Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwd

Dragonblood: анализ рукопожатия Dragonfly в WPA3 и EAP-pwd
Mathy Vanhoef, Eyal Ronen
2020-05-01

Dragonfly handshakeEAP-pwdWPA3hash-to-curveside-channel attacks
The WPA3 certification aims to secure home networks, while EAP-pwd is used by certain enterprise Wi-Fi networks to authenticate users. Both use the Dragonfly handshake to provide forward secrecy and resistance to dictionary attacks. In this paper, we systematically evaluate Dragonfly's security. First, we audit implementations, and present timing leaks and authentication bypasses in EAP-pwd and WPA3 daemons. We then study Dragonfly's design and discuss downgrade and denial-of-service attacks. Our next and main results are side-channel attacks against Dragonfly's password encoding method (e.g. hash-to-curve). We believe that these side-channel leaks are inherent to Dragonfly. For example, after our initial disclosure, patched software was still affected by a novel side-channel leak. We also analyze the complexity of using the leaked information to brute-force the password. For instance, brute-forcing a dictionary of size 1010requires less than $1 in Amazon EC2 instances. These results are also of general interest due to ongoing standardization efforts on Dragonfly as a TLS handshake, Password-Authenticated Key Exchanges (PAKEs), and hash-to-curve. Finally, we discuss backwards-compatible defenses, and propose protocol fixes that prevent attacks. Our work resulted in a new draft of the protocols incorporating our proposed design changes.
1
Dragonfly is vulnerable to downgrade and denial-of-service attacks arising from protocol design weaknesses.
2
Leaked side-channel information enables practical password recovery; brute-forcing a dictionary of size 10^10 costs less than $1 on Amazon EC2 instances.
3
Side-channel attacks against Dragonfly’s password encoding, including hash-to-curve, appear inherent and persisted after software patches.
4
The authors propose backwards-compatible defenses and protocol fixes, contributing to a new protocol draft incorporating these changes.
5
The study identifies timing leaks and authentication bypasses in implementations of EAP-pwd and WPA3 daemons.

The Dragonfly handshake as used in WPA3 and EAP-pwd, including its implementations and password-encoding process

Security vulnerabilities and attack resistance, particularly implementation leaks, downgrade and denial-of-service behavior, and side-channel leakage in password encoding and hash-to-curve

Publication Details
Publication Date
2020-05-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Mathy Vanhoef
Eyal Ronen
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%