Re: A proposal on key management of block ciphers



Am 18.05.2011 17:51, schrieb Tran Ngoc Duong:
For a good cipher, K alone is practically secure. For a bad cipher,
well, algebraic attacks (which get big improvements recently) can
recover K given very few pairs of (plaintext, ciphertext) so it's hard
to say how practical is this scheme.

Nevertheless, there are combined ciphers that use AES or Serpent as the
key-management cipher and a weak but very fast cipher as the
data-encryption cipher that encrypts a tiny amount of data under the
same key.

One motivation of my proposal was to attempt to convince some
researchers in differential analysis etc. etc. that they might
eventually better use their creativity/capability in researching
stuffs that may be more urgently needed in the practice of crypto.

M. K. Shen
.



Relevant Pages

  • Re: Needle in a haystack--or is this just stupid?
    ... In practice, no OTP ... >> no cipher can be trusted in practice. ... This is not a new attack model. ...
    (sci.crypt)
  • Re: [ipsec] aes-ctr question
    ... cipher will allow listeners to recover the plaintext. ...
    (freebsd-net)
  • Re: Needle in a haystack--or is this just stupid? - LONG
    ... Or cryptography? ... independence in practice. ... that the main cipher has an exploitable flaw ... To go from any one transformation in A to ...
    (sci.crypt)
  • Re: Long Vigenere Keys
    ... Vigenere cipher requires key the same length as the encrypted ... Am I correct in my assumption that, in practice, the keys ... > avoidable weakness in the encryption. ...
    (sci.crypt)
  • Re: weakest link
    ... >Seeding an RNG from private or secret key material is not ... >good practice. ... a cipher, you don't want to seed the PRNG with the key. ...
    (sci.crypt)