Practical state recovery attacks against legacy RNG implementations

Shaanan N Cohney, Matthew D Green, Nadia Heninger

Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security | ASSOC COMPUTING MACHINERY | Published : 2018


We thank David McGrew and Dario Ciccarone for helpful discussions and research into Cisco's product lines, and Steve Checkoway for reverse-engineering the Juniper ScreenOS implementation of the X9.31 PRG. This work was supported by the National Science Foundation under grants CNS-1651344, CNS-1505799, CNS-1408734, CNS-1010928, CNS-1228443, and EFMA-1441209; The Office of Naval Research under contract N00014-14-1-0333; the Mozilla Foundation; and a gift from Cisco. We are grateful to Cisco for donating the Cisco UCS servers we used for the computational experiments.