Conference Proceedings
A systematic analysis of the Juniper Dual EC incident
S Checkoway, J Maskiewicz, C Garman, J Fried, S Cohney, M Green, N Heninger, RP Weinmann, E Rescorla, H Shacham
CCS '16: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security | Association for Computing Machinery | Published : 2016
Open access
Abstract
In December 2015, Juniper Networks announced multiple security vulnerabilities stemming from unauthorized code in ScreenOS, the operating system for their NetScreen VPN routers. The more sophisticated of these vulnerabilities was a passive VPN decryption capability, enabled by a change to one of the elliptic curve points used by the Dual EC pseudorandom number generator. In this paper, we describe the results of a full independent analysis of the ScreenOS randomness and VPN key establishment protocol subsystems, which we carried out in response to this incident. While Dual EC is known to be insecure against an attacker who can choose the elliptic curve parameters, Juniper had claimed in 2013..
View full abstractGrants
Awarded by National Science Foundation
Awarded by Office of Naval Research