Feeds

128-bit crypto scheme allegedly cracked in two hours

Boffins splat 'supersingular curve' crypto

Security for virtualized datacentres

Crypto researchers are preparing to scatter the ashes of a class of Discrete Logarithm Problems (DLPs) as the future of security, following a claim by Swiss researchers to have cracked a 128-bit crypto scheme in two hours.

So as not to frighten the horses, The Register will start by pointing out that our understanding of this paper at Arxiv doesn't mean the schemes you're now using have been broken. Rather, the work by researchers at EPFL in Switzerland excludes crypto based on “supersingular curves” from future consideration.

As the Lausanne-based polytechnic states in its media release, “Whereas it was believed that it would take 40,000 times the age of the universe for all computers on the planet to do it”, the supersingular curve DLP algorithm only lasted two hours on the 24-core cluster used to crack it.

Authored by Robert Granger and Thorsten Kleinjung of EPFL's LACAL (Laboratory for Cryptologic Algorithms) and Jens Zumbrägel of TU Dresden, the paper says this about the cracking of supersingular curves:

“When initially proposed, these fields were believed to be 128-bit secure, and even in light of the recent algorithmic advances, were believed to be 128-bit and 94.6-bit secure. On the contrary, we have shown that the former field has only59 bits of security and we have implemented a total break of the latter. Since asymptotically more efficient techniques can be brought to bear as bit lengths increase, we conclude that small characteristic pairings at all security levels should now be regarded as completely insecure.”

Their results are to be presented at IACR Crypto 2014 conference. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.