Re: [Cfrg] Reference for hash substitution attack against RSASSA-PSS and its mitigation

"Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk> Sun, 04 June 2017 19:28 UTC

Return-Path: <Kenny.Paterson@rhul.ac.uk>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C37F129C6F for <cfrg@ietfa.amsl.com>; Sun, 4 Jun 2017 12:28:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.021
X-Spam-Level:
X-Spam-Status: No, score=-0.021 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=rhul.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GAK_XWGohJkf for <cfrg@ietfa.amsl.com>; Sun, 4 Jun 2017 12:28:45 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0076.outbound.protection.outlook.com [104.47.2.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D1261129C6C for <cfrg@irtf.org>; Sun, 4 Jun 2017 12:28:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rhul.onmicrosoft.com; s=selector1-rhul-ac-uk; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=pdzyZD3wKeElmMMQI4CIm2xrgP299nTLBWXqHSmEuls=; b=3S0Qb6tKMunGJKIyFit/CiO/OR97WUnVulDGc+3iVUD9PcxzNe+9CqJtdZkz4+HLYVASs8XR72FwekCM13pDU+cnYlk5j3ic9Q71DTtns+hnkRIOdYAYZKKZW7ZNGBkRgPWMxF+XwDq6vueaNWJqZoHdqsUCbPexu+ff+a3qVcw=
Received: from AM4PR0301MB1906.eurprd03.prod.outlook.com (10.168.2.156) by AM4PR0301MB1906.eurprd03.prod.outlook.com (10.168.2.156) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1143.10; Sun, 4 Jun 2017 19:28:42 +0000
Received: from AM4PR0301MB1906.eurprd03.prod.outlook.com ([fe80::9dfc:6390:892b:6c59]) by AM4PR0301MB1906.eurprd03.prod.outlook.com ([fe80::9dfc:6390:892b:6c59%14]) with mapi id 15.01.1143.016; Sun, 4 Jun 2017 19:28:42 +0000
From: "Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk>
To: Mike Jones <Michael.Jones@microsoft.com>, "cfrg@irtf.org" <cfrg@irtf.org>
CC: Steve KENT <steve.kent@raytheon.com>
Thread-Topic: [Cfrg] Reference for hash substitution attack against RSASSA-PSS and its mitigation
Thread-Index: AQHS3WjG4Nl2YzYgAEC1Bs76jiQZZA==
Date: Sun, 04 Jun 2017 19:28:41 +0000
Message-ID: <D55A1D7D.94F54%kenny.paterson@rhul.ac.uk>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.7.1.161129
authentication-results: microsoft.com; dkim=none (message not signed) header.d=none;microsoft.com; dmarc=none action=none header.from=rhul.ac.uk;
x-originating-ip: [78.146.52.40]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; AM4PR0301MB1906; 7:docoeYCpAI/5jXydQunHIFZ7awH0V4U6XnprV3ik101TMJWYymPtSBGSHbkJ+O8vBIDABlfA1dfBezldut86TGL9tIYU/wDowVx/s3AzapyvcrQB8Rc7Dcyo7sM0czvQQrbGBigx24uYd6KUv95inWkZSeKgZCeQ94+6UHyCo8u6MggvSMDA0LA8rM1AVBh6yiEOHsfXkvwLUyvptjbYsiQcZtPcHqgojRFGAJGQvqWrLQDj61egQU99U01xPtEMaAZcngHzqn4ucS+vIblUbAPbGtFHX8Qc0ejiBYTlsLfzqpSbm7DIyknXmTVP4rR8z2bUK54TqR6d2EDS0SgXMg==
x-forefront-antispam-report: SFV:SKI; SCL:-1SFV:NSPM; SFS:(10009020)(6009001)(39410400002)(39400400002)(39850400002)(39840400002)(39450400003)(24454002)(25786009)(478600001)(6506006)(5660300001)(72206003)(6486002)(1511001)(229853002)(53936002)(2900100001)(66066001)(189998001)(6512007)(4001350100001)(99286003)(86362001)(8666007)(36756003)(305945005)(50986999)(54356999)(6246003)(38730400002)(74482002)(5250100002)(8936002)(6436002)(7736002)(53546009)(3280700002)(8676002)(3660700001)(2906002)(3846002)(81166006)(83506001)(6116002)(42882006)(2501003)(4326008)(102836003); DIR:OUT; SFP:1101; SCL:1; SRVR:AM4PR0301MB1906; H:AM4PR0301MB1906.eurprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
x-ms-traffictypediagnostic: AM4PR0301MB1906:
x-ms-office365-filtering-correlation-id: ce48df5a-7a17-476b-b819-08d4ab7fe8c5
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075)(201703131423075)(201703031133081)(201702281549075); SRVR:AM4PR0301MB1906;
x-microsoft-antispam-prvs: <AM4PR0301MB19062329335FBDF5CEA4ED3FBCF50@AM4PR0301MB1906.eurprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(601004)(2401047)(8121501046)(5005006)(3002001)(93006095)(93001095)(10201501046)(100000703101)(100105400095)(6041248)(20161123560025)(20161123555025)(20161123558100)(20161123562025)(20161123564025)(201703131423075)(201702281529075)(201702281528075)(201703061421075)(201703061406153)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:AM4PR0301MB1906; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:AM4PR0301MB1906;
x-forefront-prvs: 03283976A6
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <591DEDECFD86BD46A2711557311E3A49@eurprd03.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: rhul.ac.uk
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Jun 2017 19:28:41.9925 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2efd699a-1922-4e69-b601-108008d28a2e
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR0301MB1906
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/_4K6mB8rESts_HOIlcVl5pjcvq0>
Subject: Re: [Cfrg] Reference for hash substitution attack against RSASSA-PSS and its mitigation
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Jun 2017 19:28:47 -0000

Hi Mike,

I'm not sure what attacks you're referring to here, so could you briefly
summarise them for me? That might help me and others figure out if there's
a suitable research paper to point you towards.

Thanks,

Kenny 

On 02/06/2017 21:06, "Cfrg on behalf of Mike Jones" <cfrg-bounces@irtf.org
on behalf of Michael.Jones@microsoft.com> wrote:

>Is there a paper that describes the theoretical hash substitution attacks
>against RSASSA-PSS and how they are mitigated?
> 
>                                                                Thanks,
>                                                                -- Mike
> 
>