arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

规范化失败作为一类反复出现的漏洞:密码系统中的表示分歧及其规避

Canonicalization Failures as a Recurring Vulnerability Class: Representation Divergence in Cryptographic Systems and Its Avoidance

Arslan Brömme

arXiv 2608.06508首次发表:更新:

AI 中文总结

本研究系统化了密码系统中因表示分歧导致的反复出现的规范化失败漏洞,建立了相关理论基础并提出可预防性审查程序,以降低该类漏洞的可利用性。

AI 中文摘要

密码系统基于字节运行,但处理的是语义对象。两者之间的转换极少是唯一的。当这种唯一性未被强制时,一旦哈希、签名、重放保护或共识身份依赖于表示形式,就会出现攻击面。同一类故障已在多个生态系统中被独立发现并被分别命名为交易可塑性、非确定性值编码、消息可塑性或哈希链可塑性,却未被追踪为跨生态系统的共性问题。本研究系统整理了这些分散的发现:表明它们是同一被违反的唯一性条件的实例,分为两个基本方向:一个对象对应多个有效编码(对象侧多表示),或一个编码对应多个对象(代码侧语义崩溃)。本研究的贡献并非发现该现象,而是三重:按表示机制而非受影响系统进行系统化;在经典规范化安全性与表示及可计算性理论基础之间建立桥梁;转化为可应用的审查程序(含规范化义务、一系列审查步骤、领域类型分类及操作边界模型),以此可预防性识别风险。我们通过详细案例佐证该漏洞类,将其与非表示问题的事件区分开,并明确主张:强制唯一性可降低某类故障的可利用性,但既不能替代其他防护措施,也不对狭义的密码安全性作出任何断言。

英文摘要

Cryptographic systems operate on bytes but mean semantic objects. The translation between the two is rarely unique. Where this uniqueness is not enforced, an attack surface opens up as soon as a hash, a signature, replay protection, or consensus identity depends on the representation. The same class of failure has been discovered independently and named locally across many ecosystems, as transaction malleability, non-deterministic value encoding, message malleability, or hash chain malleability, without its common root being tracked as a cross-ecosystem grid. This work organizes the scattered findings systematically: it shows that they are instances of one violated uniqueness condition, along two basic directions: multiple valid codes for one object (object-side multiple representation) or one code for multiple objects (code-side semantic collapse). The contribution is explicitly not the discovery of the phenomenon, but is threefold: the systematization by representation mechanism rather than by affected system, the bridge between classical canonicalization security and a representation- and computability-theoretic foundation, and the translation into an applicable review procedure (a canonicalization obligation with a sequence of review steps, a field-type classification, and an operational boundary model) with which the risk can be recognized preventively. We substantiate the class with worked-out cases, delimit it against incidents that are not representation problems, and deliberately keep the claims to what is demonstrable: enforced uniqueness can reduce the exploitability of a failure class, but it neither replaces further protective measures or makes any statement about cryptographic security in the narrower sense

Comments33 pages, 1 figure, 4 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑