Christmas is coming soon! To thank for the support from all our dear customers, Christmas promotional activity is going on in JavaCardOS online store. For more activities details, please check this post.

Cryptographic research results on GP SCP Protocols

Algorithm School

Moderator: UNKNwYSHSA

tay00000
Posts: 125
Joined: Tue Sep 27, 2016 10:58 am
Points :1612
Contact:

Cryptographic research results on GP SCP Protocols

Post by tay00000 » Tue Jan 17, 2017 11:13 pm

Cryptographers have posted a paper on their recent attempts to attack the GlobalPlatform Secure Channel Protocol suite.

The research paper concludes that SCP02 is getting weak and SCP03 protocol is pretty strong and resist attempts to attack the protocol and provides resilience against attempts for possible backdoors if used correctly.

You may view the research paper here (https://eprint.iacr.org/2017/032).

For anyone using SCP protocol for security, please start to migrate away from the weakened SCP02 (and consider it as legacy protocol) and favour the newer SCP03 protocol which have been proven in the research paper to be secure.

On top of that, I have sent an email to Feitian personally to request them to add support for SCP03 whenever possible in their products.

Have fun reading the paper :) .

User avatar
UNKNwYSHSA
Posts: 630
Joined: Thu May 21, 2015 4:05 am
Points :3027
Contact:

Re: Cryptographic research results on GP SCP Protocols

Post by UNKNwYSHSA » Tue Jan 17, 2017 11:27 pm

Thank you for share this.
sense and simplicity

tay00000
Posts: 125
Joined: Tue Sep 27, 2016 10:58 am
Points :1612
Contact:

Re: Cryptographic research results on GP SCP Protocols

Post by tay00000 » Tue Jan 17, 2017 11:58 pm

Do note that the paper stresses on the importance of nonce and IV being random when needed instead of hard-coded IVs and nonces that are always re-used and never permutated.

Post Reply Previous topicNext topic

Who is online

Users browsing this forum: Google [Bot] and 2 guests

JavaCard OS : Disclaimer