메뉴
BL
Ars Technica • 58일 전

앤스로픽 AI, 수년간 미지의 암호화 취약점 발견

IMP
8/10
핵심 요약

앤스로픽의 '미토스(Mythos)' AI 보안 모델이 미국 차세대 표준으로 검토 중이던 양자 내성 암호 알고리즘인 HAWK의 취약점을 발견해 결국 철회하게 만들었습니다. 또한 널리 쓰이는 AES 암호 체계의 약화된 테스트 버전에서도 공격 효율성을 높이는 방법을 찾아내며, AI가 보안 및 개인정보 보호의 핵심인 암호 해독 분야에서 강력한 분석 도구로서의 잠재력을 입증했습니다.

번역된 본문

텍스트 설정 스토리 텍스트 크기 작게 표준 크게 너비 * 표준 넓게 링크 표준 주황색 * 구독자 전용 더 알아보기 내비게이션으로 최소화

미국 공식 표준으로 검토되던 양자 내성 암호화 알고리즘이 앤스로픽(Anthropic)의 보안 모델이 치명적인 결함을 발견하면서 결국 테스트에서 탈락했다. HAWK로 불리는 이 알고리즘은 미래의 양자 컴퓨터 공격에도 견딜 수 있도록 설계된 디지털 서명 방식이다. HAWK는 PQC(양자 내성 암호) 알고리즘의 보안을 평가하기 위해 미국 국립표준기술연구소(NIST)가 진행한 광범위한 1, 2차 테스트를 통과했다. HAWK는 바로 미토스(Mythos)가 도운 발견의 종류를 잡아내기 위해 설계된 3차 테스트에 머물고 있었다. 앤스로픽의 월요일 결과 발표에 이어 HAWK의 개발자는 화요일에 이를 철회한다고 밝혔다.

이번 발표 이전부터 앤스로픽은 미토스(Mythos) AI 보안 모델에 두 가지 암호학적 문제를 던져 얻은 결과에 찬사를 보냈다. 이 모델은 HAWK의 기반이 되는 수학적 문제와 개별적으로 널리 사용되는 AES 암호에서 취약점을 발견했다. HAWK가 철회되었음에도 불구하고 회사의 보고서가 마케팅 과장인지는 알기 어렵지만, 이번 발견은 개인정보 보호와 보안에 필수적인 암호 해독 분야에서 중요한 진전을 알리는 신호일 수 있으므로 여전히 주목할 가치가 있다.

결과를 파고들기 전에 몇 가지 유의사항이 있다. 첫째, 이번 결과는 점진적이다. 오늘날 우리가 의존하는 어떠한 암호 시스템도 완전히 파괴하지 않는다. 대신 시스템을 공격하는 데 필요한 작업량을 적당히 줄이는 방법을 보여줄 뿐이다. 둘째, 테스트된 암호 시스템은 공식 사양에 정의된 것보다 약화된 버전이었다. 이러한 '챌린지 인스턴스'는 적대적 동료 평가(adversarial peer review)를 위해 사양 작성자가 제공한다. 테스트에 약화된 버전을 사용하는 것은 표준적이지만, 실제 프로덕션 환경에서 사용되는 진짜 버전은 훨씬 더 강력하다. 셋째, 개선이 이루어졌음에도 불구하고 기반이 되는 '원시 자료(primitives)', 즉 암호 시스템의 기본 빌딩 블록을 형성하는 수학적 문제는 적어도 현재로서는 안전하다. 마지막으로, 두 공격 모두 테스트 환경 밖에서는 실행 불가능할 가능성이 높은 방법을 사용한다.

HAWK의 종말 앤스로픽은 현재 소수의 신뢰할 수 있는 사용자에게만 제공되는 미토스 모델이 두 가지 암호 시스템에 대한 공격을 발전시킬 수 있었다고 밝혔다. 첫 번째 시스템은 미래의 양자 컴퓨터 공격을 견디도록 설계된 디지털 서명 방식인 HAWK이다. 암호학 전문 지식이 없는 앤스로픽 연구원은 약 60시간의 작업과 약 10만 달러의 컴퓨팅 비용을 들여 미토스에게 프롬프트를 주어 알고리즘의 키 강도를 사실상 절반으로 줄이는 데 사용되는 기존 최고의 공격을 개선했다.

HAWK의 보안이 의존하는 수학은 '격자 동형 문제(Lattice Isomorphism Problem)'의 난해함이며, 이는 오늘날 가장 많이 사용되는 디지털 서명 방식과 달리 양자 컴퓨팅 공격으로부터 안전한 것으로 여겨진다. 이 문제를 해결하기 위해 가장 잘 알려진 고전적인 컴퓨팅 공격은 '자기동형 대칭(Automorphism symmetries)'이라고 불리는 것을 찾는 방식으로 작동한다. 미토스는 이러한 대칭을 찾는 이전에 알려지지 않은 방법을 출력했으며, 이는 정의상 알고리즘을 파손시켰다. 이 취약점은 키 크기를 두 배로 늘려 완화할 수 있지만, 추가되는 연산량 때문에 HAWK는 현재 사용 가능한 PQC 서명 알고리즘보다 매력도가 떨어진다.

학계에서는 취약점으로 인해 공격자가 무차별 대입 공격(brute-force attack)보다 더 빨리 키를 도출할 수 있을 때 암호화 알고리즘이 파손된 것으로 간주한다. 존스 홉킨스 대학교 교수이자 암호학 전문가인 매튜 그린(Matthew Green)은 이 발견의 인상적인 점이 이전에 아무도 결합할 생각을 하지 못했던 여러 기존 방법에 의존했다는 것이라고 말했다. 그린은 "특히 우려되는 부분(그리고 AI가 특히 유망한 이유)은 이 공격이 근본적으로 새로운 수학을 발명한 것이 아니라는 점입니다. 이는 단지 우리가 [가진] 도구들을 확장했을 뿐입니다."라고 작성했다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav A quantum-resistant cryptography algorithm that was under consideration as an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken . The algorithm is known as HAWK . It’s a digital signature scheme designed to withstand future attacks from quantum computers. HAWK had survived two rounds of testing by NIST (the National Institute of Standards and Technology) for evaluating the security of PQC (post-quantum cryptographic) algorithms through widespread testing. HAWK was in a third round of testing designed to catch precisely the kinds of flaws Mythos helped uncover. Following Anthropic’s Monday announcement of the results, the developer of HAWK said Tuesday he was withdrawing it. Even before the development, Anthropic was hailing the results of the two cryptographic problems it threw at its Mythos AI security model. The model found weaknesses in the mathematical problems underpinning HAWK and, separately, the widely used AES cipher. Despite the withdrawing of HAWK, it’s hard to know how much of the company’s reporting is marketing hype, but the findings are still worth paying attention to because they could signal important advances in breaking cryptography that’s crucial to privacy and security. Before digging into the results, a few caveats. First, the outcomes are incremental. They don’t break any of the cryptosystems anyone relies on today. Instead, they reveal methods for moderately reducing the work that would be required to defeat the systems. Second, the cryptosystems tested were weakened versions of the ones defined in their formal specifications. Such “challenge instances” are provided by the specification authors for use in adversarial peer review. It’s standard to use the weakened versions in testing, but the real ones are considerably more robust in production settings. Third, even with the improvement, the underlying “primitives”—meaning the underlying mathematical problems that form the basic building blocks of cryptosystems—remain safe, at least for now. Lastly, both of the attacks use methods that would likely be infeasible outside of testing environments. HAWK is dead Anthropic said its Mythos model—which currently remains available only to a select group of trusted users—was able to advance attacks against two cryptosystems. The first system is HAWK , a digital signature scheme designed to withstand future attacks from quantum computers. With about 60 hours of work and about $100,000 of compute cost, an Anthropic researcher with no expertise in cryptography prompted Mythos to improve the best-known existing attack on the algorithm that effectively cut its key strength in half. The math HAWK’s security relies on is the hardness of the Lattice Isomorphism Problem , which, unlike today’s most used digital signature schemes, is believed to be safe from quantum computing attacks. The best-known classical computing attack to solve this problem works by finding what are known as automorphism symmetries. Mythos outputted a previously unknown method for finding such symmetries by definition broke the algorithm. The weakness can be mitigated by doubling the key size, but the added computation makes HAWK less desirable than available PQC signing algorithms. In academics cryptographic algorithms are considered broken when weaknesses allow an adversary to derive a key faster than is possible using a brute-force attack. Matthew Green, a Johns Hopkins professor and expert in cryptography, said the impressive thing about the discovery was its reliance on several existing methods that no one previously thought to put together. “What’s particularly concerning (and so especially ripe for AI) is that the attack does not invent fundamentally new mathematics,” Green wrote . “It simply extends a bunch of tools that were lying around and well-known, and gets a good result.” Anthropic elaborated: To find the attack, Claude Mythos Preview worked semi-autonomously in an agentic harness, with occasional human guidance and nontechnical direction. Mythos found the attack after an extensive literature review to understand the state of the art, and substantial mathematical reasoning and computational experiments. After finding the attack, Mythos implemented an end-to-end verification pipeline to convince itself—and the human operator—of the attack’s correctness. To find the improved method, Mythos deployed two separate agents that worked largely independently. One initially rejected the method as unworkable. The second found a way to make it work. The agents eventually worked in unison until they produced an agreement that the improved attack was effective. (As with the description of the attack against AES later in this article, the HAWK attack methodology has been simplified. For the full details, see the Anthropic post or two longer papers on the HAWK and AES attacks, respectively.) Sophie Schmieg, an expert in PQC at Google, said HAWK was already suspected to have weaknesses that would eventually be found. Still, the method for halving the key strength found through Mythos made the candidate algorithm less competitive than existing PQC digital signature schemes such as ML-DSA and FN-DSA. “Basically with this paper, HAWK is dead,” she wrote. Less drama, but still kind of neat The attack against AES produced less dramatic results. It’s based on an improvement found through Mythos for performing a “meet-in-the-middle” attack, which is used to derive a key under a chosen plaintext threat model, the best-known existing attack against AES. The technique inputs large numbers of known plaintext into the crypto system and analyzes the encrypted output for clues that, with enough inputs, eventually reveal an unknown key. Previously, the best-known meet-in-the-middle attack against AES required roughly 2 105 plaintext inputs, a number large enough to make the method infeasible. Mythos helped to find a new meet-in-the-middle technique that relies on a Möbius Bridge , a more sophisticated fingerprinting algorithm used in meet-in-the-middle attacks. Using it, Green said, the code Mythos produced was able to reduce the number of required inputs to 2 89 . Anthropic said that savings can reduce the time required for such attacks by 200- to 800-fold. The ability to produce that many inputs makes the attack beyond reach outside of the laboratory. Further, the actual speed-up is unknown, since the weakened AES algorithm tested used only 7 rounds. Specification-compliant AES, Green said, uses 10, 12, or 14 rounds, depending on key size. Anthropic is careful to explicitly spell out most of these caveats. The Monday blog post goes on to argue, however, that the results are nonetheless meaningful and could ultimately fundamentally disrupt the process of cryptanalysis, or the adversarial testing of cryptosystems. “The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up,” Anthropic wrote. “We predict that the same will soon be true in academic cryptography research. As language models increasingly produce novel research outputs autonomously, human researchers may become bottlenecked on studying and validating these results for technical validity, novelty, and utility.” Not mentioned in Anthropic’s report is whether its researchers used Mythos to attack more tested cryptosystems, such as elliptic curve cryptography and RSA. Attack improvements against these systems would be more impressive. By achieving the most impressive result against an algorithm still in its infancy, it’s not clear how much of an advantage Mythos truly provided. There’s no way of knowing if researchers using conventional cryptanaly