Skip to main content

Ooh Aah Just a Little Bit.....

News Image

06 March 2014



More News...
A paper by Joop van de Pol and Nigel Smart, co-authored with colleagues from Australia, entitled ``Ooh Aah... Just a Little Bit'' : A small amount of side channel can go a long way shows that one can recover secret keys from the OpenSSL implementation of certain cryptographic systems with very little effort. 

The systems in particular studied in the paper relate to the elliptic curve used in the bitcoin protocol; but the method applies to all elliptic curve algorithms which use the OpenSSL library. By running attack code in parallel with the OpenSSL code, an attacker can 'spy' on the OpenSSL library and so recover secret keys.

The attack has been covered today in internet based media.