Security fears over encryption after key discovery

Security fears over encryption after key discovery

Microsoft researchers highlight weakness that could be exploited in the future.

Security experts have warned administrators that a leading encryption standard could be cracked in the future.

The Advanced Encryption Standard (AES) is used by security agencies to protect secret communications, and in the background by consumers in online banking, but research points to weaknesses that could be exploited in the future.

"I don't think there's any danger of a practical attack against AES for a long time now," said Bruce Schneier, chief security technology officer of BT, said in a blog post. "Which is why the community should start thinking about migrating now."

Although AES remains safe for the short term, researchers from Microsoft have worked out a way of cracking keys four times faster than using brute-force attacks – and further research into their methods could yield practical cracking techniques in the long term.

While previous attacks have relied on knowing a similar key and trying to guess keys from that information, the new method theoretically works with any key, using a meet-in-the-middle attack based on a mathematical concept called "bicliques".

“We show how to carry over the concept of bicliques to block cipher cryptanalysis and get even more significant results, including the first key recovery method for the full AES faster than brute-force,” Andrey Bogdanov, Dmitry Khovratovich, and Christian Rechberger wrote in Biclique Cryptanalysis of the Full AES (pdf).

"In contrast to most shortcut attacks on AES variants, we do not need to assume related keys. Most of our attacks only need a very small part of the codebook and have small memory requirements, and are practically verified to a large extent."

Although for all practical purposes the research makes little impact on security in the short term, with supercomputers still requiring years to crack a key, it does provide researchers with a new attack vector that could be exploited in future if the method is honed and deployed on more powerful computers.

This article originally appeared at pcpro.co.uk

Source: Copyright © PC Pro, Dennis Publishing

See more about:  security  |  fears  |  encryption  |  key  |  discovery  |  securitysoftware
 
 

Readers of this article also read...

Best Android apps this week 

Best Android apps this week

 
Toshiba's new 2013 laptops unveiled 

Toshiba's new 2013 laptops unveiled

 
New Kira Ultrabook is a stylish, aspirational gem, according to Toshiba 

New Kira Ultrabook is a stylish, aspirational gem, according to Toshiba

 
Preparing for the future - How the evolution of the PC highlights the importance of the NBN 

Preparing for the future - How the evolution of the PC highlights the importance of the NBN

 
A beginners guide to getting Simcity up and running 

A beginners guide to getting Simcity up and running

 
Comments: 1
j876
22 August 2011
AES is also one of the encryption algorithms on WiFi networks it just goes to show that as hackers evolve, encryption methods need to evolve faster.


Comment made about the PC & Tech Authority article:
Security fears over encryption after key discovery?
Microsoft researchers highlight weakness that could be exploited in the future.

What do you think? Join the discussion.
Comments have been disabled for this article.
Latest articles on BIT Latest Articles from BIT
Federal Budget 2013: So what are you going to be required to pay?
15 May 2013
Opinion: Want a handy summary of the 2013 federal budget? Here is one by Newcastle accountants ...
Architects: another profession on the list of people using Evernote
10 May 2013
Yes, apparently the hugely popular Evernote note-syncing app is also being used by people who ...
In Brisbane? Setting up a business?
10 May 2013
Too embarrassed to ask even the most basic questions? Here's your chance to find out about ...
Worried about staff losing the office keys?
8 May 2013
Here's an interesting idea: a system which lets you assign a digital office "key" to your ...
Need a LOT more storage?
7 May 2013
Do you have multiple offices or servers? Are your systems requiring so much storage your IT ...

Latest Comments

Latest Poll

Which broadband network do you think is the best choice for Australia?



or View results
The Coalition's.
  19%
 
Labor's.
  63%
 
Screw this I'm going back to smoke signals and string on a can.
  19%
TOTAL VOTES: 1758

Vote now
Ads by Google

From our Partners

PC & Tech Authority Downloads