Re: cipher combinations



Paul Rubin wrote:
invalid@xxxxxxxxxxx writes:
It has been proven that naively cascading ciphers does not necessarily yield a secure combination.

If the above were true, I could attack any strong sipher by adding/cascading my own compromized cipher at the end.

You're confusing "does not necessarily yield" with "never yields".

Consider the notorious one-time pad: ciphertext = plaintext xor K.

What happens if you double encrypt?

It's as secure as a single encryption, assuming the keys are independently chosen at random.

Ueli Maurer, who wrote the paper [1] I *think* you are referring to - though I don't really understand your post - says "The distinction between cascade ciphers and product ciphers 6 is that, in the latter, the keys of the component ciphers need not be statistically independent, whereas they are in the former."

For the record, Ueli's example in the paper doesn't work (at all!), and afaict Even and Goldreich's result [2] stands (ie a cipher cascade is at least as strong as the strongest cipher, independent of order).


-- Peter Fairbrother


[1] Cascade Ciphers: The Importance of Being First, Journal of Cryptology Volume 6, Number 1 / March, 1993
[2] S. Even and O. Goldreich, On the power of cascade ciphers, ACM Transactions on Computer. Systems, Vol. 3, Issue 2 Pages: 108 - 116
.



Relevant Pages

  • Re: My little something...
    ... since ECC is kinda new field. ... You mean you offer two ciphers in different modes or that you chain ... Two ciphers in different modes with different, independend keys. ... and XOR to create blockkey. ...
    (sci.crypt)
  • Re: Should be in crypto for John E. Hadstate Re: just stupid?
    ... Ritter was cited an as expert by this CryptoSMS fellow. ... Authority tends to hide the basis for drawing ... > needs to analyzed as if it was one (not a cascade of ciphers) cipher. ... conventional block ciphers, some keys could ...
    (sci.crypt)
  • Re: A new public key algorithm based on avalanche properties
    ... > demanding of the evidence or arguments I produce in favour of where I ... I've gotten some good responses here, but Tom didn't like it. ... "designing ciphers by a hobbyist is a really bad ... Secure encryption should be like an off-the-shelf electronic part. ...
    (sci.crypt)
  • Re: My little something...
    ... Its more unlikely that attack on 1024 ECC to subvert it to weaker than ... More secure ofcourse. ... Dont give BS about two cascading ciphers not neccessarely being more ... 10101 as hash. ...
    (sci.crypt)
  • Re: Should be in crypto for John E. Hadstate Re: just stupid?
    ... Ritter was cited an as expert by this CryptoSMS fellow. ... Do you claim expertise on the concatenation of ciphers? ... > conventional block ciphers, some keys could ... We are not talking about analyzing each key; ...
    (sci.crypt)