0x3445a4613445…3445a45e

ConfirmedSecurity508 vB63 sat/vB3 min decode

Researchers Forge 1,024-bit RSA Signatures Inside a Hardware Security Module

UC San Diego and INRIA researchers forged 1,024-bit RSA signatures inside a hardware security module without extracting the key. The preprint shows limits of unpadded signing, not Bitcoin or Ethereum.

Outputs

  1. Researchers forged RSA signatures on a 1,024-bit key inside an HSM without extracting it, per a paper submitted to the IACR Cryptology ePrint Archive on September 20.

  2. The attack required approximately 2^32 (about 4 billion) signing requests and 1,380 CPU core-years of computation.

  3. Bitcoin and Ethereum use ECDSA, not RSA, and fall outside the paper's scope.

  4. The authors say the attack likely poses no immediate operational threat to modern RSA deployments that use PKCS#1 v1.5 or PSS padding.

  5. Google has set 2029 as the deadline for completing its internal migration to post-quantum cryptography.

Researchers at UC San Diego and France's INRIA forged RSA signatures on a 1,024-bit key inside a hardware security module without extracting it, per a paper submitted to the IACR Cryptology ePrint Archive on September 20.

The team disabled the HSM's FIPS-certified security mode so the device would sign unformatted numbers, then submitted approximately 2^32 (about 4 billion) chosen signing requests using a test key of their own. The combined computation required roughly 1,380 CPU core-years. The researchers did not factor the modulus; they exploited the device as a signing oracle.

What does this change for crypto custody?

The attack does not affect Bitcoin or Ethereum. Bitcoin transactions use ECDSA on the secp256k1 curve, with Schnorr signatures supported on the same curve. Ethereum uses the same scheme. The paper's claims cover RSA only, a different signature family created in 1977 by Ron Rivest, Leonard Adleman and Adi Shamir.

Who is actually exposed?

Standard RSA signing applies padding — such as PKCS#1 v1.5 or PSS — that runs before the exponentiation. The authors write that padded schemes do not create the exploitable oracle and that the attack "likely poses no immediate operational threat to most modern RSA deployments."

The exposure concentrates where unpadded RSA is in use, including systems that hand out the oracle on purpose. RSA-based blind signatures let a server sign a message without seeing it; one variant of Privacy Pass works this way. Cloudflare states that Apple deploys a Privacy Pass variant so users can prove they passed a CAPTCHA without revealing who they are. Cryptographer David Chaum used the same technique in 1989 when founding DigiCash.

The paper itself is a preprint. The authors frame their result as classical evidence supporting the shift away from RSA during the post-quantum migration.

Why does it matter to institutional custody?

Custodians such as BitGo rely on tamper-resistant HSMs precisely so private keys never exist outside the device. The UC San Diego / INRIA demonstration does not refute that property — the key never left the box — but it does show that the seal alone is insufficient when the signing mode permits unformatted input. Operational configuration, not just hardware boundaries, carries part of the trust model.

How does it fit the post-quantum timeline?

"RSA is broken" claims have a track record of overstating results. In January 2023, Chinese researchers published a quantum method said to threaten RSA; the demonstration factored a 48-bit number and was dismissed by specialists.

Caltech researchers estimated at the end of March that 10,000 to 20,000 qubits could be enough to run Shor's algorithm against elliptic-curve signatures. Google has set 2029 as the deadline for completing its own migration to post-quantum cryptography inside its product stack.

The forward-looking arc now runs through Google's 2029 internal milestone and the NIST post-quantum standards already finalized for key establishment and signature schemes, with HSM vendors facing renewed scrutiny over which padding and mode configurations ship enabled by default.

via bitgo.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles