Invention Grant
- Patent Title: Avoiding padding oracle attacks
- Patent Title (中): 避免填补oracle攻击
-
Application No.: US13782191Application Date: 2013-03-01
-
Publication No.: US08745389B2Publication Date: 2014-06-03
- Inventor: John Clay Richard Wray , Peter James Argue , Krithika Prakash
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L9/32
- IPC: H04L9/32

Abstract:
A method to prevent information leakage in a cryptographic protocol is implemented in a network device. The method implements an error message processing strategy to mask information otherwise useful to an attacker and that has been generated (by decryption processes) as a consequence of an attacker's exploit. The technique avoids information leakage associated with a padding oracle attack. In one aspect each error message (irrespective of its content) is replaced with a generic error message so that the attacker does not obtain the specific error message content(s) that might otherwise provide useful information. In addition to masking the error message content, the technique preferably implements a “delay” policy that delays the transmission of particular error messages (or message types) to hide (from the attacker's point-of-view) whether a particular error message is relevant to (or a consequence of) the attacker's exploit.
Public/Granted literature
- US20130343539A1 Avoiding padding oracle attacks Public/Granted day:2013-12-26
Information query