home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: sci.crypt
- Path: sparky!uunet!newsgate.watson.ibm.com!yktnews!admin!aixproj!uri
- From: uri@watson.ibm.com (Uri Blumenthal)
- Subject: Re: Enlarging key size of the DES algorithm
- Sender: news@watson.ibm.com (NNTP News Poster)
- Message-ID: <1992Dec17.205145.10511@watson.ibm.com>
- Date: Thu, 17 Dec 1992 20:51:45 GMT
- Reply-To: uri@watson.ibm.com
- Disclaimer: This posting represents the poster's views, not necessarily those of IBM
- References: <6681@tuegate.tue.nl> <BzDp6F.6zn@chinet.chi.il.us>
- Nntp-Posting-Host: aixproj.watson.ibm.com
- Organization: Why do you care?
- Keywords: DES, key size
- Lines: 31
-
- In article <BzDp6F.6zn@chinet.chi.il.us>, schneier@chinet.chi.il.us (Bruce Schneier) writes:
- |> > 2) Does anybody know of other modifications concerning the key size ?
- |>
- |> There have been many. None of them are any good. Biham and Shamir showed
- |> that DES with independent subkeys (the 768-bit key variant you mentnion) is no
- |> more secure than DES. Something else called GDES was also shown to be no more
- |> secure than DES. The security of DES seems pretty much limited to a 56-bit
- |> key.
-
- I beg to differentiate! (:-)
-
- There are two feasible attacks [on DES]: exhaustive search and differential
- cryptanalysis.
-
- While indeed Biham-Shamir attack produces a key with probability 1 with every
- 2^47 chosen plaintexts - how good a chance is, that your adversary can get
- that many encryption of his stuff performed on your DES engine? Or how
- likely is it for him to have similar amount of known plaintexts (and
- if he does have that much of it - probably there's no need for the
- key anyway, all the data passed is there :-).
-
- Thus the only practical threat left is an exhaustive search. And
- I fail to understand why the DES with independent subkeys
- (760-bit key) is "limited to 56-bit key". I'd say
- it's wrong, at least from practical point
- of view.
- --
- Regards,
- Uri. uri@watson.ibm.com
- ------------
- <Disclaimer>
-