Network Working Group M. Leech Request for Comments: 3607 Nortel Networks Category: Informational September 2003Chinese Lottery Cryptanalysis Revisited: The Internet as a Codebreaking Tool
1. Introduction
In 1991, Quisquater and Desmedt [DESMEDT91] proposed an esoteric, but technically sound, attack against DES or similar ciphers. They termed this attack the Chinese Lottery. It was based on a massively-parallel hardware approach, using consumer electronics as the "hosts" of the cipher-breaking hardware.
Leech Informational [Page 1]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003 2. Dangerous SynergyThe combined growth of the Internet, and the unstoppable march of Moore's Law have combined to create a dangerous potential for brute-force cryptanalysis of existing crypto systems.
3. Winner phone home
When a given instance of the worm determines the key, it needs to contact the originator in order to give them the key. It has to do this in such a way as to minimize the probability that the originator will get caught.
Leech Informational [Page 2]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003
Another approach would be to post a (possibly PGP-encrypted) message to several newsgroups, through an anonymous posting service. Similarly, Internet "chat" services like IRC could be used; indeed there's an emerging tradition of using IRC and similar services for real-time, anonymous, control of worms and viruses.
4. Evaluating the threat
Both Internet growth and CPU performance follow a reasonably predictable doubling interval. Performance of computing hardware appears to still be following Moore's Law, in which performance doubles every 1.5 years. Internet growth appears to be following a doubling period of 3 years.
Leech Informational [Page 3]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003
The numbers given above suggest that an undetected attack against MD5, for a reasonable key length, isn't likely in 2002. A successful attack against DES, however, appears to be a near-certainty.
5. Security Considerations
DES has been shown to be weak in the recent past. The success of the EFF machine, described in [EFF98] shows how a massively-parallel hardware effort can succeed relatively economically. That this level of brute-force cryptanalytic strength could be made available without custom hardware is a sobering thought. It is clear that DES needs to be abandoned; in favor of either 3DES or the newer AES [FIPS197].
6. Acknowledgements
John Morris, of Nortel IS, contributed the idea of anonymous newsgroup posting.
Leech Informational [Page 4]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003
Appendix A: Source Code
Leech Informational [Page 5]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003
(int)multiplier);
Leech Informational [Page 6]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003
Normative References
Leech Informational [Page 7]
RFC 3607 Chinese Lottery Cryptanalysis Revisited September 2003
Full Copyright Statement