{"id":12004,"date":"2023-01-06T13:53:43","date_gmt":"2023-01-06T07:53:43","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=12004"},"modified":"2023-01-06T13:53:43","modified_gmt":"2023-01-06T07:53:43","slug":"know-your-vulnerabilities-key-exchange-in-danger","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/know-your-vulnerabilities-key-exchange-in-danger\/","title":{"rendered":"Know Your Vulnerabilities: Key Exchange in Danger"},"content":{"rendered":"<p>The quantum threat is around the corner. You already know that Post-Quantum Cryptography (PQC) is a cost-effective and practical solution. However, modern data communication cryptosystems used in network protocols like SSH and TLS are complicated and typically consist of multiple encryption algorithms working together. Which parts are the most vulnerable and which ones need to be fixed first? Let&#8217;s find out.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-12005  aligncenter\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2023\/01\/Blog-image-1920-\u00d7-1080-px-23-300x169.png\" alt=\"\" width=\"685\" height=\"386\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Public-key cryptosystems date back to the introduction of RSA in 1977. They offer clear advantages compared to their earlier counterparts: unlike symmetric key encryption where both the sender and the receiver share the same key, public-key systems are immune to the key being intercepted during transmission. Additionally, beyond just encrypting data in transit, public-key cryptosystems are used also to authenticate the other party so that you can be sure of their identity.<\/p>\n<p>Because of these advantages, public-key cryptosystems in network protocols like SSH and TLS have dominated the field of data communications since their inception, and there has been no serious challenge to their security&#8230; until now.<\/p>\n<p><strong>Key Exchange aka Key Agreement<\/strong><\/p>\n<p>A typical session with a public-key cryptosystem starts with a key exchange, a critical phase where a server authenticates itself and both parties agree on a secret session key which is then used to encrypt the actual session payload.<\/p>\n<p>Because of its heavy computational requirements, a key exchange algorithm is not used to encrypt the actual payload data, but a symmetric-key algorithm like AES is used instead.<\/p>\n<p>All cryptographic algorithms are based on a mathematically hard problem. And for RSA, this is prime factoring: as we know, multiplication is relatively easy even for large prime numbers, while breaking down the result into its component factors is so hard that even classical supercomputers struggle with it. However, quantum computers excel in prime factoring and finding solutions to the discrete logarithm problem, which also means that they are able to break RSA and classical Diffie-Hellman.<\/p>\n<p>Traditional symmetric ciphers, like AES, are significantly harder to crack with a quantum computer, and AES-128 and above are considered safe for decades to come. However, it doesn&#8217;t help that the payload encryption holds if its secret session key, which is protected by a classical key agreement algorithm, can be compromised.<\/p>\n<p><strong>Quantum Security &amp; Safety <\/strong><\/p>\n<p>To reach quantum security and safety, your efforts should be focused on fixing the key exchange first, because the threat is retroactive.<\/p>\n<p>Then you can concentrate on addressing the authentication keys that will be vulnerable in the future.<\/p>\n<p>This is exactly what the PQC standardization project of the U.S. Department of Commerce&#8217;s National Institute of Standards and Technology (NIST) was created for. NIST has already selected their preferred PQC key encapsulation algorithm, Crystals-Kyber, suitable to be used in the key exchange.<\/p>\n<p>We at SSH have fortified this with the hybrid approach of combining a PQC and a classical ECDH algorithm. All products in our quantum-safe portfolio offer a modernized quantum-safe hybrid key exchange to protect the session key of a well-known and stable symmetric payload encryption algorithm, such as AES.<\/p>\n<p>By subscribing to any quantum-safe product in our portfolio, you also get the full benefit of Crypto Agility &#8211; since we carefully keep our software up-to-date with the latest recommendations, you will always have the most relevant quantum-safe algorithms at your disposal with no additional cost.<\/p>\n<p>Source: <a href=\"https:\/\/www.ssh.com\/blog\/key-exchange-in-danger\">https:\/\/www.ssh.com\/blog\/key-exchange-in-danger<\/a>?<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>The quantum threat is around the corner. You already know that Post-Quantum Cryptography (PQC) is a cost-effective and practical solution. However, modern data communication cryptosystems used in network protocols like SSH and TLS are complicated and&#8230;<\/p>","protected":false},"author":11,"featured_media":12005,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-12004","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12004","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=12004"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/12004\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/12005"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=12004"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=12004"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=12004"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}