<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mocana DeviceLine Blog &#187; openssl</title>
	<atom:link href="http://mocana.com/blog/tag/openssl/feed/" rel="self" type="application/rss+xml" />
	<link>http://mocana.com/blog</link>
	<description>Security News for Embedded Device Designers</description>
	<lastBuildDate>Fri, 03 Sep 2010 02:40:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Serious Flaw Found in OpenSSL</title>
		<link>http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/</link>
		<comments>http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 02:48:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://mocana.com/blog/?p=1007</guid>
		<description><![CDATA[Computer scientists at the University of Michigan have found a way to uncover the secret cryptographic keys of devices secured with the OpenSSL crypto library. By modifying the current running through a device&#8217;s power supply as it processed encrypted data, researchers were able to extrapolate small bits of the device&#8217;s private crypto key. After repeated [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1008" title="pic1-38" src="http://mocana.com/blog/wp-content/uploads/pic1-38.jpg" alt="pic1-38" width="150" height="165" />Computer scientists at the University of Michigan have found a way to uncover the secret cryptographic keys of devices secured with the OpenSSL crypto library. By modifying the current running through a device&#8217;s power supply as it processed encrypted data, researchers were able to extrapolate small bits of the device&#8217;s private crypto key. After repeated interventions, they were successful in assembling the entire 1024-bit key.</p>
<p>According to a recent article on <a href="http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/">The Register,</a></p>
<blockquote><p>The attack is enabled by what the researchers described as a &#8220;severe vulnerability&#8221; in the OpenSSL innards that carry out authentication based on the RSA public key encryption algorithm. It resides in the so-called fixed window exponentiation algorithm of the open-source crypto library, which is used when errors arise. By triggering a single-bit error in a multiplication operation, the scientists were able to force OpenSSL to divulge 4 bits of the secret key.</p>
<p>Once they gathered about 8,800 malformed messages from the targeted device, they fed the data into an 81-machine cluster of 2.4 GHz Pentium-4 systems running a custom-designed algorithm&#8230;and were able to extract its 1024-bit private key in 104 hours.</p></blockquote>
<p>The Register reports that an OpenSSL representative has confirmed that a patch is currently in development.</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-mail">
			<a href="mailto:?subject=%22Serious%20Flaw%20Found%20in%20OpenSSL%22&amp;body=I+thought+this+article+might+interest+you.%0A%0A%22Computer%20scientists%20at%20the%20University%20of%20Michigan%20have%20found%20a%20way%20to%20uncover%20the%20secret%20cryptographic%20keys%20of%20devices%20secured%20with%20the%20OpenSSL%20crypto%20library.%20By%20modifying%20the%20current%20running%20through%20a%20device%27s%20power%20supply%20as%20it%20processed%20encrypted%20data%2C%20researchers%20were%20able%20to%20extrapolate%20small%20%22%0A%0AYou+can+read+the+full+article+here%3A%20http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/&amp;t=Serious+Flaw+Found+in+OpenSSL" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Serious+Flaw+Found+in+OpenSSL+-+File: /data/app/webapp/functions.php<br />Line: 7<br />Message: Too many connections+&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/&amp;title=Serious+Flaw+Found+in+OpenSSL&amp;summary=Computer%20scientists%20at%20the%20University%20of%20Michigan%20have%20found%20a%20way%20to%20uncover%20the%20secret%20cryptographic%20keys%20of%20devices%20secured%20with%20the%20OpenSSL%20crypto%20library.%20By%20modifying%20the%20current%20running%20through%20a%20device%27s%20power%20supply%20as%20it%20processed%20encrypted%20data%2C%20researchers%20were%20able%20to%20extrapolate%20small%20&amp;source=Mocana DeviceLine Blog" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="sexy-delicious">
			<a href="http://delicious.com/post?url=http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/&amp;title=Serious+Flaw+Found+in+OpenSSL" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/&amp;title=Serious+Flaw+Found+in+OpenSSL" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://mocana.com/blog/2010/03/08/serious-flaw-found-in-openssl/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hints from Mocana Engineering</title>
		<link>http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/</link>
		<comments>http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/#comments</comments>
		<pubDate>Sat, 08 Nov 2008 04:31:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[engineering]]></category>
		<category><![CDATA[Mocana]]></category>
		<category><![CDATA[nanossl]]></category>
		<category><![CDATA[openssl]]></category>

		<guid isPermaLink="false">http://mocana.com/blog/?p=56</guid>
		<description><![CDATA[Can I use OpenSSL certificate and keys with NanoSSL?
Yes. To convert an OpenSSL certificate to NanoSSL, simply convert the certificate from PEM to DER format by defining in your project __ENABLE_MOCANA_PEM_CONVERSION__; and then use the CA_MGMT_decodeCertificate() API to convert OpenSSL certificate to NanoSSL. To convert OpenSSL key to NanoSSL key, simply call: CA_MGMT_convertKeyDER() or CA_MGMT_convertKeyPEM() [...]]]></description>
			<content:encoded><![CDATA[<p><em>Can I use OpenSSL certificate and keys with NanoSSL?</em></p>
<p>Yes. To convert an OpenSSL certificate to NanoSSL, simply convert the certificate from PEM to DER format by defining in your project __ENABLE_MOCANA_PEM_CONVERSION__; and then use the CA_MGMT_decodeCertificate() API to convert OpenSSL certificate to NanoSSL. To convert OpenSSL key to NanoSSL key, simply call: CA_MGMT_convertKeyDER() or CA_MGMT_convertKeyPEM() depending whether your key is stored as DER or PEM file. Note: PEM files are base64 encoded DER files.</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-mail">
			<a href="mailto:?subject=%22Hints%20from%20Mocana%20Engineering%22&amp;body=I+thought+this+article+might+interest+you.%0A%0A%22Can%20I%20use%20OpenSSL%20certificate%20and%20keys%20with%20NanoSSL%3F%0D%0A%0D%0AYes.%20To%20convert%20an%20OpenSSL%20certificate%20to%20NanoSSL%2C%20simply%20convert%20the%20certificate%20from%20PEM%20to%20DER%20format%20by%20defining%20in%20your%20project%20__ENABLE_MOCANA_PEM_CONVERSION__%3B%20and%20then%20use%20the%20CA_MGMT_decodeCertificate%28%29%20API%20to%20convert%20OpenSSL%20certifica%22%0A%0AYou+can+read+the+full+article+here%3A%20http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/&amp;t=Hints+from+Mocana+Engineering" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Hints+from+Mocana+Engineering+-+http://b2l.me/snw4d+&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/&amp;title=Hints+from+Mocana+Engineering&amp;summary=Can%20I%20use%20OpenSSL%20certificate%20and%20keys%20with%20NanoSSL%3F%0D%0A%0D%0AYes.%20To%20convert%20an%20OpenSSL%20certificate%20to%20NanoSSL%2C%20simply%20convert%20the%20certificate%20from%20PEM%20to%20DER%20format%20by%20defining%20in%20your%20project%20__ENABLE_MOCANA_PEM_CONVERSION__%3B%20and%20then%20use%20the%20CA_MGMT_decodeCertificate%28%29%20API%20to%20convert%20OpenSSL%20certifica&amp;source=Mocana DeviceLine Blog" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="sexy-delicious">
			<a href="http://delicious.com/post?url=http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/&amp;title=Hints+from+Mocana+Engineering" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/&amp;title=Hints+from+Mocana+Engineering" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://mocana.com/blog/2008/11/07/hints-from-mocana-engineering-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
