Risk
8/1/2009
11:50 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Is AES On The Way Out?

Cryptographic researchers have uncovered a new attack against the ubiquitous AES encryption algorithm. While there have been a number of complex attack aimed at AES recently, this one, experts warn, may be practical enough for run-of-the-mill attackers to exploit.

Cryptographic researchers have uncovered a new attack against the ubiquitous AES encryption algorithm. While there have been a number of complex attack aimed at AES recently, this one, experts warn, may be practical enough for run-of-the-mill attackers to exploit.The Advanced Encryption Standard (AES) was selected by the U.S. Department of Commerce in October 2000 to replace the then de facto standard, triple DES. Today, AES is one of the most widely used algorithms for symmetric key cryptography. Symmetric key cryptography, like the name implies, is when the keys for encryption and decryption are either the same, or only slightly different. Generally, it's a shared secret between the person encrypting something, and those with the key to decrypt the information.

Well a group of researchers, including Adi Shamir (whose last name puts the S in the RSA algorithm) and Alex Biryukov, Orr Dunkelman, Nathan Keller and Dmitry Khovratovich.

The paper, which details the attack, has yet to be made public. Brice Schneier has read the paper, and provided a peek on his Web site:

In this paper we describe several attacks which can break with practical complexity variants of AES-256 whose number of rounds are comparable to that of AES-128. One of our attacks uses only two related keys and 239 time to recover the complete 256-bit key of a 9-round version of AES-256 (the best previous attack on this variant required 4 related keys and 2120 time). Another attack can break a 10 round version of AES-256 in 245 time, but it uses a stronger type of related subkey attack (the best previous attack on this variant required 64 related keys and 2172 time).

The paper, detailing the attack technique, should be available within days. For now, Schneier is recommending people not use AES-256 and that AES-128 "provides more than enough security margin for the foreseeable future."

Let's hope so.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
IIWK1101@IWK.COM152
50%
50%
IIWK1101@IWK.COM152,
User Rank: Apprentice
11/1/2011 | 9:44:43 AM
re: Is AES On The Way Out?
I Agree
IIWK1101@IWK.COM152
50%
50%
IIWK1101@IWK.COM152,
User Rank: Apprentice
11/1/2011 | 9:44:33 AM
re: Is AES On The Way Out?
Nice Blog
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.