Sunday, October 30, 2016

Symmetric Block Ciphers

So, here is a partial list of symmetric block ciphers available in Bouncy Castle :
  • RC5 has 64 bit block size and 128 bit key size
  • Blowfish has 64 bit block size and 1 to 448 bit key size
  • AES has 128 bit block size and 128, 192, 256 bit key sizes
  • RC6 has 128 bit block size and 128, 192, 256 bit key sizes
  • Serpent has 128 bit block size and 128, 192, 256 bit key sizes
  • Twofish has 128 bit block size and key sizes up to 256 bits



You will certainly need a byte array for a Key, and a SecretKeySpec object to convert this byte array to a form acceptable to the Cipher object that does the actual encryption and decryption of your Input. The Key byte array doesn't need to be the same length as the Cipher block size, but must be a length acceptable to the Cipher. Note the above ciphers all have both a block size and acceptable key sizes.

Any of the above block ciphers without additional processing only securely encrypts a single block. To securely encrypt larger amounts of input, encryption Modes have been developed that use the encrypted results of the current block to additionally secure the following block.

Obviously an initial block must be available to securely encrypt the first block of actual input. This block is called the Initialization Vector (IV). It can be explicitly provided, or derived from the password or from looking ahead in the input.

CBC (Cipher Block Chaining) is a commonly used mode that uses an explicitly provided random byte block as the IV. Nothing has to be communicated to the receiver for decryption, the first block of the decrypted message is discarded and the remainder is the original message. CBC requires the input to be padded if necessary to be modulo 0 block size.



For Symmetric Block Ciphers to work at all, both parties must agree on the Cipher, the Mode, and the Key byte array.

Technically there is no reason that once established any of these need to be changed. However as a matter of policy, since the Key byte array may somehow become compromised, they are often changed on a schedule. Then a secure means must be found to communicate the new key to the other party.



No comments: