Customer Relationship Management News for Industry Pros
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home CRM Systems Customer Service Sales & Marketing Contact Centers More Topics...
Network Security
Average Rating:
Rate this article:  
Chip Design Flaw Could Subvert Encryption Chip Design Flaw Could Subvert Encryption
By Richard Koman
November 21, 2007 8:22AM

Bookmark and Share
Following news that RSA's Adi Shamir said that a processor design flaw could lead to millions of PCs being attacked simultaneously, Andrew Storms, director of security operations for nCircle Network Security, downplayed the threat. The cryptographic attack that Adi Shamir postulated is "still in a theoretical stage," he said.
 


Adi Shamir, a leading expert on computer cryptography, has posited that a new security risk might be dawning as computer chips get more and more complex. Shamir is a professor at the Weizmann Institute of Science in Israel and is the "S" is RSA.

The New York Times reported recently that Shamir circulated a research note to colleagues hypothesizing that a subtle math error in advanced computer chips could be recognized and exploited in a way that would break public-key cryptography systems, including RSA security.

Shamir said that if an intelligence organization discovered such a flaw, security software on a computer with a compromised chip could be "trivially broken with a single chosen message." The attacker would send a "poisoned" encrypted message to a protected computer, he wrote. It would then be possible to compute the value of the secret key used by the targeted system Relevant Products/Services.

Trouble with Design Secrets

"Millions of PCs can be attacked simultaneously, without having to manipulate the operating environment of each one of them individually," Shamir wrote.

One problem, Shamir said, is that due to the top-secret nature of chip design, it would be impossible to verify that a manufacturer's chip was not flawed. "Even if we assume that Intel Relevant Products/Services had learned its lesson and meticulously verified the correctness of its multipliers," he said, "there are many smaller manufacturers of microprocessors who may be less careful with their design."

Andrew Storms, director of security operations for nCircle Network Security, emphasized that Shamir's work is hypothetical and intended for discussion among his peers.

"It's important to note that Shamir had not intended for his notes to be dispersed among large crowds," Storms wrote in an e-mail. "This was more of the case of him sending an interesting note among trusted colleagues." Times reporter John Markoff made the issue one for public discussion by reporting on it.

Still in a Theoretical Stage

"This is a hypothetical thought process at this time and if it hadn't come from Shamir, one of the co-inventors of RSA, then it would not be receiving so much attention," Storms said. "My guess is that Shamir is also reticent that this is now open to public discourse at this time."

The attack that Shamir postulated is "still in a theoretical stage," Storms said. This is why we have innovators like Shamir, who can help to invent a method to secure data Relevant Products/Services and years later discover potential flaws with that method, he added. Storms said that, for the time being, there is no imminent threat and the fact that Shamir has done this research provides awareness to microchip producers to ensure new products are free of potential problems.

Jean-Jacques Quisquater, a cryptographic researcher at Louvain University in Belgium was quoted by the Times as saying that the remarkable thing about Shamir's note is that "Adi Shamir is saying that RSA is potentially vulnerable."
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Mobile Enterprise Spotlight
Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?
 
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Sales & Marketing | Contact Centers | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.