Insufficient cryptographic key size

Insufficient cryptographic key size

Description

A cryptographic key that is too short makes it easier for an attacker to decrypt data or forge signatures. This can compromise the confidentiality and integrity of sensitive information.

Potential impact

  • Data exposure: An attacker may decrypt sensitive information.
  • Data tampering: Weakened integrity protection may allow data to be altered.
  • Authentication bypass: Decrypting protected authentication information may undermine authentication controls.

Remediation

  • Use strong algorithms with suitable key sizes, such as AES-256 or RSA with at least 2048 bits.
  • Follow the recommended minimum sizes:
    • AES: at least 128 bits.
    • RSA: at least 2048 bits.
    • ECC: at least 224 bits. For new systems, prefer P-256 or stronger curves, providing at least 128-bit security strength.

Examples

RSA key generation

Before

python
# Noncompliant RSA key generation with pycryptodome
from Crypto.PublicKey import RSA

key = RSA.generate(1024)  # Insufficient key size

After

python
# Compliant RSA key generation with pycryptodome
from Crypto.PublicKey import RSA

key = RSA.generate(3072) # Use at least 2048 bits

Explanation

  • Before: A 1024-bit RSA key does not provide the currently recommended strength.
  • After: Use at least 2048 bits for RSA; this example uses 3072 bits.

DSA key generation

These excerpts compare key sizes in existing DSA code. FIPS 186-5 permits DSA only to verify existing signatures, not to generate new ones. Do not use this comparison as a recommended configuration for a new signing system.

Before

python
# Noncompliant DSA key generation with pycryptodome
from Crypto.PublicKey import DSA

key = DSA.generate(1024)  # Insufficient key size

After

python
# DSA key-size comparison with pycryptodome
from Crypto.PublicKey import DSA

key = DSA.generate(3072) # Use at least 2048 bits

Explanation

  • Before: A 1024-bit DSA key is not strong enough.
  • Key-size comparison: A 3072-bit key is stronger than a 1024-bit key, but DSA is not recommended for generating new signatures.

ECC key generation

Before

python
# Noncompliant ECC key generation with pycryptodome
from Crypto.PublicKey import ECC

key = ECC.generate(curve="secp192r1") # Insufficient key size

After

python
# Compliant ECC key generation with pycryptodome
from Crypto.PublicKey import ECC

key = ECC.generate(curve="P-256") # Use NIST P-256 for 128-bit security strength

Explanation

  • Before: The 192-bit curve secp192r1 falls short of the currently recommended security strength.
  • After: Use a curve such as P-256, which provides 128-bit security strength. Ed25519 is used for signatures, so it is not a general encryption-key-size example.

References