Conference Proceedings

A systematic analysis of the Juniper Dual EC incident

S Checkoway, J Maskiewicz, C Garman, J Fried, S Cohney, M Green, N Heninger, RP Weinmann, E Rescorla, H Shacham

CCS '16: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security | Association for Computing Machinery | Published : 2016

Open access

Abstract

In December 2015, Juniper Networks announced multiple security vulnerabilities stemming from unauthorized code in ScreenOS, the operating system for their NetScreen VPN routers. The more sophisticated of these vulnerabilities was a passive VPN decryption capability, enabled by a change to one of the elliptic curve points used by the Dual EC pseudorandom number generator. In this paper, we describe the results of a full independent analysis of the ScreenOS randomness and VPN key establishment protocol subsystems, which we carried out in response to this incident. While Dual EC is known to be insecure against an attacker who can choose the elliptic curve parameters, Juniper had claimed in 2013..

View full abstract

University of Melbourne Researchers

Grants

Awarded by National Science Foundation


Awarded by Office of Naval Research