AES proved vulnerable by Microsoft researchers
- 19 August, 2011 02:37
- Comments
Researchers from Microsoft and the Dutch Katholieke Universiteit Leuven have discovered a way to break the widely used Advanced Encryption Standard (AES), the encryption algorithm used to secure most all online transactions and wireless communications.
Their attack can recover an AES secret key from three to five times faster than previously thought possible, reported the Katholieke Universiteit Leuven, a research university based in Belgium.
The researchers caution that the attack is complex is nature, and so can not be easily carried out using existing technologies. In practice, the methodology used by the researchers would take billions of years of computer time to break the AES algorithm, they noted.
But the work, the result of a long-term cryptanalysis project, could be the first chink in the armor of the AES standard, previously considered unbreakable. When an encryption standard is evaluated for vital jobs such as securing financial transactions, security experts judge the algorithm's ability to withstand even the most extreme attacks. Today's seemingly secure encryption method could be more easily broken by tomorrow's faster computers, or by new techniques in number crunching.
The U.S. NIST (National Institute of Standards and Technology) agency commissioned AES in 2001, to replace the DES Digital Encryption Standard (DES), which was then repeatedly being shown to be fragile even as it provided adequate security for most everyday tasks.
With this work, the "safety margin" of AES continues to erode, noted security expert Bruce Schneier in a blog posting. "Attacks always get better; they never get worse," he wrote, quoting an expert from the U.S. National Security Agency.
Though unwieldy to execute, the attack can be applied to all versions of AES.
K.U. Leuven researcher Andrey Bogdanov, Microsoft Research's Dmitry Khovratovich and Christian Rechberger from École Normale Supérieure, Paris, completed the work. Both Bogdanov and Rechberger had taken leave from their respective universities to work on the project with Microsoft Research.
The creators of AES, Joan Daemen and Vincent Rijmen have acknowledged the validity of the attack, according to K.U. Leuven.
Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Seven SOA Practices to Unlock Business Value
- IDC MarketScape: Worldwide Business Process Platforms 2011 Vendor Analysis
- Case Study - TNT Express successfully reduces their paper usage and costs using a new document solution
- 3PAR Storage: Tailor-Made for Virtual Infrastructures
- SOA Best Practices and Design Patterns
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Enabling Agile and Intelligent Businesses
In the last 3 to 5 years there has been widespread adoption of SOA with businesses making significant economic investments in service-enabling their IT systems. Looking to enable your business for efficient IT execution? Read this white paper now. -
Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
A revolutionary new video collaboration device, the Avaya Desktop Video Device has been making waves in the communications industry ever since Avaya introduced the product in the fall of 2010. Avaya’s own employees have been among the earliest users and have seen first-hand how the product can improve collaboration and make people more efficient and effective. Read more. -
Enterprise Buyers Guide for Cloud Storage
Customer interest in public cloud storage is increasing, driven by the promise of affordable, elastic storage for archiving, backup/recovery, and disaster purposes. To understand the types of offerings available and to assist buyers with purchasing decisions Computerworld has prepared a public cloud storage buyers guide.
-
Group Policy
-
Microsoft Works Suite 2000 for Dummies
-
Professional Dotnetnuke ASP.NET Portals
-
Concept Data Analysis - Theory and Applications
-
More Autodesk Maya Hyper-realistic Creature Creation
-
The Celebrity Tweet Directory
-
Risk Management Solutions for Sarbanes-Oxley Section 404 It Compliance
-
Coder to Developer - Tools and Strategies for Delivering Your Software
-
Beta Testing for Better Software








Comments
Post new comment