Back to results

University of Saskatchewan

Large-scale analysis of the security of cryptographic keys

Abstract

dc:description.abstract

Cryptographic algorithms are considered provably secure due to their strong mathematical foundation. Notwithstanding, real-life application of cryptographic algorithms and protocols continues to fail. These failures are frequently due to low entropy, faulty library implementation, and Application Programming Interface (API) misuse. Biases introduced during the generation process incorporate distinct bit patterns in RSA cryptographic keys allowing their attribution, thus endangering their advertised security. This thesis proposes a novel attribution approach to link cryptographic keys to their originating libraries based on moduli’s characteristics. We analyze over 6.5 million generated keys and show that only a few of these characteristics are enough to achieve a 75% accuracy in the attribution of individual keys to their originating library. Also, depending on the library, our approach is sensitive enough to pinpoint the corresponding major, minor, and build release information for several libraries with accuracy levels between 81% and 98%. We further explore the attribution of SSH keys collected from publicly facing IPv4 addresses proving that our approach differentiates individual libraries of RSA keys with a 95% accuracy.

Degree

thesis:*
Name thesis:degree_name
Master of Science (M.Sc.)
Level thesis:degree_level
Masters
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Saskatchewan
Year dc:date.issued
2021

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Rivera Carranza, Ronald Ernesto
Advisor dc:contributor.advisor
  • Stakhanova, Natalia
Committee members dc:contributor.committeemember
  • Vassileva, Julita
  • Keil, Mark
  • Zhang, Chris

Subjects

dc:subject × 5

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10388/13234
OAI identifier oai:identifier
oai:harvest.usask.ca:10388/13234

Chain of custody

source
Harvested from
University of Saskatchewan
Base URL
harvest.usask.ca/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Rivera Carranza, Ronald Ernesto. Large-scale analysis of the security of cryptographic keys. Masters thesis, University of Saskatchewan, 2021. https://hdl.handle.net/10388/13234