3 ms·
The first question I would ask is: what attacks are you trying to defend against? Can the attacker eavesdrop on the initial communication? If so, the attacker
by cdman 13y ago
The first question I would ask is: what attacks are you trying to defend against? Can the attacker eavesdrop on the initial communication?
If so, the attacker has all the needed information.
If the initial channel is assumed to be protected against eavesdropping, why can't the same channel be used on follow-up communications or perhaps the initial communication used to set up a shared secret and use it to encrypt later communications.
So the main question would be: what is your goal with this algorithm? Simply to construct encryption schemes using hash functions? (since the reverse has been done - given a block cypher like AES you can construct hash functions, just not very good ones).
- aruggirello 13y agoYou are right: the goal of this algorithm is to construct an alternative encryption/decryption scheme using a cryptographically secure hash, and exclusive or. So I'm trying to look for possible weaknesses in the scheme, e.g.: would it be safe to store (random-padded) plain text this way (vs. should it be compressed)? Since the encrypted messages are xor'ed with a (binary) hash, would they be exposed to attacks such as byte-by-byte crypto-analysis? And, how does simple xor compare against the classical power/modulus math in this respect - considering the random-like context and short length of a single, cryptographically secure hash? Finally, should the algorithm be proven too weak, we might choose to substitute he = xor(hb,m) with e.g.: e = AES_encrypt(hb, m).