From: "Frykholm, Niklas" Date: 2001-10-15T18:01:16+09:00 Subject: [ruby-talk:22558] Re: OSSL opinion >Out of interest could you elaborate on what the things noted below >"means": > >> - allows you to plugin any backend (provider) >> >Whats the idea behind this? Whats the main advantages? The idea is that Java specifies an API that is independant of the implementation. Then you can plug-in a particular implementation (called a Cryptographic Service Provider, CSP) without having to change your code. You can have several CSPs installed that provide different algorithms, different speed of implementation, etc. If you then request a "Blowfish" algorithm, Java checks all your CSPs to see if you have someone installed that supports this algorithm. (You can also request to get the algorithm from a particular CSP.) The advantages are flexibility and interoperability. Not only Java does this. Microsoft has a crypto API (MSCAPI) that lets you plug-in a backend, Netscape uses another API (PKCS #11) which lets you change the backend. (As usual, there are many standards to choose from :) I haven't worked with these API's directly and am not sure whether you can have multiple CSPs running simultaneously, as in Java, but you can do such things as writing a CSP that lets the encryption be done by a smartcard instead of by software on the computer. >> + modes of operation (ECB, OCB, CTR...) >> >What are these acronyms? Block-cipher algorithms (AES, Blowfish, DES, etc...) only work at one block of data at a time, i.e. they take a chunk (typically 64 or 128 bits) and encrypt it as another chunk of the same size. If you want to encrypt something larger than a block (such as a file), you must specify how this should be done. The simplest is to just encrypt each block of the file. This is called Electronic Codebook Mode (ECB). You also need to specify the length of the file (since it may not be an integral number of blocks) in some way. ECB has some disadvantages. For example, if the same block is encrypted twice, the encryption looks the same. So if you send me the answer to three questions YES YES NO and we assume that each answer is encoded in a 64 bit structure (or whatever the block size is) --- this is inefficient, but bear with me --- then encoded with ECB it would look something like this H8GF... H8GF... PUt7... From this, an attacker could conclude that you have given the same answer to the two first questions and a different answer to the third question, i.e. he will know that you either answered NO NO YES or YES YES NO. The other modes deal with this problem. You will find descriptions of them in standard cryptographics texts or on the internet (search for "modes of operation" or something similar). >Please excuse my ignorance... We are all ignorant about something. -- Niklas