3 ms·
For starters, maybe we should ask why Mitro is only using 128bit AES (stated in their PDF design doc)?
by timonel 12y ago
For starters, maybe we should ask why Mitro is only using 128bit AES (stated in their PDF design doc)?
- helper 12y agoPlease see the answer by cryptographer Thomas Pornin on AES 128 vs 256: http://security.stackexchange.com/questions/14068/why-most-people-use-256-bit-encryption-instead-of-128-bit http://security.stackexchange.com/questions/14068/why-most-p...
- AaronFriel 12y agoAES-256 is not the most secure variant of AES any longer, as it appears that variant with key extension improves certain types of attacks. One of those, called a related key attack, requires only 2^119 time against AES-256, and 2^172 time against AES-192. (Time against AES-128 is approximately 2^128, I'd wager about 2^126-127). This is a very particular kind of attack, however, and it doesn't necessarily mean other weaknesses will be exposed. Cryptographers, though, are a conservative sort by nature, and many feel more comfortable sticking with AES-128, which was part of the original Rijndael specification and what was designed most rigorously. AES-128 also seems to have had the fewest weaknesses developed against it. The fact that any attack succeeded in reducing AES-256 to below AES-128's security can give crypto folks pause. I think realistically they are all very safe and AES-128 is unlikely to be broken by anything within the next decade. After that? I wouldn't wager.
- nightcracker 12y agoBecause it's the most secure.