Comum · História
Padding oracle attack
Attack which uses the padding validation of a cryptographic message to decrypt the ciphertext
In cryptography, a padding oracle attack is an attack which uses the padding validation of a cryptographic message to decrypt the ciphertext. In cryptography, variable-length plaintext messages often have to be padded (expanded) to be compatible with the underlying cryptographic primitive.
Na Wikipédia
Texto em inglês Ainda não há artigo no seu idioma: trecho em inglês.
In cryptography, a padding oracle attack is an attack which uses the padding validation of a cryptographic message to decrypt the ciphertext. In cryptography, variable-length plaintext messages often have to be padded (expanded) to be compatible with the underlying cryptographic primitive. The attack relies on having a "padding oracle" which freely responds to queries about whether a message is correctly padded or not. The information could be directly given, or leaked through a side-channel. The earliest well-known attack that uses a padding oracle is Bleichenbacher's attack of 1998, which attacks RSA with PKCS #1 v1.5 padding. The term "padding oracle" appeared in literature in 2002, after Serge Vaudenay's attack on the CBC mode decryption used within symmetric block ciphers. Variants of both attacks continue to find success more than one decade after their original publication.
Texto: Wikipédia em inglês, CC BY-SA 4.0. ·
Cartas próximas
-
O★
Optimal asymmetric encryption padding
Padding scheme often used together with RSA encryption; a form of Feistel network which uses a pair of random oracles to process the plaintext prior to asymmetric encryption; introduced by Bellare and Rogaway; standardized in PKCS#1 v2 and RFC 2437
-
P★
POODLE
Man-in-the-middle exploit taking advantage of fallback to SSL 3.0, disclosed on October 2014
-
A★★
Ataque de canal lateral
-
★
Ciphertext
Encrypted information
-
★★
Ciberataque
Ataque a uma rede de computadores
-
L★
Learning with errors
Problem in machine learning that is conjectured to be hard to solve. Introduced by Oded Regev in 2005, it is a generalization of the parity learning problem