inconsistent with that, they have eliminated that guess for t=
he password.&nbsp;
<o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">When DF is applied to TLS in as describ=
ed in draft-harkins-tls-pwd-03, two nonces are used as
<br>
inputs to the KDF, which has two consequences:<o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0in;text-indent:-.25in;mso-list:l0 level1 lfo2">
<![if !supportLists]><span style=3D"font-size:11.0pt;font-family:&quot;Cali=
bri&quot;,&quot;sans-serif&quot;"><span style=3D"mso-list:Ignore">a.<span s=
tyle=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:11.0pt;font-family:=
&quot;Calibri&quot;,&quot;sans-serif&quot;">the PE MUST be computed online<=
o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:0in;text-indent:-.25in;mso-list:l0 level1 lfo2">
<![if !supportLists]><span style=3D"font-size:11.0pt;font-family:&quot;Cali=
bri&quot;,&quot;sans-serif&quot;"><span style=3D"mso-list:Ignore">b.<span s=
tyle=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;
</span></span></span><![endif]><span style=3D"font-size:11.0pt;font-family:=
&quot;Calibri&quot;,&quot;sans-serif&quot;">each DF exchange gives an indep=
endent timing check on the password.<o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">The opponent can passively sit back, mo=
nitoring the timing of DF exchanges on various links until
<br>
they stumble across one where the timings match up with the timings associa=
ted with one of the<br>
passwords they are testing. They&#8217;ve now are able to bypass the authen=
tication provided by DF.<br>
<br>
A possible fix is to use the KDF to generate a random X, 1&lt;X&lt;q, where=
 q is the size of the cryptographic<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">subgroup of the curve, and take PE =3D =
X*G, where G is the generator of the cryptographic subgroup.&nbsp; For
<br>
most cryptographic curves,&nbsp; q&nbsp; is very, very close to 2^n, so it =
is VERY unlikely that more than 1 call to the
<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">KDF will be needed.<o:p></o:p></span></=
p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">Another fix would be to require PE gene=
ration be done offline, which would eliminate any possibility of<br>
using nonces in the DF protocol.&nbsp; One could, however, mix the nonces i=
n after the completion to the<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">DF based Diffie-Hellmann exchange.&nbsp=
;
<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#333333">&nbsp;</span><span style=
=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;=
"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:#333333">----------------&#43;-----------------------=
---------------------------</span><span style=3D"font-size:11.0pt;font-fami=
ly:&quot;Calibri&quot;,&quot;sans-serif&quot;"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:#333333">Kevin M. Igoe&nbsp;&nbsp; | &quot;We can't s=
olve problems by using the same kind</span><span style=3D"font-size:11.0pt;=
font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"><o:p></o:p></span><=
/p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;"><a href=3D"mailto:kmigoe@nsa.gov"><span=
 style=3D"font-size:10.0pt;font-family:&quot;Courier New&quot;">kmigoe@nsa.=
gov</span></a></span><span style=3D"font-size:10.0pt;font-family:&quot;Cour=
ier New&quot;;color:#333333">&nbsp;
 | of thinking we used when we created them.&quot; </span><span style=3D"fo=
nt-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"><o:p=
></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:#333333">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; - Albert Einstein -</sp=
an><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sa=
ns-serif&quot;"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:#333333">----------------&#43;-----------------------=
---------------------------</span><span style=3D"font-size:11.0pt;font-fami=
ly:&quot;Calibri&quot;,&quot;sans-serif&quot;"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;">&nbsp;<o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<pre>_______________________________________________<o:p></o:p></pre>
<pre>Cfrg mailing list<o:p></o:p></pre>
<pre><a href=3D"mailto:Cfrg@irtf.org">Cfrg@irtf.org</a><o:p></o:p></pre>
<pre><a href=3D"http://www.irtf.org/mailman/listinfo/cfrg">http://www.irtf.=
org/mailman/listinfo/cfrg</a><o:p></o:p></pre>
</blockquote>
<p class=3D"MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<pre>-- <o:p></o:p></pre>
<pre>email: <a href=3D"mailto:rstruik.ext@gmail.com">rstruik.ext@gmail.com<=
/a> | Skype: rstruik<o:p></o:p></pre>
<pre>cell: &#43;1 (647) 867-5658 | US: &#43;1 (415) 690-7363<o:p></o:p></pr=
e>
</div>
</div>
</body>
</html>

--_000_3C4AAD4B5304AB44A6BA85173B4675CA4AE0C72DMSMRGH1UEA03cor_--
