IPSO Data Security
October 12, 2011, IPSO Alliance, Santa Clara, CA–The IPSO Alliance had Witt Diffie talk about data security. Diffie is half of the Difie-Hellman key exchange protocol for encryption.
Technology and cryptography have been on a parallel evolution path since the beginning of the 20th century. When Marconi demonstrated the wireless telegraph, the first users were the naval organizations. When communicating in a war environment, information security is paramount. Unfortunately, cryptography was not easily implemented in the available technologies.
Early in the 1500’s people were working with poly alphabetical ciphers. The elements were a 2-table look-up and some arithmetic. This cipher was automated in a wheel key, where the rotor operated as the table and rotations provided an indexing function.
By 1970, this function evolved into a single key, central control cipher administered by the NSA. Key distribution has always been a challenge going from distributing codes through (suspected) secure channels, to trusted couriers handcuffed to a brief case, etc. As a result, the concept of a public key for encryption came about.
In ’97, AES became an official public key standard, after much work to get approval from NSA and other security agencies. The AES standard is now regarded as adequately secure at a 128-bit level, and any efforts beyond that are unreasonable. Although someone could rent a large server farm and brute force a solution, it probably would take longer than the data had any value to be decrypted.
The NSA has determined that cryptography should be a hard component and not software. One version of a key was called Suite B and was tuned for a strength of 128 to 196 bits. The challenge was to get interoperability across systems. The NSA is continuing to work on public standards for approved levels of security.
Now, they have developed a rotor machine in an IC. This device uses 16-bit rotors and block ciphers. There is no path for plain text in the IC, which uses one pass for authentication and secrecy. The resulting IC is an industrial strength encryption tool.
AES is the most investigated algorithm in cryptography. Their implementation uses about 5 percent of the time and energy of AES, yet still requires between 1080 to 10120 attack vectors. The first uses will be in passive RFID systems.


