PuTTY's deterministic ECDSA nonces for NIST P-521 are biased by nine bits, allowing private key recovery from 58 valid signatures (CVE-2024-31497).
Title resolution pending
1 Pith paper cite this work, alongside 16 external citations. Polarity classification is still indexing.
1
Pith paper citing it
16
external citations · OpenAlex
fields
cs.CR 1years
2025 1verdicts
ACCEPT 1representative citing papers
citing papers explorer
-
On the Security of SSH Client Signatures
PuTTY's deterministic ECDSA nonces for NIST P-521 are biased by nine bits, allowing private key recovery from 58 valid signatures (CVE-2024-31497).