ROCA and Minerva Vulnerabilities
Jan Jancar, Petr Švenda, Marek Sýs · 2025
The Return of Coppersmith's Attack (ROCA) and Minerva are two examples of real-world practically exploitable vulnerabilities found in cryptographic smartcards certified to high security levels under the Common Criteria certification scheme. The Minerva vulnerability is caused by an implementation weakness providing an attacker with the knowledge of one or more most significant bits of an ECDSA noncevia timing side-channel leakage. The Minerva group of vulnerabilities was discovered in 2019. It affects a Common Criteria–certified smartcard and is used to affect five popular open-source cryptographic libraries. All of the affected implementations leak information on the most-significant bits (usually the bit-length) of the random nonce used in ECDSA signatures via a timing side-channel. The exact cause of the vulnerability of each affected implementation differs slightly, as does the leakage itself, but the main issue is the same.