5 ms·
OTPs are not vulnerable to anything except compromise of the OTP itself (the pre-shared keystream).
by harshreality 1y ago
OTPs are not vulnerable to anything except compromise of the OTP itself (the pre-shared keystream).
- WalterBright 1y agoOf course. And that's why one shouldn't rely on a single layer of encryption. With 1940s technology, generating a practical one time pad generator would have been an interesting engineering project. I would have simply used a newspaper. Even if your enemy knew you were using Die Zeitung, with the computer technology at the time it would have been tough to brute force which date and which article was used.
- mannykannot 1y agoI don’t know much about encryption, but I can see a couple of concerns about such a scheme. The first is that such keys will have all the statistical regularities of the German language, which I believe is problematic, even though I don’t know how one would go about exploiting it. The second is the matter of how much encrypted text had to be transmitted every day, by the German military as a whole. If it significantly exceeded the daily output of Germany’s newspapers (and I would guess it did) there would seem to be considerable key reuse under this scheme. For submarines and other units not receiving newspapers daily, there also seems to be a key-distribution issue. I don’t know if there is a better way to guarantee that communication can be maintained through a patrol than to depart with the equivalent of a stack of old newspapers. Is this a problem? I don’t know, but if the allies had figured out the broad outlines of the scheme, I imagine they might be able to do some preparation in anticipation of messages being intercepted.
- WalterBright 1y agoBy itself, yes, the newspaper would not be a great one time pad. But in conjunction with Enigma, it could be enough to make it not practical to brute force Enigma with the available compute technology.
- mannykannot 1y agoI feel it is important to recognize that schemes like this are not OTP, and drawing an analogy between the two risks inducing false intuitions. This discussion started with a proposal to back up Enigma with one-time pads, but harshreality pointed out that OTPs are not vulnerable to anything except compromise of the OTP itself. This has the unstated corollary that if you are using a true OTP system, adding Enigma to the process does nothing to improve security (unless your pre-shared keystream is compromised - and even then, capturing one U-boat's OTP will not compromise any other's communication.) You then raised the concern of generating keys in sufficient quantity, which is certainly part of the problem (though I suspect that an electro-mechanical solution for that problem was well within the capabilities of contemporary technology, especially as, by then, Konrad Zuse had produced the first digital computer.) If, however, we are restricting our source of keys to the amount of text in a daily newspaper (or even all of the Third Reich's daily newspapers combined), that is something that could be achieved by a corps of dice-rollers, if it came to that, which would avoid one of the other problems of using newspapers: the statistical regularities of newspaper text. Even then, you still have the problems of key reuse [1] and key distribution, and another which I think might be by far the hardest: training people to use it. Even just considering the submarine fleet, at least one person on each U-boat would have to be trained in properly using the technique. This would delay implementation, and once deployed, even with no mistakes, it would be slow in use. Alternatively, a machine to do the work might have been developed (together with another to generate physical machine-readable keys), but that itself would have meant considerable delays in implementation. In view of this, I feel that the measure actually adopted - adding another rotor position to the Enigma machine - was one of the better options (though it would have been even better if the additional rotor were interchangeable with the others.) This took time to implement and was ultimately defeated, but anything other than an OTP system would likely have the latter problem, and all would have had the former. [1] Maybe not so much of an issue if one is only dealing with submarine communication, given that most of this was with the U-boat High Command in Germany, and assuming that it was of sufficiently low volume for each U-boat to be be given its own unique set of keys for each patrol.
- WalterBright 1y ago
- peddling-brink 1y agoThis was part of the plot of Cryptonomicon by Neal Stephenson. In the book they used bingo style mechanical RNGs, by hand.
- adrian_b 1y agoThe method described by you had been in use since the 19th century (typically using a designated book as the one-time pad), but it was cracked at the end of WWI, in 1918, by an American cryptographer, William Frederick Friedman, who was thus the first who has demonstrated that it is not enough for the encryption mask stream to be non-periodic, but it must also be random, otherwise it is still possible to decrypt the message by statistical analysis. This fact proved by Friedman in 1918 has become widely known a few years later, in 1926, when Gilbert Sandford Vernam has published an article "Cipher Printing Telegraph Systems For Secret Wire and Radio Telegraphic Communications" in a journal. While Vernam mentioned the help from Friedman, he gave no details and the works written by Friedman for the education of American cryptographers have remained classified for many decades. Because of this, secure one-time pads have been referred frequently as the Vernam cipher, but this is wrong, as he is not its inventor, but only the first who has mentioned it in the non-classified literature. Vernam (as a Bell Labs engineer) had a very important contribution to cryptography, but of a different kind. He has invented enciphering by modulo-2 sum (a.k.a. XOR), which is cheaper to implement in hardware than the integer addition used previously.
- deleted 1y ago[deleted]
- WalterBright 1y agoYou are correct, but I doubt that computers in WW2 were fast enough to do that job on top of cracking Enigma. Enigma messages had a short duration of having value.