next up previous
Nächste Seite: Symmetric vs. asymmetric algorithms Aufwärts: Basics Vorherige Seite: Basics

How secure is it?

There are a couple of algorithms which are considered safe by mathematicians. Safe means, that there is no known weak point in the algorithm, resulting in the fact, that the only possible attack is brute force3. Brute force means that every possible key is tried, until the right one has been found. A brute force attack against a 56 bit DES key took a little more than a year to crack by thousands of computers spending their idle time to crack it in 1997/1998 in the distributed.net effort. In 1999, specialized hardware built by the EFF was able to crack it within less than a day. So 56 bit DES can no longer be considered to be safe.

As every single bit in the length of the key doubles the number of possible keys, reasonably long keys are safe, unless some mathematician finds a weak point in the algorithm. The 168 bits of Triple DES won't be found by brute force attacks within the next hundred years. If computer power increased by a factor of two every year, you'd need one more bit every year for the same level of safety ...


next up previous
Nächste Seite: Symmetric vs. asymmetric algorithms Aufwärts: Basics Vorherige Seite: Basics
Kurt Garloff
2000-08-28