Description
Choose a mode and padding scheme appropriate to the encryption algorithm. Unsuitable choices can expose encrypted data to attack. For example, electronic codebook (ECB) mode turns identical plaintext blocks into identical ciphertext blocks, revealing patterns. Use authenticated encryption such as GCM for AES and padding such as OAEP for RSA encryption; OAEP is not applied to GCM.
Potential impact
- Data exposure: Ciphertext patterns may reveal information about the plaintext.
- Data tampering: Inadequate encryption or authentication settings may allow modified data to be accepted.
- Loss of protection: Attacks against an unsuitable configuration can undermine confidentiality.
Remediation
- For AES, use authenticated modes such as CCM or GCM and verify the authentication tag. Never reuse a nonce with the same key.
- For RSA encryption, use OAEP. OAEP alone does not authenticate the sender; configure any required signature or authentication separately.
- Follow current security guidance when selecting cryptographic settings.
Examples
These excerpts focus on keys and cipher-object construction. Prepare secure keys appropriate to each algorithm. With GCM, handle the ciphertext, nonce and tag together, and reject data when tag verification fails during decryption.
AES ECB / GCM
Before
python
# AES encryption using ECB mode
from Crypto.Cipher import AES
cipher = AES.new(key, AES.MODE_ECB)
After
python
# AES-GCM cipher construction
from Crypto.Cipher import AES
AES.new(key, AES.MODE_GCM) # Use GCM mode.
Explanation
- Before: AES-ECB reveals repeated plaintext patterns by producing identical ciphertext blocks.
- After: The code creates an AES-GCM object. Integrity protection also requires generating a tag during encryption and verifying it during decryption.
RSA RSAES-PKCS1-v1_5 / OAEP
Before
python
# RSA encryption using RSAES-PKCS1-v1_5
from Crypto.Cipher import PKCS1_v1_5
PKCS1_v1_5.new(key)
After
python
# RSA encryption using OAEP
from Crypto.Cipher import PKCS1_OAEP
PKCS1_OAEP.new(key)
Explanation:
- Before: Distinguishable padding errors during RSAES-PKCS1-v1_5 decryption can enable a Bleichenbacher padding-oracle attack.
- After: Use PKCS#1 OAEP for RSA instead.