18 Sep 2002
Two of the most widely used encryption standards - Advanced Encryption Standard (AES) and Serpent - may have been broken, but the theoretical attacks will not be a reality for at least 10 years.
It is also unclear whether the attacks actually work. Bruce Schneier, chief technology officer at Counterpane and renowned crypto expert, said: "In either case, there's no need to panic. Yet. But there might be soon. Maybe."
A recently presented paper by cryptographers Nicolas Courtois and Josef Pieprzyk outlined attacks against AES and Serpent carried out by "expressing the entire algorithm as multivariate quadratic polynomials, and then using an innovative technique to treat the terms of those polynomials as individual variables".
In layman's terms, they claimed to break the algorithms.
But the paper outlining the XSL attack was so hard to understand in itself that interest waned quickly. The problem is that cipher key lengths have become so long that attacks simply cannot be implemented because their complexity is too great.
"There's no cause for alarm yet. These attacks can be no more implemented in the field than they can be tested in a lab," said Schneier, explaining that no communications are yet at risk and no products need to be recalled.
"But there is call for worry," he added. "If the attack really works, it can only get better."
Schneier said that optimisations of the XSL attack could break AES at a lesser complexity, "in which case things starts to get dicey about 10 years from now. That's the problem with theoretical cryptanalysis: we learn whether or not an attack works at the same time we learn whether or not we're at risk."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Solution Architect / Technical Project Manager / Corporate...
Tier 1 Investment Bank seeks an Administrator with an...
Are you a proven agile test engineer that wants to work...
A leading global organisation seeks a Lead Project Planner...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?