Description
A key that is too short for the required security strength leaves less resistance to brute force or algorithm-specific attacks. RSA factorization, elliptic-curve discrete logarithms and symmetric-key searches have different strength estimates, so their bit lengths cannot be compared directly. The practical attack cost depends on the algorithm, key size, implementation and required protection period.
Potential impact
- Recovering a key can compromise encrypted data or the trust placed in signatures.
- Data requiring long-term protection can become more exposed as computing capabilities advance.
- The configuration may fall below an organization's or applicable standard's minimum security strength.
Remediation
- Select an algorithm and key size for the required protection period. As a general baseline, use at least 2048-bit RSA and consider 3072 bits or more for longer-term protection. For EC, use a reviewed curve such as
secp256r1. - AES supports 128-, 192- and 256-bit keys. Choose according to the required strength; a 64-bit AES key is an unsupported setting, rather than a valid but weak key.
- Specify reviewed sizes or curves and a secure random generator when using
KeyPairGeneratororKeyGenerator. Enforce the same minimums for values loaded from configuration. - Plan compatibility with existing ciphertext, certificates and signature verification when replacing keys. Adequate key length does not replace secure modes, key storage or access controls.
Examples
Before
java
import java.security.KeyPairGenerator;
public class WeakKeyExample {
public static void main(String[] args) throws Exception {
// RSA 1024 bits: insufficient baseline
KeyPairGenerator rsa = KeyPairGenerator.getInstance("RSA");
rsa.initialize(1024); // BAD: below the 2048-bit baseline
rsa.generateKeyPair();
}
}
After
java
import javax.crypto.KeyGenerator;
import java.security.KeyPairGenerator;
import java.security.SecureRandom;
import java.security.spec.ECGenParameterSpec;
public class StrongKeyExample {
public static void main(String[] args) throws Exception {
SecureRandom rnd = SecureRandom.getInstanceStrong();
// RSA 3072 bits: above the 2048-bit baseline
KeyPairGenerator rsa = KeyPairGenerator.getInstance("RSA");
rsa.initialize(3072, rnd);
rsa.generateKeyPair();
// Specify the reviewed 256-bit EC curve
KeyPairGenerator ec = KeyPairGenerator.getInstance("EC");
ec.initialize(new ECGenParameterSpec("secp256r1"), rnd);
ec.generateKeyPair();
// AES with a 256-bit key
KeyGenerator aes = KeyGenerator.getInstance("AES");
aes.init(256, rnd);
aes.generateKey();
}
}
The first example generates a 1024-bit RSA key. The second specifies 3072-bit RSA, EC secp256r1 and 256-bit AES. Review these choices against the system's strength and interoperability requirements.