节点文献

基于JSON的RSA-PKCS#1加密算法的安全性研究

The security analysis of RSA-PKCS#1 encryption algorithm in JSON

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 何建蒋琳廖清王轩

【Author】 He Jian;Jiang Lin;Liao Qing;Wang Xuan;School of Computer Science and Technology,Harbin Institute of Technology Shenzhen Graduate School;

【机构】 哈尔滨工业大学深圳研究生院计算机科学与技术学院

【摘要】 基于JSON的RSA-PKCS#1加密算法作为JSON的加密标准中首选的公钥加密算法,由于其要求明文在被加密前使用特定的填充规则对明文进行预处理操作,导致可被攻击者利用的选择密文攻击漏洞的产生,使得攻击者可以在未掌握RSA私钥的情况下破解密文。为此,本文从安全性角度分析基于JSON的RSA-PKCS#1加密算法以及选择密文攻击漏洞产生的成因,并根据分析结果构造攻击实验以证明其安全漏洞的存在,同时针对此漏洞提出基于固定值填充的加固方案,消除选择密文攻击的利用点,以提升加密算法的安全性。

【Abstract】 The RSA-PKCS#1 encryption algorithm in JSON is the first-choice encryption algorithm of the JSON encryption standard. But a chosen ciphertext attack against the algorithm is found because of bad padding process upon the plaintext before encrypted. Through this attack,attackers can crack the ciphertext without knowing the RSA private key. Therefore,this paper analyzes the security of the RSA-PKCS#1 encryption algorithm in JSON and the cause of the chosen ciphertext attack vulnerability. According to the analysis results,an attack experiment is constructed to prove the existence of the security vulnerability. At the same time,a strengthening scheme is proposed to avoid this vulnerability by returning fixed value instead of the plaintext.

【基金】 国家重点研发计划网络空间安全重点专项项目(2017YFB0802204)
  • 【文献出处】 信息技术与网络安全 ,Information Technology and Network Security , 编辑部邮箱 ,2018年01期
  • 【分类号】TP309
  • 【被引频次】1
  • 【下载频次】70
节点文献中: 

本文链接的文献网络图示:

本文的引文网络