Top 10 winner
Weaknesses in RC4
On the Security of RC4 in TLS
Measured the keystream biases of RC4 as used in TLS and turned them into plaintext recovery. A single-byte-bias attack over the first 256 keystream bytes recovers 220 bytes of a repeated plaintext from roughly 2^30 sessions, and a double-byte (Fluhrer-McGrew) attack works within one connection. The single-byte attack carries to WPA/TKIP because of its per-packet keys.
Record
- Document
- On the Security of RC4 in TLS
- Researcher
- Nadhem AlFardan, Dan Bernstein, Kenny Paterson, Bertram Poettering and Jacob Schuldt
- Published by
- isg.rhul.ac.uk
- Topic
- Other
In the archive
Related sources
- RC4 single-byte bias distributions Whitepaper
- WPA/TKIP bias distributions Whitepaper
- Dan Bernstein’s FSE 2013 presentation Whitepaper
- RC4 keystream distributions
- On the Security of RC4 in TLS Whitepaper
- On the Security of RC4 in TLS Whitepaper
- On the Security of RC4 in TLS
Tags
This page is the archive's own catalogue record. The research is the work of Nadhem AlFardan, Dan Bernstein, Kenny Paterson, Bertram Poettering and Jacob Schuldt, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .