Description
A cryptographic key that is too short makes it easier for an attacker to decrypt data or forge signatures. This can compromise the confidentiality and integrity of sensitive information.
Potential impact
- Data exposure: An attacker may decrypt sensitive information.
- Data tampering: Weakened integrity protection may allow data to be altered.
- Authentication bypass: Decrypting protected authentication information may undermine authentication controls.
Remediation
- Use strong algorithms with suitable key sizes, such as AES-256 or RSA with at least 2048 bits.
- Follow the recommended minimum sizes:
- AES: at least 128 bits.
- RSA: at least 2048 bits.
- ECC: at least 224 bits. For new systems, prefer P-256 or stronger curves, providing at least 128-bit security strength.
Examples
RSA key generation
Before
python
# Noncompliant RSA key generation with pycryptodome
from Crypto.PublicKey import RSA
key = RSA.generate(1024) # Insufficient key size
After
python
# Compliant RSA key generation with pycryptodome
from Crypto.PublicKey import RSA
key = RSA.generate(3072) # Use at least 2048 bits
Explanation
- Before: A 1024-bit RSA key does not provide the currently recommended strength.
- After: Use at least 2048 bits for RSA; this example uses 3072 bits.
DSA key generation
These excerpts compare key sizes in existing DSA code. FIPS 186-5 permits DSA only to verify existing signatures, not to generate new ones. Do not use this comparison as a recommended configuration for a new signing system.
Before
python
# Noncompliant DSA key generation with pycryptodome
from Crypto.PublicKey import DSA
key = DSA.generate(1024) # Insufficient key size
After
python
# DSA key-size comparison with pycryptodome
from Crypto.PublicKey import DSA
key = DSA.generate(3072) # Use at least 2048 bits
Explanation
- Before: A 1024-bit DSA key is not strong enough.
- Key-size comparison: A 3072-bit key is stronger than a 1024-bit key, but DSA is not recommended for generating new signatures.
ECC key generation
Before
python
# Noncompliant ECC key generation with pycryptodome
from Crypto.PublicKey import ECC
key = ECC.generate(curve="secp192r1") # Insufficient key size
After
python
# Compliant ECC key generation with pycryptodome
from Crypto.PublicKey import ECC
key = ECC.generate(curve="P-256") # Use NIST P-256 for 128-bit security strength
Explanation
- Before: The 192-bit curve
secp192r1falls short of the currently recommended security strength. - After: Use a curve such as
P-256, which provides 128-bit security strength. Ed25519 is used for signatures, so it is not a general encryption-key-size example.