Insufficient Cryptographic Key Size

Insufficient cryptographic key size in C#

Description

Using keys below the recommended minimum size in RSA, DSA, or symmetric cryptography can make them vulnerable to brute-force or mathematical attacks.

Potential impact

  • Increased risk of ciphertext decryption, forged signatures, and authentication bypass.

Remediation

Choose key sizes for the required security level, starting with at least 2048 bits for RSA and finite-field DH, and at least 128 bits for modern symmetric algorithms. FIPS 186-5 permits DSA only for verifying existing signatures; use another approved algorithm to generate new signatures.

Examples

Before

csharp
using var rsa = new RSACryptoServiceProvider(1024);

After

csharp
using var rsa = new RSACryptoServiceProvider(2048);

Explanation:

  • Before: Small RSA, DSA, DH, or symmetric keys can make cryptographic protection easier to break.
  • After: The example increases the RSA key size to 2048 bits. Key size alone does not replace appropriate algorithm selection and an overall security policy.

References