{"id":{"repo_id":"sask","oai_identifier":"oai:harvest.usask.ca:10388/13234"},"canonical_url":"https://search.dev.ndltd.org/etd/sask/oai:harvest.usask.ca:10388/13234","repository":{"repo_id":"sask","name":"University of Saskatchewan","base_url":"https://harvest.usask.ca/server/oai/request"},"display":{"title":"Large-scale analysis of the security of cryptographic keys","abstract":"Cryptographic algorithms are considered provably secure due to their strong mathematical foundation. Notwithstanding, real-life application of cryptographic algorithms and protocols continues to fail. These failures are frequently due to low entropy, faulty library implementation, and Application Programming Interface (API) misuse. Biases introduced during the generation process incorporate distinct bit patterns in RSA cryptographic keys allowing their attribution, thus endangering their advertised security. This thesis proposes a novel attribution approach to link cryptographic keys to their originating libraries based on moduli’s characteristics. We analyze over 6.5 million generated keys and show that only a few of these characteristics are enough to achieve a 75% accuracy in the attribution of individual keys to their originating library. Also, depending on the library, our approach is sensitive enough to pinpoint the corresponding major, minor, and build release information for several libraries with accuracy levels between 81% and 98%. We further explore the attribution of SSH keys collected from publicly facing IPv4 addresses proving that our approach differentiates individual libraries of RSA keys with a 95% accuracy.","abstract_html":"Cryptographic algorithms are considered provably secure due to their strong mathematical foundation. Notwithstanding, real-life application of cryptographic algorithms and protocols continues to fail. These failures are frequently due to low entropy, faulty library implementation, and Application Programming Interface (API) misuse. Biases introduced during the generation process incorporate distinct bit patterns in RSA cryptographic keys allowing their attribution, thus endangering their advertised security. This thesis proposes a novel attribution approach to link cryptographic keys to their originating libraries based on moduli’s characteristics. We analyze over 6.5 million generated keys and show that only a few of these characteristics are enough to achieve a 75% accuracy in the attribution of individual keys to their originating library. Also, depending on the library, our approach is sensitive enough to pinpoint the corresponding major, minor, and build release information for several libraries with accuracy levels between 81% and 98%. We further explore the attribution of SSH keys collected from publicly facing IPv4 addresses proving that our approach differentiates individual libraries of RSA keys with a 95% accuracy.","abstract_has_math":false,"creators":["Rivera Carranza, Ronald Ernesto"],"institution":"University of Saskatchewan","degree_name":"Master of Science (M.Sc.)","degree_level":"Masters","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Stakhanova, Natalia"],"committee_chairs":[],"committee_members":["Vassileva, Julita","Keil, Mark","Zhang, Chris"],"year":2021,"date_issued":"2021-01-27","date_published":"2021-01-27","updated_at":"2026-07-24T04:26:45Z","subjects":["Public-Key Cryptography","RSA","Cryptography","Attribution","Machine Learning"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10388/13234","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Stakhanova, Natalia"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Vassileva, Julita","Keil, Mark","Zhang, Chris"]},{"key":"dc:creator","label":"Author","values":["Rivera Carranza, Ronald Ernesto"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2021-01-27T17:40:06Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2021-01-27T17:40:06Z"]},{"key":"dc:date.issued","label":"Date","values":["2021-01-27"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Masters"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (M.Sc.)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Saskatchewan"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Public-Key Cryptography","RSA","Cryptography","Attribution","Machine Learning"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10388/13234"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Cryptographic algorithms are considered provably secure due to their strong mathematical foundation. Notwithstanding, real-life application of cryptographic algorithms and protocols continues to fail. These failures are frequently due to low entropy, faulty library implementation, and Application Programming Interface (API) misuse. Biases introduced during the generation process incorporate distinct bit patterns in RSA cryptographic keys allowing their attribution, thus endangering their advertised security. This thesis proposes a novel attribution approach to link cryptographic keys to their originating libraries based on moduli’s characteristics. We analyze over 6.5 million generated keys and show that only a few of these characteristics are enough to achieve a 75% accuracy in the attribution of individual keys to their originating library. Also, depending on the library, our approach is sensitive enough to pinpoint the corresponding major, minor, and build release information for several libraries with accuracy levels between 81% and 98%. We further explore the attribution of SSH keys collected from publicly facing IPv4 addresses proving that our approach differentiates individual libraries of RSA keys with a 95% accuracy."]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Large-scale analysis of the security of cryptographic keys"]}]}],"canonical_facts":{"dc:contributor.advisor":["Stakhanova, Natalia"],"dc:contributor.committeemember":["Vassileva, Julita","Keil, Mark","Zhang, Chris"],"dc:creator":["Rivera Carranza, Ronald Ernesto"],"dc:date.accessioned":["2021-01-27T17:40:06Z"],"dc:date.available":["2021-01-27T17:40:06Z"],"dc:date.issued":["2021-01-27"],"dc:description.abstract":["Cryptographic algorithms are considered provably secure due to their strong mathematical foundation. Notwithstanding, real-life application of cryptographic algorithms and protocols continues to fail. These failures are frequently due to low entropy, faulty library implementation, and Application Programming Interface (API) misuse. Biases introduced during the generation process incorporate distinct bit patterns in RSA cryptographic keys allowing their attribution, thus endangering their advertised security. This thesis proposes a novel attribution approach to link cryptographic keys to their originating libraries based on moduli’s characteristics. We analyze over 6.5 million generated keys and show that only a few of these characteristics are enough to achieve a 75% accuracy in the attribution of individual keys to their originating library. Also, depending on the library, our approach is sensitive enough to pinpoint the corresponding major, minor, and build release information for several libraries with accuracy levels between 81% and 98%. We further explore the attribution of SSH keys collected from publicly facing IPv4 addresses proving that our approach differentiates individual libraries of RSA keys with a 95% accuracy."],"dc:format.mimetype":["application/pdf"],"dc:identifier.uri":["https://hdl.handle.net/10388/13234"],"dc:subject":["Public-Key Cryptography","RSA","Cryptography","Attribution","Machine Learning"],"dc:title":["Large-scale analysis of the security of cryptographic keys"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Masters"],"thesis:degree_name":["Master of Science (M.Sc.)"],"thesis:institution_name":["University of Saskatchewan"]},"updated_at":"2026-07-24T04:26:45Z"}