[52367] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: handling weak keys using random selection and CSPRNGs

daemon@ATHENA.MIT.EDU (Perry E. Metzger)
Fri Oct 13 09:25:45 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
To: "Travis H." <solinym@gmail.com>
Cc: "Leichter, Jerry" <leichter_jerrold@emc.com>,
	"Steven M. Bellovin" <smb@cs.columbia.edu>,
	Cryptography <cryptography@metzdowd.com>
From: "Perry E. Metzger" <perry@piermont.com>
Date: Fri, 13 Oct 2006 09:25:16 -0400
In-Reply-To: <d4f1333a0610121835m38548145raaf1638494b6bf74@mail.gmail.com> (Travis
 H.'s message of "Thu, 12 Oct 2006 20:35:29 -0500")


"Travis H." <solinym@gmail.com> writes:
> On 10/12/06, Leichter, Jerry <leichter_jerrold@emc.com> wrote:
>> Beyond that:  Are weak keys even detectable using a ciphertext-only
>> attack (beyond simply trying them - but that can be done with *any* small
>> set of keys)?
>
> Yes, generally, that's the definition of a weak key.

No, that is not the definition of a weak key.

Look at DES weak keys, for example. They are simply keys for which the
encryption and decryption transform are identical -- encrypting twice
with the weak key returns you to the plaintext -- but they are not in
some way obviously detectable without trying them.

Might I suggest reading the literature on this before discussing it
further?

Perry

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post