Top Banner
ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT 2012
13

ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Dec 10, 2018

Download

Documents

dinhbao
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

ATTACKING BONEH ET AL.(WORK IN PROGRESS)

Peter Nordholt

Claudio Orlandi

Aarhus University, Denmark

RUMP SESSION ASIACRYPT 2012

Page 2: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Identification

Known identification schemes are vulnerable to so

called ”rubber hose” attacks

This is a knowledge

extractor!

Check Credentials

Page 3: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

New era for crypto?

Neuroscience tells us that your brain

knows things you don’t!

How to ride a bike…

How to play Guitar Hero…

Embed information in your motory skills!

But where??

Page 4: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Legs?

Bike: Not very effective for identification

(but participants lost weight!)

Page 5: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Fingers?

Guitar Hero

(test subjects did not want to stop identifying)

Page 6: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Full-Body Memory!

Page 7: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

The Boneh Crypto Challenge

How to make sure that this system is

secure to rubber hose attack?

”The BONEH Crypto Challenge”

Page 8: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Rules of the challenge

You can order a challenge on our homepage

(shipping fees might apply)

4 kind of challenges:

easy,

medium,

hard,

Impossible

Goal: ”extract” password from the challenge

Page 9: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Challenges – Easy (~40 bits security)

(...or other cryptographers

of equivalent weight class...)

Page 10: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Challenges – Medium (~80 bits security)

Page 11: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

Challenges – Hard (~160 bits security)

Page 12: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT
Page 13: ATTACKING BONEH ET AL. - International Association for ... · ATTACKING BONEH ET AL. (WORK IN PROGRESS) Peter Nordholt Claudio Orlandi Aarhus University, Denmark RUMP SESSION ASIACRYPT

THANK YOU!

• Disclaimer 1: No cryptographers (including Dan Boneh) wereharmed in the making of this presentation!

• Disclaimer 2: we are not responsible if you get hurt whiletrying to extract Chuck Norris’ password!