commuting?/non-group cipher?

From: Peter Fairbrother (zenadsl6186_at_zen.co.uk)
Date: 10/28/04


Date: Thu, 28 Oct 2004 06:56:03 +0100

Some ciphers have the property that a double encryption can always be
replaced by a single encryption, ie E(k3)[P] = E(k1)[E(k2)[P]]

Does anyone know the correct name for this property? If there isn't one,
does anyone know a reason why "commuting (adj.)" cipher would not be okay?

Can anyone think of an example of a cipher with this property that is not a
group?

-- 
Peter Fairbrother


Relevant Pages

  • Re: Should Initialization Vectors be public ?
    ... CBC XORes every previous cipher block with next plain text block before ... encryption key on the same plain text, ... add them at the beginning of your plaintext data ...
    (microsoft.public.dotnet.security)
  • Re: Should Initialization Vectors be public ?
    ... > CBC XORes every previous cipher block with next plain text block before ... Chaining and feedback modes does provide extra strength to ... > encryption key on the same plain text, ... >>>> then to decrypt. ...
    (microsoft.public.dotnet.security)
  • Re: cryptoloop CBC mode
    ... >> identical it could be the case that two would get same encryption. ... For such blocks you will know exactly which bits differ ... and the two IVs are different. ... > the key will still be the same (ok, different cipher output, but the ...
    (comp.os.linux.security)
  • Chaffing and deniability in pencil-and-paper ciphers
    ... Although pencil and paper ciphers are entirely impractical these days, ... _encryption_ step. ... The real message is encrypted using your best algorithm, ... The fake message can be encrypted in a weaker cipher, ...
    (sci.crypt)
  • Re: Break This
    ... I'd guess that you're trying to ascertain if your cipher is ... > against your attackers? ... > engineer your encryption algorithm, they'll try and stick a trojan on ... This is I think the only secure way. ...
    (sci.crypt)