Insufficient cryptographic key size

Choose cryptographic key sizes that meet the required security strength

Description

A key that is too short for the required security strength leaves less resistance to brute force or algorithm-specific attacks. RSA factorization, elliptic-curve discrete logarithms and symmetric-key searches have different strength estimates, so their bit lengths cannot be compared directly. The practical attack cost depends on the algorithm, key size, implementation and required protection period.

Potential impact

  • Recovering a key can compromise encrypted data or the trust placed in signatures.
  • Data requiring long-term protection can become more exposed as computing capabilities advance.
  • The configuration may fall below an organization's or applicable standard's minimum security strength.

Remediation

  • Select an algorithm and key size for the required protection period. As a general baseline, use at least 2048-bit RSA and consider 3072 bits or more for longer-term protection. For EC, use a reviewed curve such as secp256r1.
  • AES supports 128-, 192- and 256-bit keys. Choose according to the required strength; a 64-bit AES key is an unsupported setting, rather than a valid but weak key.
  • Specify reviewed sizes or curves and a secure random generator when using KeyPairGenerator or KeyGenerator. Enforce the same minimums for values loaded from configuration.
  • Plan compatibility with existing ciphertext, certificates and signature verification when replacing keys. Adequate key length does not replace secure modes, key storage or access controls.

Examples

Before

java
import java.security.KeyPairGenerator;

public class WeakKeyExample {
    public static void main(String[] args) throws Exception {
        // RSA 1024 bits: insufficient baseline
        KeyPairGenerator rsa = KeyPairGenerator.getInstance("RSA");
        rsa.initialize(1024); // BAD: below the 2048-bit baseline
        rsa.generateKeyPair();

    }
}

After

java
import javax.crypto.KeyGenerator;
import java.security.KeyPairGenerator;
import java.security.SecureRandom;
import java.security.spec.ECGenParameterSpec;

public class StrongKeyExample {
    public static void main(String[] args) throws Exception {
        SecureRandom rnd = SecureRandom.getInstanceStrong();

        // RSA 3072 bits: above the 2048-bit baseline
        KeyPairGenerator rsa = KeyPairGenerator.getInstance("RSA");
        rsa.initialize(3072, rnd);
        rsa.generateKeyPair();

        // Specify the reviewed 256-bit EC curve
        KeyPairGenerator ec = KeyPairGenerator.getInstance("EC");
        ec.initialize(new ECGenParameterSpec("secp256r1"), rnd);
        ec.generateKeyPair();

        // AES with a 256-bit key
        KeyGenerator aes = KeyGenerator.getInstance("AES");
        aes.init(256, rnd);
        aes.generateKey();
    }
}

The first example generates a 1024-bit RSA key. The second specifies 3072-bit RSA, EC secp256r1 and 256-bit AES. Review these choices against the system's strength and interoperability requirements.

References