AI & TechCybersecurityNewswireScienceTechnologyWhat's Buzzing

New RSA Breakthrough: Faster Attack Than Any Seen Before

▼ Summary

– Researchers have discovered a novel classical computing method to forge RSA signatures without factoring the key, challenging long-held cryptographic assumptions.
– This attack significantly reduces the computational resources required to break RSA security, making previously safe key sizes vulnerable to unacceptable levels of risk.
– While immediate practical threats are limited due to high resource requirements, the finding is considered a conceptual breakthrough by cryptography experts.
– The method brings the feasibility of breaking 1024-bit RSA keys into reach much sooner than estimated, while also degrading the security of 2048- and 4096-bit keys.
– Current industry standards require a minimum of 128 bits of security, which this new technique threatens to undermine across various RSA implementations.

Cryptographic researchers have unveiled a novel attack method that significantly lowers the security threshold for the RSA encryption standard. This discovery introduces a new paradigm in breaking RSA keys, moving beyond the traditional reliance on factoring large integers. While the immediate practical threat to widely deployed systems remains low, the theoretical implications are profound. The method demonstrates that valid digital signatures can be forged without first deriving the private key, a process previously believed to be computationally prohibitive for anything less than state-level resources.

The timeline for quantum computing rendering RSA obsolete has long been cited as a looming deadline, with estimates ranging from three to over twenty years. However, this new research highlights vulnerabilities within classical computing frameworks. It reveals that the mathematical assumptions underpinning RSA’s difficulty may not be as robust as previously thought. By reducing the computational effort required to compromise these keys by orders of magnitude, the study challenges the established benchmarks for cryptographic security.

A Conceptual Breakthrough

The reaction from the security community has been one of surprise, primarily because the technique bypasses the conventional route of key recovery. Signature forgery allows an attacker to generate valid signatures without ever cracking the underlying key structure. Karsten Nohl, head of innovation at Allurity and a recognized cryptography expert, emphasized the significance of this shift.

“If this result holds up under peer review, it would indeed be a conceptual break-through,” Nohl stated. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”

This distinction is critical. For decades, the consensus was that generating a valid signature required computing the private key through integer factorization. This new approach decouples those two processes, suggesting that the barrier to entry for attacking RSA is lower than the industry assumed.

Redefining Security Thresholds

Nadia Heninger, a professor at the University of California San Diego and the lead author of the study, provided context on how this changes the landscape for different key sizes. She explained the historical cost associated with breaking these standards.

“Cryptographers thought that the only way to compute valid RSA digital signatures was to first compute the private key by factoring, and then use the private key to compute the signatures. For 1024-bit RSA, this was thought to be very expensive, albeit probably doable if you have the computational resources of the large tech companies or the NSA,on the order of tens of millions of dollars of computation time for a single key. For 2048-bit RSA, it was thought to be totally out of reach.”

The new method drastically alters these calculations. It brings the compromise of 1024-bit RSA into a much more feasible timeframe, while also degrading the security of 2048-bit and 4096-bit keys to unacceptable levels. Current guidelines from major bodies, including the National Security Agency (NSA), the National Institute of Standards and Technology (NIST), and the European Union Agency for Network and Information Security, mandate a minimum security level of 128 bits. This standard requires operations to exceed $2^{128}$ complexity. The findings suggest that existing implementations may no longer meet these rigorous safety margins when subjected to this specific type of forgery attack.

(Source: Ars Technica)

Topics

rsa cryptography 95% signature forgery 90% classical computing attacks 85% cryptographic standards 80% quantum computing impact 75%
Show More