Re: Simple steps to improve CIPE security

[email protected]
Newsgroups gmane.comp.encryption.cipe
Message-ID <[email protected]>
On Wed, Oct 01, 2003 at 09:45:49AM +0200, Allan Latham wrote:
> Hi all
> 
> 1. I am considering alternatives to MD5.
> 
> 2. Almost all packets are encrypted with the dynamic key. Those that fail CRC 
> are subject to an extra decryption with the static key. In normal 
> circumstances this is no great problem. The risk is that it increases the 
> effectiveness of a DOS attack. (Sending garbage to CIPE would make it consume 
> twice as much CPU).
> 
> I did not make it clear. The intention is to use the static key only for KX 
> and the dynamic key only for data. This means that if an attacker breaks a 
> dynamic key he cannot then use this to decrypt the KX and get the next 
> dynamic key. Avoiding using the static key for data minimises its use and 

Is this a good idea?
Suppose that an attacker gets an encrypted KX, after that he gets the
dynamic key, now he has known plaintext, and isnt it then easier to
find the static key?



JonB

--
Message sent by the [email protected] mailing list.
Unsubscribe: mail [email protected], "unsubscribe cipe-l" in body
Other commands available with "help" in body to the same address.
CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.