5 ms·
This is an intellectual question for curiosity’s sake. I realize that an OTP encryption system will not be a practical improvement for communication compared t
by jcrites 4y ago
This is an intellectual question for curiosity’s sake.
I realize that an OTP encryption system will not be a practical improvement for communication compared to e.g. the Signal protocol, which is easier to use and provides a number of other advantageous properties; or something like TLS. (If you could securely exchange one time pad material, then you could also more easily exchange asymmetric keys)
I realize that actual systems have a large number of threat vectors, and that the encryption protocol itself is unlikely to be the primary risk.
Nevertheless, I’m curious: if one decides to implement digital encryption using one time pads, what is the most practical source of suitable randomness?
And have communication protocols been designed for OTP, or would your best bet be to layer it on top of something like Signal or TLS? It seems that you probably need to exchange at least some metadata along with each message describing, e.g., the message size and starting offset into the pad material - metadata that you’d want to protect with encryption, and I don’t see a very straightforward way to protect it using OTP.
On reflection, this probably only has relevance for government or military communications that might need to remain secure for longer than 50 years.
Perhaps the use-case is something like an aircraft carrier, submarine, or other large, critical vehicle or facility, that receives OTP material by delivery of a hard drive protected by considerable physical security.
Critical communication from these vehicles/infrastructure would remain protected against future cryptographic attacks - e.g., if an algorithmic vulnerability is discovered, or there’s a breakthrough in quantum or traditional computing that renders today’s encryption vulnerable within the next few decades — the OTP-protected message content remains protected. (Even if intercepted, recorded, and attacked decades later)
Yes, I agree that the practical applications are limited… The questions are an exercise for curiosity’s sake: if you’re going to employ OTP encryption, then …
- tptacek 4y agoTo achieve the "theoretical" unbreakability that keeps one time pads perennially in the discussion, you need a true random source of bits: a (sufficiently bias-free) measurable natural process to sample. That's what makes OTPs unbreakable: there's no structure anywhere to attack. To achieve practical unbreakability, you just need your bits to be indistinguishable from random. You can take a relatively small number of unguessable bits and then run them through the Blake2-based LRNG algorithm to spool out a practically unlimited number of "random" bits. Theoretically you can attack Blake2 and the LRNG system; there could be some vulnerability there. In practice, this would be a deeply shitty setting to try to cryptanalyze anything, even if Blake2 was broken, which it isn't. If you are going to go through the trouble of literally distributing physical pads to all the counterparties, though, you might as well just generate true random numbers.
- Vecr 4y agoThe problem with true random is that you might screw up your avalanche diode circuit (or whatever) in a way that makes it random, but not uniformly distributed. It might also pick up EM from somewhere and not "really" be random all the way. By the time you add all the whitening and that sort of thing to make those problems go away I'm not sure how the information theory proofs hold up. Probably what you would want to do is keep the physical random number generator in a fine-mesh Faraday cage in a controlled environment, and run statistical tests for a while before generating your pads. The rng-tools package on Linux has a test tool. Make sure you disconnect the test wires before generating the pads though!
- tptacek 4y agoI don't think you can verify the safety of a one-time pad with statistical tests.
- josephg 4y ago> By the time you add all the whitening and that sort of thing to make those problems go away I'm not sure how the information theory proofs hold up. Why wouldn't the information theory proofs hold up? Fun puzzle: Suppose I give you coin you can flip with some bias (weight). Maybe 75% of coin flips are heads. Maybe its 65%. You don't know. You want to generate a sequence of bits with uniform randomness (exactly 50%). Without first sampling the coin & calculating the bias, how do you generate the uniform sequence of bits? The answer to that puzzle would probably work fine for your theoretical one time pad. Also, in practice I suspect most of the obvious ways your random noise circuit could be broken could be detected using statistical methods. You can't use math to prove a random number generator is truly random. But you can certainly detect a lot of common failure modes of "random" number sources.
- fdupress 4y agoRejection sampling works when your bias is constant, not when it varies depending on the environment.
- 4y ago
- Vecr 4y agoGetrandom(0) on the latest Linux kernel, assuming the computer is used for a while first (as there's no real way to figure out how much entropy is "enough") is probably fine for actual one time pads. I think it's very unlikely that any future attacks could pwn ChaCha20 (and Blake2s) to that extent. You would have to figure out were you were in the stream, and with what key (possibly multiple keys). That's pretty close to zero information in cryptanalysis terms. You would need to make sure the computer generating the pads, as well as the printers, etc. Are well shielded and not emitting usable EM information, don't store the pads in any way, and are not compromised beforehand in some way, such as a supply chain attack.
- tptacek 4y agoIf you trust ChaCha20 and Blake2s this way, you should just use them. Most of the point of a one-time pad is not having to trust algorithms like these. (In reality, just forget that one-time pads exist).