Answer Posted / ramkumar
Keys have limited lifetimes for a number of reasons. The
most important reason is protection against cryptanalysis.
Each time the key is used, it generates a number of
ciphertexts. Using a key repetitively allows an attacker to
build up a store of ciphertexts (and possibly plaintexts)
which may prove sufficient for a successful cryptanalysis
of the key value. If you suspect that an attacker may have
obtained your key, the your key is considered compromised .
Research in cryptanalysis can lead to possible attacks
against either the key or the algorithm. For example, RSA
key lengths are increased every few years to ensure that
the improved factoring algorithms do not compromise the
security of messages encrypted with RSA.
Another reason for limiting the lifetime of a key is to
minimize the damage from a compromised key. It is unlikely
that a user will discover that his key has been compromised
by an attacker if the attacker remains "passive."
Relatively frequent key changes will limit any potential
damage from compromised keys. Ford [For94] describes the
life cycle of a key as follows:
key generation and possibly registration for a public key
key distribution
key activation/deactivation
key replacement or key update
key revocation
key termination, involving destruction and possibly
archival
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers
What is the mceliece cryptosystem?
What is luc?
How can we use quantum properties in cryptography ?
What is cryptographic synchronisation?
What is exhaustive key search ?
What is probabilistic encryption?
How to change the location of the Kryptel (Silver Key) program group?
What is multiple encryption?
How to remove the Kryptel (Silver Key) icon from the desktop?
Does encryption of connection strings in web.config file possible? How?
What are the counter and pcbc modes?
Do digital signatures help detect altered documents and transmission errors?
How is an s-box value of AES can be modified? How is it done?
How to change the encrypted file icon?
What is merkles tree signature scheme?