Running 2017 through the framework

On 2 November 2017 the Estonian government endorsed suspending the certificates of 760,000 ID cards, and at midnight on 3 November it did. Renewal ran through Police and Border Guard service points and online. A national re-key campaign, executed as one decision, because one key-generation design’s failure domain covered the issued estate. Our Universal Framework’s Annex 1 re-runs the method over that event, and this post sets out the retrodiction at reading speed.

The event

On 16 October 2017, researchers at Masaryk University’s CRoCS laboratory, Enigma Bridge and Ca’ Foscari University disclosed CVE-2017-15361. The RSA key-generation routine in Infineon’s RSALib produced structured primes, leaving the resulting keys practically factorable from the public key alone. Their disclosure page priced the attack on a 2014-era CPU at roughly 2 CPU-hours for a 512-bit key, 97 CPU-days and $40–80 for 1024 bits, and 140.8 CPU-years and $20,000–40,000 for 2048 bits.

The library sat inside smartcards, tokens and trusted platform modules across product lines from many vendors. Microsoft, Google, HP, Lenovo and Fujitsu all shipped mitigations at disclosure. The affected chips, manufactured from 2012 onward, held FIPS 140-2 and Common Criteria EAL5+ certifications. Infineon had been notified in February 2017. The paper followed at ACM CCS on 2 November, the day Estonia decided.

The 2016 reading

Annex 1 places an assessment in 2016, at an institution running a TPM-attested device fleet and an issued-token estate, and asks what the record supports.

Observed diversity runs high, with several laptop manufacturers, several token brands and several card products. A vendor-substitutability test passes comfortably, for the reasons our launch post sets out.

Layer 6 resolution collapses it. The generation point for each asset is the embedded chip. The pre-disclosure trail, vendor documentation plus the certification records that named the Infineon chip families and their on-chip RSA generation, resolves a brand-diverse estate toward one generation design. Where the certification record evidences the design, the resolution is direct. Where it evidences only conformance to a profile, the framework records a bound rather than a finding. The honest answer is then an interval.

Either way, the design node’s failure-domain reach spans most or all of the issued estate, a Single-source-equivalent reading at the node behind a diversified vendor register.

The same event reads at layer 2 in parallel, because the library is also an executing implementation family. One failure appearing in two layers is expected behaviour, not double counting, since the layers ask different questions of the same estate.

The framework’s failure-impact determination fails in advance. Its layer-6 scenario, a generation defect disclosed in the shared design, sets the recovery task at re-keying the affected estate plus the retroactive exposure of every key already generated. For an issued physical estate, re-keying means updating or reissuing every card and token, a months-long campaign against any operational tolerance measured in hours or days. The retroactive term engages the consequence threshold regardless of how fast anyone moves. The determination the framework requires an analyst to record in advance is the one Estonia performed live, at national scale, over a weekend.

What it validates, and what it cannot

No pre-2017 evidence could have shown the design was broken, and the framework doesn’t claim otherwise, and it produces no cryptanalytic judgment anywhere. What the public record shows is that the framework’s actual outputs were computable before disclosure: one design behind many brands, a reach at or near the whole estate, a recovery task no tolerance survives, and certifications that attested correctness while saying nothing about provenance or design independence. That last item is the certification row in our false-moves catalogue, validated by events.

A retrodiction also comes with a selection effect, stated plainly in the annex itself. ROCA was chosen because its record is rich, so the validation claim is only that the computation needed pre-disclosure inputs, and it did.

Nothing in the event is quantum, which is the annex’s quiet second point. The method is defined over cryptographic failure modes generally, and post-quantum migration is its first instantiated use case because that’s the failure mode with regulatory dates attached.

Two further classical retrodictions join at v1.1, Debian (2008) at layer 6 and KyberSlash (2023) at layer 2, per the public roadmap. The full annex, with every claim tiered to its record class and linked to its primary source, ships inside the Universal Framework at ccframework.org.