3 ms·
Not totally an expert but the explanation of what a PKRNG is overly simplified. The problem with Dual EC is not that it is a PKRNG, but that some design choice
by LukaAl 11y ago
Not totally an expert but the explanation of what a PKRNG is overly simplified. The problem with Dual EC is not that it is a PKRNG, but that some design choice made allowed for allegedly planting a backdoor for agencies with enough computing power.
Basically one of the problem you are trying to solve with a CSPRNG is how you avoid to disclose the generator state with the random numbers. Obviously once the state is known it is easy to replay the sequence.
Since we don't like to reinvent the wheel overtime, a solution is leveraging known properties of hashing and encryption algorithms. The idea behind a PKRNG is to use a fairly simple state evolution function but then to encrypt the output with a known public key. Since a property of public key encryption is that you can't know the message if you don't know the private key, the state is safe for everybody except the owner of the key. If you then truncate the encrypted message and you choose the public key without computing the private key you get a very strong CSPRNG. To be more clear:
- There are procedure to generate a public key without generating the private key (but you should trust the person who generated the numbers).
- The encrypted message is truncated, so even if you still have the private key, you should guess the missing bit of the message to decode the state.
The problem with Dual EC is that the resulting encrypted message is not truncated enough (it is enough to protect against a casual attacker, not an organization with massive computing power like an intelligence agency). Plus doubt were casted on the procedure used to generate the public key, given that you were forced to use the one in the standard and not your own if you want to get certified.
- tptacek 11y agoThere's no reason to use a public key transform to generate random bits other than to leverage the fact that the tranform is trapdoored with a private key. They are otherwise cost-prohibitive. If you can point to a "good" PKRNG that sees any use, that would be an interesting way to rebut my argument.