Re: Simple steps to improve CIPE security

Sandino Araico Sanchez <[email protected]>
Newsgroups gmane.comp.encryption.cipe
Message-ID <[email protected]>
Hans Steegers wrote:

>Hi Allan,
>
>  
>
>>2. Disable static key for data exchange (via options).
>>    
>>
>Probably not difficult to implement.
>
>  
>
>>3. Do not identify static key use in the IV (via options). This will
>>    
>>
>involve
>  
>
>>an extra decrytion step is the dynamic key decrypt fails.
>>    
>>
>Looks like more difficult to implement. Trial and error decryption is
>costly.
>
It's not that costly if we assume static keys are not being used for 
data transfer so we just have two choices to guess from: static key or 
the current dynamic key.
In the wost case it's twice as costly because dynamic key decryption 
needs to fail before trying static key decryption. And there's no 
overhead on processing data traffic..

>I have to investigate, but at the moment I haven't got the time for it.
>
>  
>

-- 
Sandino Araico Sánchez
-- Lo que no mata engorda.



--
Message sent by the [email protected] mailing list.
Unsubscribe: mail [email protected], "unsubscribe cipe-l" in body
Other commands available with "help" in body to the same address.
CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.