[12200] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Implementation guides for DH?

daemon@ATHENA.MIT.EDU (Jeroen C. van Gelderen)
Wed Jan 1 23:46:27 2003

Date: Wed, 1 Jan 2003 21:43:14 -0500
Cc: cryptography@wasabisystems.com
To: Adam Shostack <adam@homeport.org>
From: "Jeroen C. van Gelderen" <jeroen@vangelderen.org>
In-Reply-To: <20030101185342.GA3000@lightship.internal.homeport.org>

Adam,

This may be of use:

http://citeseer.nj.nec.com/anderson96minding.html

"Over the last year or two, a large number of attacks have been found 
by the authors and others on protocols based on the discrete logarithm 
problem, such as ElGamal signature and Diffie Hellman key exchange. 
These attacks depend on causing variables to assume values whose 
discrete logarithms can be calculated, whether by forcing a protocol 
exchange into a smooth subgroup or by choosing degenerate values 
directly. We survey these attacks and discuss how to build systems that 
are robust against..."

@inproceedings{ anderson96minding,
     author = "Anderson and Vaudenay",
     title = "Minding Your p's and q's",
     booktitle = "{ASIACRYPT}: Advances in Cryptology -- {ASIACRYPT}: 
International Conference on the Theory and Application of Cryptology",
     publisher = "LNCS, Springer-Verlag",
     year = "1996",
     url = "citeseer.nj.nec.com/anderson96minding.html" }

Cheers,
-J

On Wednesday, Jan 1, 2003, at 13:53 US/Eastern, Adam Shostack wrote:

> I'm looking for a list of common implementation flaws in DH.  Things
> like: How to check the key the other side sends, what are acceptable
> values for p, etc?
>
> Any pointers?
>
> Adam
>
>
> -- 
> "It is seldom that liberty of any kind is lost all at once."
> 					               -Hume
>
>
>
> ---------------------------------------------------------------------
> The Cryptography Mailing List
> Unsubscribe by sending "unsubscribe cryptography" to 
> majordomo@wasabisystems.com


---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@wasabisystems.com

home help back first fref pref prev next nref lref last post