Top 10 winner
Weaknesses in RC4
Measured the keystream biases of RC4 as used in TLS and turned them into plaintext recovery. A single-byte-bias attack over the first 256 keystream bytes recovers 220 bytes of a repeated plaintext from roughly 2^30 sessions, and a double-byte (Fluhrer-McGrew) attack works within one connection. The single-byte attack carries to WPA/TKIP because of its per-packet keys.
Record
- Researcher
- Nadhem AlFardan, Dan Bernstein, Kenny Paterson, Bertram Poettering and Jacob Schuldt
- Published by
- isg.rhul.ac.uk
In the archive
Related sources
- Supporting slides: RC4 biases
- Supporting slides: TKIP biases
- Original announcement slides
- Supporting dataset
- Full research paper
- USENIX slides
- Conference publication
Tags
This page is the archive's own catalogue record. The research is the work of Nadhem AlFardan, Dan Bernstein, Kenny Paterson, Bertram Poettering and Jacob Schuldt, first published at the original source. Preserved copies are kept so the citation survives its host.