Key facts
- Researchers forged RSA signatures on a 1,024-bit key inside a hardware security module.
- The attack required about 2^32 signing requests and 1,380 CPU core-years.
- Bitcoin and Ethereum use elliptic-curve signatures (ECDSA), not RSA.
- The attack likely poses no immediate threat to modern RSA deployments that use padding.
- The researchers disabled the hardware security module's FIPS mode to sign unformatted numbers.
Researchers from UC San Diego and France's INRIA have successfully forged RSA signatures using a hardware security module (HSM) without extracting the private key. The attack, detailed in a paper submitted to the IACR Cryptology ePrint Archive on September 20, targeted a 1,024-bit RSA key. HSMs are tamper-resistant devices commonly used by institutional custodians to safeguard private keys for digital assets.
The researchers were able to impersonate an HSM and generate valid signatures by sending approximately 4 billion signing requests to the device. This process required significant computational resources, estimated at 1,380 CPU core-years. To achieve this, they disabled the HSM's FIPS mode, a certified security setting, allowing it to sign unformatted numbers. The analogy used is that of a vault that stamps blank paper slid under its door; with enough attempts, one can learn to replicate the stamp.
However, the findings are unlikely to pose an immediate threat to most modern RSA deployments, which typically employ padding schemes like PKCS#1 v1.5 or PSS. These schemes scramble and format data before signing, preventing the creation of the exploitable 'oracle' that this attack leveraged. The paper's authors suggest the result serves as a stress test for key safeguarding methods and advocates for moving away from RSA in the context of post-quantum cryptography.
It is important to note that this attack specifically targets RSA cryptography. Major cryptocurrencies like Bitcoin and Ethereum utilize elliptic-curve digital signature algorithms (ECDSA) and Schnorr signatures, which are different cryptographic schemes. The paper's authors and experts have dismissed previous claims of RSA being broken, particularly those involving quantum computing methods on much smaller key sizes.
