Hacker News

Se ke oa fetisa li-block ciphers tse nyane

Se ke oa fetisa li-block ciphers tse nyane Tlhahlobo ena e felletseng ea pasa e fana ka tlhahlobo e qaqileng ea likarolo tsa eona tsa mantlha le litlamorao tse batsi. Libaka tsa Bohlokoa tsa Tsepamiso Lipuisano li shebane le: Mekhoa ea mantlha le lits'ebetso ...

10 min read Via 00f.net

Mewayz Team

Editorial Team

Hacker News

Li-block ciphers tse nyane ke symmetric encryption algorithms e sebetsang ho li-block tsa data tsa 64 bits kapa ka tlase ho moo, 'me ho utloisisa matla le mefokolo ea tsona ho bohlokoa bakeng sa khoebo efe kapa efe e sebetsanang le data ea bohlokoa. Le hoja litsamaiso tsa lefa li ntse li itšetlehile ka tsona, litekanyetso tsa sejoale-joale tsa ts'ireletso li ntse li hloka mokhoa oa leano oa khetho ea li-cipher tse leka-lekaneng ho lumellana, ts'ebetso, le ho pepeseha ha kotsi.

Hantle-ntle Li-block Ciphers tse Nyenyane ke Hobaneng ha Likhoebo li Lokela ho Hlokomela?

Block cipher encrypts likotoana tsa boholo bo sa fetoheng tsa plain text hore e be ciphertext. Li-block cipher tse nyenyane—tse sebelisang boholo ba li-block tse 32 ho isa ho tse 64—e ne e le tsona tekanyetso e ka sehloohong ka lilemo tse mashome. DES, Blowfish, CAST-5, le 3DES kaofela li oela sehlopheng sena. Li entsoe nakong eo lisebelisuoa tsa khomphutha li neng li haella, 'me boholo ba liboloko tsa tsona tse kopaneng li ne li bontša litšitiso tseo.

Bakeng sa likhoebo kajeno, tšebelisano ea li-block ciphers ha se thutong. Sistimi ea likhoebo, lisebelisoa tse kentsoeng, lisebelisoa tsa libanka tsa khale, le litsamaiso tsa taolo ea indasteri hangata li sebelisa li-ciphers tse kang 3DES kapa Blowfish. Haeba mokhatlo oa hau o sebelisa e 'ngoe ea maemo ana - kapa o hokahana le balekane ba o sebelisang - o se o le ka har'a tikoloho e nyane ea block cipher, ho sa tsotellehe hore na ua elelloa kapa che.

Taba ea mantlha ke seo litsebi tsa li-cryptographs li se bitsang tlamo ea letsatsi la tsoalo. Ka 64-bit block cipher, kamora li-gigabyte tse ka bang 32 tsa data tse kentsoeng ka senotlolo se le seng, monyetla oa ho thulana o nyolohela maemong a kotsi. Libakeng tsa sejoale-joale tsa data moo li-terabyte li phallang lits'ebetsong letsatsi le letsatsi, moeli ona o feta kapele.

Ke Likotsi Tsefe Tsa 'Nete Tsa Tšireletseho Tse Tlanngoeng le Li-Small Block Ciphers?

Likotsi tse amanang le li-block ciphers tse nyane li ngotsoe hantle ebile li sebelisoa ka matla. Sehlopha sa litlhaselo tse hlahelletseng ka ho fetesisa ke SWEET32 tlhaselo, e senotsoeng ke bafuputsi ka 2016. SWEET32 e bontšitse hore mohlaseli ea khonang ho beha leihlo sephethephethe se lekaneng tlas'a 64-bit block cipher (joaloka 3DES ho TLS) a ka fumana tlhaloso e hlakileng ka ho thulana ha letsatsi la tsoalo.

"Tshireletso ha se taba ea ho qoba likotsi tsohle-ke ho utloisisa hore na ke likotsi life tseo u li amohelang le ho etsa liqeto tse nang le tsebo ka tsona. Ho hlokomoloha letsatsi la tsoalo le tlameletsoe ho li-block ciphers tse nyenyane hase kotsi e baloang; ke ho hlokomoloha. "

Ka nqane ho SWEET32, li-block ciphers tse nyane li tobane le likotsi tsena tse tlalehiloeng:

  • Litlhaselo tse thibelang ho thulana: Ha li-blocks tse peli li hlahisa li-blocks tse tšoanang tsa ciphertext, bahlaseli ba fumana temohisiso mabapi le kamano pakeng tsa likarolo tsa data, tse ka hlahisang li-tokens tsa netefatso kapa linotlolo tsa nako.
  • Ho pepeseha ha protocol ea lefa: Li-block ciphers tse nyane hangata li hlaha litlhophisong tsa TLS tse siiloeng ke nako (TLS 1.0/1.1), li eketsa kotsi ea batho ba mahareng ha ho tsamaisoa likhoebo tsa khale.
  • Mathata a ho sebelisa hape: Lits'ebetso tse sa fetoleng linotlolo tsa khomphutha hangata li holisa bothata ba letsatsi la tsoalo, haholo-holo linakong tse nkang nako e telele kapa phetisetso ea data ka bongata.
  • Ho hloleha ho latela melao: Merero ea taolo e kenyeletsang PCI-DSS 4.0, HIPAA, le GDPR hona joale e nyahamisa ka ho hlaka kapa e thibela ka ho hlaka 3DES maemong a itseng, e pepesetsa likhoebo kotsing ea tlhahlobo.
  • Tlhahiso ea ketane ea thepa: Lilaeborari tsa mekhatlo ea boraro le li-API tsa barekisi tse so ka li nchafatsoa li ka buisana ka khutso ka li-block cipher suite, tsa baka likotsi tse kantle ho taolo ea hau.

Li-block Ciphers tse Nyenyane li Bapisoa Joang le Mekhoa e meng ea Sejoale-joale ea Encryption?

AES-128 le AES-256 li sebetsa ho li-block tsa 128-bit, li eketsa makhetlo a mane moeli oa letsatsi la tsoalo ha li bapisoa le 64-bit ciphers. Ka mokhoa o sebetsang, AES e ka patala li-byte tse ka bang 340 pele kotsi ea letsatsi la tsoalo e e-ba kholo-e leng ho felisang matšoenyeho a ho thulana bakeng sa mosebetsi ofe kapa ofe oa sebele.

ChaCha20, mofuta o mong oa sejoale-joale, ke mohala o thibelang mathata a boholo ba block ka botlalo mme o fana ka ts'ebetso e ikhethang ho Hardware ntle le ho potlakisa AES - e etsa hore e be e loketseng bakeng sa tikoloho ea mehala le lisebelisoa tsa IoT. TLS 1.3, tekanyetso ea hajoale ea khauta bakeng sa ts'ireletso ea lipalangoang, e ts'ehetsa ka ho khetheha li-cipher suites tse thehiloeng ho AES-GCM le ChaCha20-Poly1305, e felisang li-block ciphers tse nyane ho tsoa lipuisanong tsa sejoale-joale tse sireletsehileng ka moralo.

Khang ea tšebetso eo pele e neng e rata li-block ciphers tse nyane le eona e putlame. Li-CPU tsa morao-rao li kenyelletsa AES-NI hardware acceleration e etsang hore AES-256 encryption e be kapele ho feta Blowfish e kentsoeng ke software kapa 3DES hoo e batlang e le lisebelisoa tsohle tsa likhoebo tse rekiloeng ka mor'a 2010.

💡 DID YOU KNOW?

Mewayz replaces 8+ business tools in one platform

CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.

Start Free →

Ke Maemo afe a Sebele a Lefatshe a sa ntseng a lokafatsa tlhokomediso ya Block Block Cipher?

Ho sa tsotelehe bofokoli ba bona, li-block ciphers tse nyane ha li so nyamele. Ho bohlokoa ho utloisisa hore na ba phehella hokae bakeng sa tlhahlobo e nepahetseng ea kotsi:

Ho kopanya tsamaiso ea lefa e ntse e le eona taba ea mantlha ea tšebeliso. Libaka tsa Mainframe, SCADA ea khale le litsamaiso tsa taolo ea indasteri, le marang-rang a lichelete a sebelisang software ea lilemo tse mashome hangata a ke ke a nchafatsoa ntle le matsete a bohlokoa a boenjiniere. Maemong ana, karabo ha se ho amohela ka boomo - ke ho fokotsa kotsi ka ho potoloha, ho beha leihlo molumo oa sephethephethe, le ho arola marang-rang.

Litikoloho tse kentsoeng le tse thibetsoeng ka linako tse ling li ntse li rata ho kenya tšebetsong compact cipher. Li-sensor tse ling tsa IoT le lits'ebetso tsa likarete tse bohlale li sebetsa tlasa memori le mathata a ts'ebetso moo esita le AES e sa sebetseng. Li-ciphers tse entsoeng ka morero tse kang PRESENT kapa SIMON, tse etselitsoeng ka ho khetheha bakeng sa lisebelisoa tse thata, li fana ka liprofaele tse betere tsa ts'ireletso ho feta li-ciphers tsa 64-bit maemong ana.

Cryptographic research and protocol analysise hloka ho utloisisa li-block ciphers tse nyane ho lekola hantle libaka tsa tlhaselo litsamaisong tse teng. Litsebi tsa ts'ireletso tse etsang liteko tsa ho kenella kapa ho hlahloba likhokahano tsa mokha oa boraro li tlameha ho tseba mekhoa ena ea ho bua hantle.

Likhoebo li Lokela ho aha Joang Leano la Taolo ea Phatlalatso?

Ho laola liqeto tsa khokahanyo khoebong e ntseng e hola ha se bothata ba tekheniki feela—ke bothata ba tšebetso. Likhoebo tse sebelisang lithulusi tse ngata, lipolanete, le likhokahano li tobane le phephetso ea ho boloka ponahalo ea data e patiloe ka mokhoa o khutsitseng ha o phomola le ha o tsamaea ka har'a mekotla eohle ea bona.

Mokhoa o hlophisitsoeng o kenyelletsa ho hlahloba lits'ebeletso tsohle bakeng sa tlhophiso ea cipher suite, ho qobella bonyane ba TLS 1.2 (TLS 1.3 e ratoang) libakeng tsohle tsa ho qetela, ho beha melaoana ea bohlokoa ea ho potoloha e bolokang linako tsa 64-bit cipher li le khuts'oane ho lekana hore li lule li le ka tlase ho meeli ea matsatsi a tsoalo, le mekhoa ea tlhahlobo ea moaho e kenyelletsang litlhoko tsa tlhahlobo ea barekisi.

Ho kenya tšebetsong khoebo ea hau bohareng ka sethala se kopaneng ho fokotsa ho rarahana ha taolo ea li-cipher haholo ka ho fokotsa palo eohle ea lintlha tse kopanyang tse hlokang tlhahlobo ea ts'ireletso ea motho ka mong.

Lipotso Tse Botsoang Hangata

Na 3DES e ntse e nkuoa e bolokehile hore e ka sebelisoa khoebong?

NIST e ile ea tlohela 3DES ka molao ho fihlela 2023 'me ea e hanela lits'ebetsong tse ncha. Bakeng sa litsamaiso tse seng li ntse li le teng tsa lefa, 3DES e ka amoheleha ka ho potoloha ha linotlolo ka thata (ho boloka lintlha tsa nako e ka tlase ho 32GB ka senotlolo) le litaolo tsa boemo ba marang-rang, empa ho fallela ho AES ho khothaletsoa ka matla le ho hlokoa haholo ke melao ea tsamaiso.

Nka tseba jwang hore na tsamaiso ya ka ya kgwebo e sebedisa di-block ciphers tse nyane?

Sebelisa lisebelisoa tsa ho hlahloba TLS joalo ka tlhahlobo ea li-server tsa SSL Labs bakeng sa liphetho tse shebaneng le sechaba. Bakeng sa lits'ebeletso tsa kahare, lisebelisoa tsa ho lekola marang-rang tse nang le bokhoni ba tlhahlobo ea protocol li ka tsebahatsa lipuisano tsa cipher suite ho sephethephethe se hapiloeng. Sehlopha sa hau sa IT kapa moeletsi oa ts'ireletso a ka etsa tlhahlobo ea cipher khahlanong le li-API, database, le li-server tsa ts'ebeliso ho hlahisa lethathamo le felletseng.

Na ho fetohela ho AES ho hloka hore ke ngole khoutu ea ka hape?

Maemong a mangata, che. Lilaebrari tsa sejoale-joale tsa li-cryptographic (OpenSSL, BouncyCastle, libsodium) li etsa khetho ea cipher phetoho ea tlhophiso ho fapana le ho ngola khoutu bocha. Boiteko ba mantlha ba boenjiniere bo kenyelletsa ho ntlafatsa lifaele tsa tlhophiso, litlhophiso tsa TLS, le tlhahlobo ea hore data e teng e kentsoeng e ka fallisetsoa kapa ea ngolisoa hape ntle le tahlehelo ea data. Lisebelisoa tse hahelletsoeng holim'a meralo ea hajoale hangata li pepesa khetho ea cipher joalo ka paramethara, eseng lintlha tse thata tsa ts'ebetsong.


Liqeto tse encryption tse entsoeng kajeno li hlalosa boemo ba ts'ireletso ea khoebo ea hau ka lilemo. Mewayz e fa likhoebo tse ntseng li hola sethala sa ts'ebetso sa li-module tse 207 - se koahelang CRM, papatso, khoebo ea khoebo, analytics, le tse ling - e hahiloeng ka lisebelisoa tse hlokomelang ts'ireletso, ka hona o ka tsepamisa maikutlo ho holisa ho fapana le ho ts'oara bofokoli holima sesebelisoa se arohaneng. Eba le basebelisi ba 138,000+ ba laolang likhoebo tsa bona ka bohlale ho app.mewayz.com, ka merero e qalang ka $19/khoeli feela.

Try Mewayz Free

All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.

Start managing your business smarter today

Join 30,000+ businesses. Free forever plan · No credit card required.

Ready to put this into practice?

Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.

Start Free Trial →

Ready to take action?

Start your free Mewayz trial today

All-in-one business platform. No credit card required.

Start Free →

14-day free trial · No credit card · Cancel anytime