# encryption algorithm (urgent)

Posted on 2003-11-24
Medium Priority
458 Views
yo im making my own (stream) encryption algorithm which is basically

for 0<=x<=length of text to be encrypted

text character(x) is xored by every pass character in turn

text character(x) is xored by the length of the entire password

text character(x) is xored by 1 pass character which rotates (i.e. the x th pass character mod the length of the password)

my problem is: if the password is longer than the text, the order of the excess of the password does not matter i.e.

text: ab
pass: 12345678

the incorrect pass: 12876543 will sucessfully decrypt the ciphertext :(

plz list ANY ideaz coz i really need to have this finished REALLY soon

thankz

suma
0
Question by:suma_ds
LVL 22

Expert Comment

ID: 9815609
If the text to be encrypted is shorter than the key, why not pad the text out?

Or, consider the following.  So short a piece of plain text, in and of itself, should never carry much import, as a brute force and ignorance attack is quickly successful.  For example, not even the greenest security officer would every condone such a short, say, password for even the least userid.

LVL 1

Author Comment

ID: 9815705
ok i have tried padding the text but this does not increase security,  for example

text: abcd

pass: 12345678

incorrect pass: 12348765

plaintext produced from decrypting with incorrect pass: abcdXXXX (X stands for any character)

this does not solve the problem coz it will be very obvious that the X's are just padding

LVL 22

Accepted Solution

cookre earned 500 total points
ID: 9815821
Hence the comment about little security for short plain text.

Now, if the recipient knows the good part is just, in this case, two bytes, and the cracker doesn't, padding with randomized instances of the plain text (e.g., abbbabaa) would make the crackers life a tad more difficult.

<justthinkingoutloud>
I wonder if you'd have the same problem with something like:

a <- leftcircularshift(a,1)

a <- leftcircularshift(a,1)

a <- leftcircularshift(a,1)

with the decrypt being:

a <- rightcircularshift(chunk,1)

a <- rightcircularshift(a,1)

a <- rightcircularshift(a,1)
</justthinkingoutloud>
LVL 84

Expert Comment

ID: 9815852
xoring with a password is a very weak encryption system even whenmodified to avoid the above problems
Here is a list of some stronger encryption algorithms
http://www.ssh.fi/support/cryptography/algorithms/symmetric.html
LVL 1

Author Comment

ID: 9816103
thankz cookre... that should work heaps good :)
