LOGBOOK

HELP

1 / 320
time's up — finish this card
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag
Topic Symmetric Cryptography

Question

What are the key parameters of DES and why is it considered insecure today?

Answer

DES uses a 56-bit key with 64-bit blocks over 16 Feistel rounds — it's insecure because 2^56 keys can be brute-forced in hours with modern hardware.

DES parameters:

Parameter Value
Block size 64 bits
Key length 56 bits (64 bits input, 8 are parity)
Rounds 16
Structure Feistel network

History:

  • Developed by IBM, adopted as a US federal standard (FIPS) by the National Bureau of Standards (now NIST) in 1977
  • IBM's original "Lucifer" design used a longer key; the published standard fixed it at 56 bits — a shortening widely attributed to NSA influence and controversial at the time
  • In 1999, the EFF's "Deep Crack" machine (working with distributed.net) recovered a DES key in about 22 hours

Why 56 bits is too short:

  • 2^56 = 7.2 × 10^16 possible keys
  • Modern hardware (FPGAs, ASICs, cloud computing) can search this space quickly
  • DES was officially withdrawn as a standard in 2005

The algorithm itself is well-designed — the weakness is purely the short key length. This is why 3DES was created as a stopgap.

Go deeper:

Illustration
Hellisp · CC0 · Wikimedia Commons
or press any other key
Topic RSA

Question

True or false: "RSA is immune to side-channel attacks."

Answer

False — RSA is highly vulnerable to side-channel attacks, particularly power analysis (SPA/DPA) during the square-and-multiply computation of $m^d \mod N$.

A power trace of square-and-multiply reveals each bit of d: a 1-bit adds a taller multiply burst

* Every 1-bit of the private exponent triggers an extra multiply, so its larger power/timing signature lets an attacker read d straight off the trace. *

Why RSA is vulnerable:

  • Decryption/signing computes $m^d \mod N$ using SAM (Square-and-Multiply)
  • For each bit of $d$: a "1" bit causes a MULTIPLY + SQUARE, a "0" bit causes only a SQUARE
  • These operations have different power consumption and different timing
  • An attacker monitoring power traces can literally read the private key $d$ bit by bit

Known side-channel attacks on RSA:

  • Simple Power Analysis (SPA): Directly read the key from one power trace
  • Differential Power Analysis (DPA): Statistical analysis over many traces
  • Timing attacks: Different keys cause different computation times
  • Electromagnetic emissions: EM radiation leaks key information

Countermeasures:

  • Blinding: Randomize the computation using RSA's multiplicative property — multiply $m$ by a random $r^e$ before decryption, then divide by $r$ afterward
  • Constant-time implementations: Ensure every bit of the key takes the same time
  • Hardware shielding: EM and power filtering

Tip: The multiplicative property of RSA is both a weakness (malleability) AND a tool for defending against side channels (blinding). Context determines whether it's friend or foe.

Go deeper:

A diagram of differential power analysis.
A diagram of differential power analysis.
Mark Pellegrini · CC BY-SA 3.0 · Wikimedia Commons
or press any other key