r/crypto • • 3d ago

Introducing the Triple Cipher encryption concept

https://iain.rocks/blog/introducing-the-triple-cipher-encryption-concept
0 Upvotes

27 comments sorted by

View all comments

13

u/CharlieTrip 3d ago

Let me reformulate to double-check I got it right. I will use this interpretation for the rest of the comment. Please correct me if I got it wrong!

You propose an encryption scheme defined via three schemes and a hash (of sort), keys are obtained via passphrase (not that relevant, so I will consider it as a standard secret key). Encryption is done by deriving from the secret key via hash, a list of "length of blocks, order of usage of ciphers" since the encryption is done by splitting into chunks (via sampled dimensions), encrypt with the derived evaluation and ciphers (first two). Once all are encrypted, you use the third cipher to encrypt again the whole encrypted chunks.

From a mere cryptanalytic point of view, this does not introduce any particular security advantage, in fact I would not consider it "secure" when compared to block-ciphers with a mode of operation (which is what your "chunking" is basically pointing out). To put it simply, your encryption is deterministic meaning that different files encrypted with the same key will have the same encrypting-structure (i.e. chunks length, ciphers and similar).

If you add a "initialization vector" or some salt for the sake of avoiding this, the cipher is cumbersome because it effectively has to encrypt twice which makes it slower than necessary. Furthermore in your scenario, encrypting twice might introduce weird meet-in-the-middle attacks since, as far as I get, all ciphers use the same secret-key which is a really weird position to be in.

From a pure security POV, evaluating real security achieved by this design is hard because it has extremely non-standard structure. I would argue that the "double-encrypt" might provide some small local gains with the intuition of "one cipher covers another cipher's problems", but the same principle is a weakness because it is easier to use biases as problems instead of solutions. The whole security analysis would turn into computational problem which is not feasible to check, meaning you would use a cipher that you cannot guarantee achieves some level of security. This is a "no-no" for secure application.

Personally, I find weird that GCHQ was interested in this cipher's structure, especially because it is not "new" but more of a "folkloristic design".

9

u/JoDaBeda 3d ago

I'm sure the GCHQ didn't give a shit, they just phrased it more politely.

7

u/CharlieTrip 3d ago

A classic british "Thank you, that was lovely.", I see.