摘要
介绍了一种利用RSA加密标准PKCS#1编码格式的脆弱性实现的、对SSL V3.0的会话密钥(pre-master-secret)进行的选择密文攻击。文章首先说明攻击原理和攻击算法,接着描述对SSL V3.0攻击的实现,随后分析导致攻击成功的原因,最后做出结论。另外文章还给出防止这种攻击的方法。
: This article introduces an attack to the pre-master-secret of a session in SSL V3.0 which takes advantage of the vulnerability of RSA encryption standard PKCS#1 encoding.First,the principle and the algorithm are presented,second,the detail of the attack to SSL V3.0,then,the reason for the successful attack,and finally the conclusion.The solutions are also given.
出处
《计算机工程与应用》
CSCD
北大核心
2001年第16期63-64,共2页
Computer Engineering and Applications
关键词
SSL
V3.0
密文攻击
密钥
互联网
网络安全
: SSLV3.0,RSA,PKCS#1,encoding,Chosen-ciphertext attack,Pre-master-secret,Session,Integrity check