{"id":921,"date":"2016-05-18T03:17:31","date_gmt":"2016-05-18T03:17:31","guid":{"rendered":"http:\/\/www.dogoodsoft.com\/blog\/?p=921"},"modified":"2024-12-23T07:57:37","modified_gmt":"2024-12-23T07:57:37","slug":"osgp-custom-rc4-encryption-cracked-yet-again","status":"publish","type":"post","link":"https:\/\/www.dogoodsoft.com\/blog\/osgp-custom-rc4-encryption-cracked-yet-again-921\/","title":{"rendered":"OSGP custom RC4 encryption cracked yet again"},"content":{"rendered":"<p><a href=\"https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2016\/05\/11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-922 size-full\" src=\"https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2016\/05\/11.png\" alt=\"OSGP custom RC4 encryption cracked yet again\" width=\"322\" height=\"183\" srcset=\"https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2016\/05\/11.png 322w, https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2016\/05\/11-300x170.png 300w, https:\/\/www.dogoodsoft.com\/blog\/wp-content\/uploads\/2016\/05\/11-2x1.png 2w\" sizes=\"auto, (max-width: 322px) 100vw, 322px\" \/><\/a><\/p>\n<p>The Open Smart Grid Protocol&#8217;s (OSGP) home-grown RC4 encryption has been cracked once again. The easy-to-break custom RC4 was cracked last year.<\/p>\n<p>A year ago, the OSGP Alliance advised that better security would be implemented, but the RC4 still remains according to German researchers Linus Feiten and Matthias Sauer.<\/p>\n<p>Feiten and Sauer claim to have the ability to extract the secret key used in the OSGP&#8217;s RC4 stream cipher. \u201cOur new method comprises the modification of a known attack exploiting biases in the RC4 cipher stream output to effectively calculate the secret encryption key. Once this secret key is obtained, it can be used to decrypt all intercepted data sent in an OSCP smart grid,\u201d Sauer and Feiten explained in their research.<\/p>\n<p>Decrypting the secret key can expose the energy consumption of an individual customer thus an attacker could create messages reporting incorrect information to the grid operator.<\/p>\n<p>Grid operators waited on vendor support to protect their networks with the alliance&#8217;s OSGP-AES-128-PSK specification bit encryption released in July as it was described as a \u201cnew work proposal for standardisation purposes\u201d.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Open Smart Grid Protocol&#8217;s (OSGP) home-grown RC4 encryption has been cracked once again. The easy-to-break custom RC4 was cracked last year. A year ago, the OSGP Alliance advised that better security would be implemented, but the RC4 still remains according to German researchers Linus Feiten and Matthias Sauer. Feiten and Sauer claim to have &hellip; <a href=\"https:\/\/www.dogoodsoft.com\/blog\/osgp-custom-rc4-encryption-cracked-yet-again-921\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">OSGP custom RC4 encryption cracked yet again<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[52,354,355],"class_list":["post-921","post","type-post","status-publish","format-standard","hentry","category-news","tag-encryption","tag-osgp","tag-rc4"],"_links":{"self":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts\/921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=921"}],"version-history":[{"count":1,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts\/921\/revisions"}],"predecessor-version":[{"id":923,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/posts\/921\/revisions\/923"}],"wp:attachment":[{"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dogoodsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}