Fujitsu Cracks Next-Gen Cryptography Standard
judgecorp writes "Fujitsu and partners have cracked a cryptogram which used 278-digit (923 bit) pairing-based cryptography. The technology was proposed as a next-generation standard, but Fujitsu cracked it, at this level in just over 148 days using 21 personal computers."
Reader Thorfinn.au adds a snippet from Fujitsu's announcement of the break: "This was an extremely challenging problem as it required several hundred times computational power compared with the previous world record of 204 digits (676 bits). We were able to overcome this problem by making good use of various new technologies, that is, a technique optimizing parameter setting that uses computer algebra, a two dimensional search algorithm extended from the linear search, and by using our efficient programing techniques to calculate a solution of an equation from a huge number of data, as well as the parallel programming technology that maximizes computer power."
forsty piss!
Frosty piss
148 PCs * 21 days is around ten years of PC time. Not much in the grand scheme of things.
See my journal for slashdot ID's by year. Mine created in 2005. http://slashdot.org/journal/289875/slashdot-ids-by-year
The real story is going to be how something with (apparently) severe weaknesses became anyone's pet new crypto standard.
This article makes very little sense to me. They don't mention what the crypto algorithm was or who was pushing it as the "next gen standard". I don't know of any proposed cryptographic standard with 923 bit anything.
The odds are 1 in whatever gazillion that the first thing you try will be the right thing.
the CIA/FBI/NSA with a trillion dollar budget can't even crack 128bit AES...
Nearly four months ago, I noticed that my internet connection was very sluggish. Eventually getting fed up with it, I began to seek out software that would speed up the gigabits in my router. After an hour of searching, I found what at first appeared to be a very promising piece of software. Not only did it claim it would speed up my internet connection, but that it would overclock my power supply, speed up my gigabits, and remove any viruses from my computer! "This is a fantastic opportunity that I simply can't pass up," I thought. I immediately downloaded the software and began the installation, all the while laughing like a small child. I was highly anticipating a future where the speed of my internet connection would leave everyone else's in the dust.
I was horribly, horribly naive. Immediately upon the completion of the software's installation, various messages popped up on my screen about how I needed to buy software to remove a virus that I wasn't aware I had from a software company I'd never once heard of. The strange software also blocked me from doing anything except buying the software it was advertising. Being that I was a computer whiz (I had taken a computer essentials class in high school that taught me how to use Microsoft Office, and was quite adept at accessing my Facebook account), I was immediately able to conclude that the software I'd downloaded was, in fact, a virus, and that it was slowing down my gigabits at an exponential rate. "I can't let this insanity proceed any further," I thought.
As I was often called a computer genius, I was confident at the time that I could get rid of the virus with my own two hands. I tried numerous things: restarting the computer, pressing random keys on the keyboard, throwing the mouse across the room, and even flipping an orange switch on the back of the tower and turning the computer back on. My efforts were all in vain; the virus persisted, and my gigabits were running slower than ever! "This cannot be! What is this!? I've never once seen such a vicious virus in my entire life!" I was dumbfounded that I, a computer genius, was unable to remove the virus using the methods I described. Upon coming to terms with my failure, I decided to take my computer to a PC repair shop for repair.
I drove to a nearby computer repair shop and entered the building with my computer in hand. The inside of the building was quite large, neat, and organized, and the employees all seemed very kind and knowledgeable. They laughed upon hearing my embarrassing story, and told me that they saw this kind of thing on a daily basis. They then accepted the job, and told me that in the worst case, it'd be fixed in three days from now. I left with a smile, and felt confident in my decision to leave the computer repairs to the experts.
A week later, they still hadn't called back. Visibly angry, I tried calling them countless times, but not a single time did they answer the phone. Their negligence and irresponsibility infuriated me, and sent me into a state of insanity that caused me to punch a gigantic hole in the wall. Being that I would require my computer for work soon, I decided to head over to the computer repair shop to find out exactly what the problem was.
Upon entering the building, I was shocked by the state of its interior; it looked as if a tornado had tore through the entire building! Countless broken computers were scattered all about the floor, desks were flipped over, the walls had holes in them, there was a puddle of blood on the floor, and worst of all, I saw that my computer was sitting in the middle of the room laying on its side! Absolutely unforgivable! I soon noticed one of the employees sitting behind one of the tipped over desks (the one that had previously had the cash register on top of it); he was shaking uncontrollably and sobbing. Despite being furious about my computer being tipped over, seeing him in that state still managed to make me less unforgiving. I decided to ask him what happened.
A few moments passed where the entire r
Given how long it takes for something to go from 'new' to 'common' and from 'common' to 'deprecated' and from 'deprecated' to 'finally dead, thank god'(and, for the spooks out there, the fact that storage is cheap and certain decade or decades-old messages may still be interesting...), the idea that anything only a few powers of ten away from trivial crackability was even being considered seems like a Very Bad Thing.
252 cores is pretty tiny by the standards of a reasonably motivated attacker. Aside from botnets, 12 cores/1U is relatively cheap commodity gear at this point. Even without springing for the fancy high-density stuff, you could shove 3 times that, with room for switches, into a rack. Toasty, sure, but possible.
NICT has an arguably better press release of the same partnership - it goes in just a little detail (which is better than almost none from Fujistsu)
http://www.nict.go.jp/en/press/2012/06/18en-1.html
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in danger. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why they sounded so frustrated and pathet
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in danger. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why they sounded so frustrated and pathet
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in danger. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why they sounded so frustrated and pathet
My ROT14 is still going strong.
Yes, ROT14. Nobody would ever suspect ROT13+1.
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in danger. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why they sounded so frustrated and pathet
About six months ago, I was overexerting myself trying to get rid of a terrible virus on a client's PC (I own a PC repair shop and have been fixing computers for over 10 years). Given my level of expertise, I thought I'd be able to get rid of it fairly quickly and without hassle, but as was made evident by my colossal failure, I was horribly, horribly wrong.
I couldn't remove the virus no matter what method I used. I tried all the latest anti-virus software and all the usual tricks, but it was all in vain. Failure after failure, my life was slowly being sucked away as I spent more and more of my time trying to get rid of this otherworldly virus.
Frustrated and stressed by my own failure, I began distancing myself from my wife and children. After a few days, I began verbally abusing them, and it eventually escalated into physical abuse. I was slowly losing what remaining sanity I had left. If this had continued for much longer, it is highly probable that I would have committed suicide. A mere shell of what I once was, I barricaded myself in my bedroom and cried myself to sleep for days on end.
That's when it happened: I found MyCleanPC! I installed MyCleanPC right on the client's PC, ran a scan, and it immediately got rid of all the viruses without a single problem. MyCleanPC accomplished in record time what I was unable to accomplish after a full week. Wow! Such a thing!
MyCleanPC is outstanding! My client's computer is running faster than ever! I highly recommend you install MyCleanPC right this minuteness, run a scan, and then boost your PC speed in record time! MyCleanPC came through with flying colours where no one else could!
My client's response? "MyCleanPC totally cleaned up my system, and increased my speed!" All the PC repair professionals are using MyCleanPC to solve all of their problems. This should be reason enough for you to switch to MyCleanPC! It'll speed up your computer, rid it of all viruses, and you'll be able to work productively again! Wow!
Even if you're not having any obvious computer problems, you could still be in danger. That's why I very highly recommend that you still use MyCleanPC. After all, it will boost your PC & internet speed to levels you never would think are possible!
MyCleanPC: For a Cleaner, Safer PC.
-----------
A few weeks ago, I foolishly ran a strange executable file that one of my acquaintances sent me by email. As someone who doesn't know much about computers, at the time, I thought nothing of it. "Why would my acquaintance want to hurt me?" Following this line of thought, I ran the file without question.
How naive I was. Despite having what was supposedly the best anti-virus software out right then, a virus took over my computer and held it hostage. It was pretending to be a warning from Windows telling me to buy some strange anti-virus software I'd never heard of from a company I'd never heard of to remove the virus.
This immediately set alarm bells off in my head. "How could this happen? My anti-virus is supposed to be second to none!" Faced with this harsh reality, I decided to take it to a PC repair shop for repair. They gladly accepted the job, told me it'd be fixed in a few days, and sent me off with a smile.
A few days later, they called me and told me to come pick up my computer. At the time, I noticed that they sounded like whimpering animals, but I concluded that it must just be stress from work. When I arrived, they, with tears in their eyes, told me that the virus was so awful and merciless that they were unable to remove it. "Ah," I thought. "That must be why they sounded so frustrated and pathet
Where are all the people who are saying that it takes millions of years to crack encryption? What, this shit is useless afterall?
The US just built the world's fastest supercomputer.
As all current x86, many ARM and other processors include AES hardware for encoding/decoding.
They'll never clean that mess up... That just means even more contamination going into the ocean
Pairing based cryptography is a relatively new kind of crypto that can be thought of as public-key plus some extra useful properties (makes Identity Based Encryption possible for instance). It does not say in the article which particular scheme they are using, but one of the big ones is Boneh-Franklin. Just as the security of RSA is based on the hardness of factoring, most pairing schemes are based on the hardness of something called the Bilinear Diffie-Hellman problem.
It may be tempting to deride this scheme for the fact that it was broken so quickly, but there are extenuating circumstances to consider. Unlike a symmetric cipher like AES, where an arbitrary key is essentially just as good as any other key, asymmetric ciphers have a much more nuanced keyspace. To start with, not every value in the keyspace can actually be used as a key. Using AES as an example again, you can choose any 128-bit value and it will work as a key for AES-128. In contrast, for RSA to work the key (modulus) must be a product of two large primes. In the space of all 1028-bit numbers, there are many such numbers but they are very sparsely distributed. This means that you need a much larger key size for RSA than AES to get the same amount of security. To complicate things further, the two factors cannot be too close together (lest they be broken with Fermat's factorization algorithm) nor can they be one larger than a number with many small factors (broken by Pollard's p-1 algorithm). In short, there are many things to consider and, although it is accepted that larger keys will be more secure, it is often not straightforward to figure out exactly how large a key should be to provide adequate security.
Now, the reason I digressed a bit there was to show that, although asymmetric encryption has proven security (which widely used block ciphers do not), it is often difficult to judge how secure certain keys and key sizes are without years or decades of researchers examining the cipher. Pairing based cryptography is a relatively new field and it is quite possible that researchers have underestimated the key size needed for adequate security, even though the underlying system is still secure. The information given in the article seems to point to that as being the case since they have not discovered any major theoretical break, only a way to speed up checking of possible keys.
This is as much a feat as those RSA factoring challenges are. Which is to say, interesting incremental progress, but not a big surprise to cryptographers.
They broke discrete logarithm over F(3^(6*97)), which would allow an attack on a pairing-based crypto scheme with an elliptic curve over F(3^97). The (well-known) existence of such attacks, and the excellent fit offered by certain F(p) curves, are why most cryptographers don't use those fields. Still, you can find implementations, such as http://homepage1.nifty.com/herumi/crypt/pairing.html. The most common implementations these days use 256-bit prime fields with 3072-bit output, or something of that magnitude. Without a mathematical breakthrough, this attack would take about as long on such a field as factoring a 3072-bit number, or breaking 128-bit AES. The attack on 923 bits was easier than 923-bit factoring, because it is more efficient against F(small^big) than it is against F(big^small).
The size 923 bits is not entirely arbitrary. When using small-prime extension fields, you need to use 2^prime 3^prime to avoid "descent" attacks. The size 97 = 96+1 (with 96 being very composite) might also allow for some sort of speedup, or maybe it's just a computer-convenient sizing thing. So the next size is 3^(101*6), which is about 960 bits of output, but the implementation I linked goes straight to 3^(193*6), double the size.
Pairings really are considered (by cryptographers) as a candidate next-generation cryptosystem, and have been studied in this role for about a decade. They are similar to traditional elliptic-curve cryptosystems, whose security is relatively well understood. The usefulness of pairings mostly isn't because of improved security, but rather because many more protocols can be implemented with them. Fujitsu obliquely references a master-key system called "identity-based encryption", which usually uses pairings (though it can use RSA-style math or lattices as well; the RSA-like systems are much slower; the lattices are much newer and thus edgier, and have huge public keys). They are correct that IBE is more brittle than traditional PKI: compromise the master key and it's game over for everyone. Still, in some situations IBE's brittleness may be outweighed by its usefulness.
For those interested - here's further analysis including commentary from a world-renowned expert on pairing based cryptography - Prof. Dan Boneh at Stanford:
"Variants of the algorithm used in the recent announcement have been known since 1994, and have been considered by researchers in the pairing based cryptography community. The result shows an efficient implementation of the algorithm, but does not change the overall security analysis of pairing based cryptography." – Professor Dan Boneh, Stanford University.
more details here:
http://superconductor.voltage.com/2012/06/understanding-the-recent-fujitsu-discrete-log-calculation.html