[openpgp] Mining protection in fingerprint schemes

Bryan Ford <brynosaurus@gmail.com> Wed, 06 April 2016 20:00 UTC

Return-Path: <brynosaurus@gmail.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8094C12D622 for <openpgp@ietfa.amsl.com>; Wed, 6 Apr 2016 13:00:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id n9bIGHt7hzX2 for <openpgp@ietfa.amsl.com>; Wed, 6 Apr 2016 13:00:11 -0700 (PDT)
Received: from mail-qg0-x232.google.com (mail-qg0-x232.google.com [IPv6:2607:f8b0:400d:c04::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8E0212D608 for <openpgp@ietf.org>; Wed, 6 Apr 2016 13:00:10 -0700 (PDT)
Received: by mail-qg0-x232.google.com with SMTP id j35so45593164qge.0 for <openpgp@ietf.org>; Wed, 06 Apr 2016 13:00:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:subject:date:message-id:to:mime-version; bh=dFgxTimLFzoMlhqSiAL9/HhO3S0b/O2ri7x/cORyNI4=; b=avK7iiI9kV1jeG64hx0R4QK0XMscUls889urfHHVnyjf0Uz+lTR9EwGHhMwXd8xLcC rnO+autspbX/noeLXSe4gXzBTbVEbCahivAuVZfDmsxZkUZl+Z3lNiYMfs2LdNlXKCoL WI7K/+L+YAHU61Ehtww8a9lMSJ99K7Jl5hdO5mmWEqmOwf5J0J0q6knaaCfHZgYJc+gv T0XMR8Yuc9L0QvXAluBsGmnXrFyIge6mnU6VFtdP/F3dPfiDchpPjjnOMGVAoV6/6ANB QAtzyjFe0RRiWq5W1dfpvk/IK+QI8nMJHFIWONFs0SVskdHM1PO9bovVzTd7saJyYTfU EDWQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:subject:date:message-id:to:mime-version; bh=dFgxTimLFzoMlhqSiAL9/HhO3S0b/O2ri7x/cORyNI4=; b=YRfpTSTMz9dG7/TUW5ZVGeKi9DXlM1A0FxhzyX1LkHcMFUdMEr3uK8fjLIC8mAPqPF ueg20bCXZacgjYYtfrtcHNAB8Nim1CFYcz62gBtfbb+cr3bHTgc7u4FlO+MKcxkx8GiM tVxGWUq9irkmVlMMx4v9xIPL1M4I6F9fslCkFM9HOZqpS5yMBtOUHdU0tE3Sg5enmUcD lpXjRyLF8qACOTzxlH58PQeBC0izZGe/zVOzhODivhIapQcJPdDW5jrNaS6R40EH9Mlf z/HcIvQeawz186z1OS0xNQEJklRE3Q6tgzWYwv0YfPa4y4k4ursr1DCdTzt9iu0W/BM5 YcAA==
X-Gm-Message-State: AD7BkJJTW192a1PIof2a6CmJKI0d+ww5TLCnWujHD9EuJvujw3eECZEJlu3BrmaJ/i/5Cw==
X-Received: by 10.140.30.8 with SMTP id c8mr55234005qgc.67.1459972809942; Wed, 06 Apr 2016 13:00:09 -0700 (PDT)
Received: from [192.168.1.9] ([186.60.153.174]) by smtp.gmail.com with ESMTPSA id u102sm1942443qge.27.2016.04.06.13.00.07 for <openpgp@ietf.org> (version=TLSv1/SSLv3 cipher=OTHER); Wed, 06 Apr 2016 13:00:08 -0700 (PDT)
From: Bryan Ford <brynosaurus@gmail.com>
X-Pgp-Agent: GPGMail 2.6b2
Content-Type: multipart/signed; boundary="Apple-Mail=_A90096DD-D03D-4068-851E-0B41E3249003"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Date: Wed, 06 Apr 2016 17:00:04 -0300
Message-Id: <4C08CDDD-4C06-41AD-9797-7DD6F08ECD06@gmail.com>
To: openpgp@ietf.org
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
X-Mailer: Apple Mail (2.3124)
Archived-At: <http://mailarchive.ietf.org/arch/msg/openpgp/w-WTcu-RL4SgXJw0K51FtWFqUJ0>
Subject: [openpgp] Mining protection in fingerprint schemes
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Apr 2016 20:00:13 -0000

Sorry for the mailing list bomb, but I wanted to get a few more thoughts on the list while they’re still fresh.  Moving back to the question of what the “fingerprint scheme” itself might look like (the function that takes an octet-string and produces an ASCII-string), which may not really be OpenPGP-specific…

One of the potential goals that’s been discussed is to give users some form of “fingerprint-mining protection”, or defense against attackers mining for keys with similar-looking fingerprints.  This could potentially be provided either by playing with “what gets fingerprinted” (the topic of the E-mail I just posted), or by playing with the fingerprint scheme itself (the topic of this E-mail).

Here’s one specific idea for a fingerprint scheme with configurable mining protection, which builds on ideas suggested earlier by Christian Huitema and Phillip Hallam-Baker and others:

* Key creation:  OpenPGP implementation first picks a hardness parameter H determining level of mining protection. Implementations could provide a reasonable default for this, while allowing power-users to tweak it if they want.  Iterate the following loop until successful:

	1. Generate a public/private key-pair.  Call this public-key K.
	2. Take a hash of K and some domain-separation context string, yielding a “nonce” N.
	3. Use nonce N as the nonce input in an Argon2 proof-of-work, using otherwise fixed, “reasonable” Argon2 configuration parameters.
	3. Compute a SHA-512 hash based on K and this Argon2 proof-of-work; this is the “pre-fingerprint”.
	4. Unless the resulting pre-fingerprint has exactly H leading bits/bytes, go back to step 1, retrying with a fresh keypair.
	5. Form the fingerprint to present to the user as a one-digit encoding of H followed by an encoding of the last 256 bits of the pre-fingerprint.

* Fingerprint verification/recomputation on PGP key import: take public-key K, hash it as above, compute Argon2 nonce N, run a single Argon2 PoW round, verify the resulting SHA-512 against the proposed fingerprint.  Compute correct resulting fingerprint based on the number of leading zero-bits found in the hash and the last 256 bits of the SHA512 output.

The potentially beneficial properties of this approach are:

- Once the public/private key pair is created, the fingerprint depends on the public key and nothing else: i.e., it is “key-canonical”, as per the preference DKG expressed, keeping things simple.

- Users (and OpenPGP implementations) can configure the hardness parameter, in particular gradually increasing it over time, so that the difficulty of fingerprint-mining attacks for newly-created keys can keep pace with the increasing computational abilities of attackers.  Average users shouldn’t necessarily be expected to see or be aware of this at all; they just get keys with stronger fingerprints when they use newer software/machines to generate them.

- The use of an Argon2 PoW step in the “inner loop” makes it more difficult for attackers to do fingerprint-mining just by being very good at computing SHAs - e.g., as PHB mentioned, by using a big bank of GPUs or a bunch of repurposed Bitcoin mining hardware.  We don’t want to make all fingerprint-verifiers solve a “big” Argon2 PoW (because the receiver might be a smartphone with limited memory for example), but even just including a small/moderate Argon2 PoW in the key-creation mining loop might reduce a typical attacker’s advantage considerably.

Just as an aside, this hybrid between Argon2 and Bitcoin-style mining is really just kind of a “poor-man’s” solution to what we really want, which is an easily-verifiable “slow hash” as Arjen Lenstra’s group proposed in this paper: https://eprint.iacr.org/2015/366 <https://eprint.iacr.org/2015/366>

Cheers
Bryan