Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

AES proved vulnerable by Microsoft researchers

Show that algorithm underlying most all of today's online transactions can be compromised

Researchers from Microsoft and the Dutch Katholieke Universiteit Leuven have discovered a way to break the widely used Advanced Encryption Standard (AES), the encryption algorithm used to secure most all online transactions and wireless communications.

Their attack can recover an AES secret key from three to five times faster than previously thought possible, reported the Katholieke Universiteit Leuven, a research university based in Belgium.

The researchers caution that the attack is complex is nature, and so can not be easily carried out using existing technologies. In practice, the methodology used by the researchers would take billions of years of computer time to break the AES algorithm, they noted.

But the work, the result of a long-term cryptanalysis project, could be the first chink in the armor of the AES standard, previously considered unbreakable. When an encryption standard is evaluated for vital jobs such as securing financial transactions, security experts judge the algorithm's ability to withstand even the most extreme attacks. Today's seemingly secure encryption method could be more easily broken by tomorrow's faster computers, or by new techniques in number crunching.

The U.S. NIST (National Institute of Standards and Technology) agency commissioned AES in 2001, to replace the DES Digital Encryption Standard (DES), which was then repeatedly being shown to be fragile even as it provided adequate security for most everyday tasks.

With this work, the "safety margin" of AES continues to erode, noted security expert Bruce Schneier in a blog posting. "Attacks always get better; they never get worse," he wrote, quoting an expert from the U.S. National Security Agency.

Though unwieldy to execute, the attack can be applied to all versions of AES.

K.U. Leuven researcher Andrey Bogdanov, Microsoft Research's Dmitry Khovratovich and Christian Rechberger from École Normale Supérieure, Paris, completed the work. Both Bogdanov and Rechberger had taken leave from their respective universities to work on the project with Microsoft Research.

The creators of AES, Joan Daemen and Vincent Rijmen have acknowledged the validity of the attack, according to K.U. Leuven.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Advanced Encryption Standard, AES, IDG, Microsoft, National Security Agency, Technology
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: encryption, Microsoft, security
Latest Blog Posts
Whitepapers
  • Enabling Agile and Intelligent Businesses
    In the last 3 to 5 years there has been widespread adoption of SOA with businesses making significant economic investments in service-enabling their IT systems. Looking to enable your business for efficient IT execution? Read this white paper now.
    Learn more »
  • Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
    A revolutionary new video collaboration device, the Avaya Desktop Video Device has been making waves in the communications industry ever since Avaya introduced the product in the fall of 2010. Avaya’s own employees have been among the earliest users and have seen first-hand how the product can improve collaboration and make people more efficient and effective. Read more.
    Learn more »
  • Enterprise Buyers Guide for Cloud Storage
    Customer interest in public cloud storage is increasing, driven by the promise of affordable, elastic storage for archiving, backup/recovery, and disaster purposes. To understand the types of offerings available and to assist buyers with purchasing decisions Computerworld has prepared a public cloud storage buyers guide.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments