This paper studies the provable security of the deterministic random bit generator (DRBG) utilized in Linux 6.4.8, marking the first analysis of Linux-DRBG from a provable security perspective since its substantial structural changes in Linux 4 and Linux 5.17. Specifically, we prove its security up to \(O(\min \{2^{\frac{n}{2}},2^{\frac{\lambda }{2}}\})\) queries in the seedless robustness model, where n is the output size of the internal primitives and \(\lambda \) is the min-entropy of the entropy source. Our result implies 128-bit security given \(n=256\) and \(\lambda =256\) for Linux-DRBG. We also present two distinguishing attacks using \(O(2^{\frac{n}{2}})\) and \(O (2^{\frac{\lambda }{2}})\) queries, respectively, proving the tightness of our security bound.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Provable Security of Linux-DRBG in the Seedless Robustness Model

  • Woohyuk Chung,
  • Hwigyeom Kim,
  • Jooyoung Lee,
  • Yeongmin Lee

摘要

This paper studies the provable security of the deterministic random bit generator (DRBG) utilized in Linux 6.4.8, marking the first analysis of Linux-DRBG from a provable security perspective since its substantial structural changes in Linux 4 and Linux 5.17. Specifically, we prove its security up to \(O(\min \{2^{\frac{n}{2}},2^{\frac{\lambda }{2}}\})\) queries in the seedless robustness model, where n is the output size of the internal primitives and \(\lambda \) is the min-entropy of the entropy source. Our result implies 128-bit security given \(n=256\) and \(\lambda =256\) for Linux-DRBG. We also present two distinguishing attacks using \(O(2^{\frac{n}{2}})\) and \(O (2^{\frac{\lambda }{2}})\) queries, respectively, proving the tightness of our security bound.