PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 1, 201415 citations

The Fragility of AES-GCM Authentication Algorithm

View Full Paper
SGShay GueronVKVlad Krasnov

Key Points

Key points are not available for this paper at this time.

Abstract

A new implementation of the GHASH function has been recently committed to a Git version of Open SSL, to speed up AES-GCM. We identified a bug in that implementation, and made sure it was quickly fixed before trickling into an official Open SSL trunk. Here, we use this (already fixed) bug as a real example that demonstrates the fragility of AES-GCM's authentication algorithm (GHASH). One might expect that incorrect MAC tag generation would only cause legitimate message-tag pairs to fail authentication (which is already a serious problem). However, since GHASH is a "polynomial evaluation" MAC, the bug can be exploited for actual message forgery.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Gueron et al. (2014) studied this question.

synapsesocial.com/papers/6a2296dd26d06b648c0df30dhttps://doi.org/10.1109/itng.2014.31
Ask AI
Helpful
Bookmark
Share
View Full Paper