Skip to main content /TECH with IDG.net
CNN.com /TECH
CNN TV
EDITIONS

Cryptologist sees digital signature flaw, fix

Network World Fusion
image

(IDG) -- A scientist at Bell Labs, the research and development wing of Lucent, has discovered a flaw in the Digital Signature Algorithm that could have affected the integrity of secure transactions on the Internet and adversely impacted VPNs, online shopping and online financial transactions.

Daniel Bleichenbacher, a member of Bell Labs' Information Sciences Research Center, discovered a glitch in the random number generation technique used with the DSA, according to the company in a statement. He learned that the DSA's random number generator was biased and was twice as likely to pick a set of numbers from one range than from another.

MESSAGE BOARD
 

The U.S. National Security Agency designed DSA and it is one of three authentication algorithms approved for generating and verifying digital signature under the Digital Signature Standard. Digital signatures allow software at the end of an electronic transaction to confirm the identity of the party initiating the transaction and to verify the integrity of the information received.

The vulnerability does not pose any immediate threat as it takes massive computing power to launch an attack on the flaw, according to Bell Labs.

IDG.net INFOCENTER
IDG.net
Related IDG.net Stories

The Digital Signature Standard was developed by the U.S. National Institute of Standards and Technology (NIST) and has been adopted by the American National Standards Institute (ANSI) and the IEEE.

The standards organizations could develop a simple fix for DSA, which providers of applications and services could implement in software, according to Bleichenbacher. NIST has agreed to fix the weakness in the DSA and is now preparing a revision of the DSA specification, which will be proposed in February, said Edward Roback, chief of the computer security division in NIST's Information Technology Laboratory.

Bleichenbacher first disclosed the vulnerability on Nov. 15, 2000 during a meeting of an IEEE working group, which focused on standard specifications for public-key cryptography. He found the flaw while analyzing an appendix to the DSA and has since devised an alternation to the DSA algorithm that would, for all practical purposes, eliminate the bias in the random number generator, Bell Labs said.




RELATED STORIES:
Crossing the wireless security gap
January 3, 2001
DNS security upgrade promises a safer Net
October 17, 2000
RSA releases computer security patent
September 7, 2000
Security flaw discovered in Network Associates PGP software
August 28, 2000
VeriSign takes the pain out of digital certificates
January 17, 2000

RELATED IDG.net STORIES:
Researchers uncover 'major' wireless security flaws
(IDG.net)
The World Economic Forum's big hack attack
(The Industry Standard)
Official seeks e-commerce privacy seal of approval
(IDG.net)
Hackers hit WEF's servers in Davos
(IDG.net)
VMware, NSA working to protect classified data
(IDG.net)
BuqTraq members cited as source of DoS attack
(InfoWorld.com)
FleetBoston unveils virtual safe-deposit boxes
(PCWorld.com)
Report recommends overhaul of cyberdefenses
(Computerworld)

RELATED SITES:
Bell Labs
National Security Agency


Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.


 Search   





MARKETS
4:30pm ET, 4/16
144.70
8257.60
3.71
1394.72
10.90
879.91
 













Back to the top