Showing posts with label Internet of Things. Show all posts
Showing posts with label Internet of Things. Show all posts

Saturday, 3 December 2016

HISTORY becomes THE FUTURE

Venona project (1943–80)



I have read that this was one of the most successful counter-intelligence efforts of the Cold War; purportedly successful because individual(s) on the soviet side began to reuse keys, rather than generating a new key for each message.

Perfect Encryption

 

Claude Shannon is accredited with defining the idea of "perfect encryption" in which the encryption key would be, at least as long, as the message.
These two paths from our collective HISTORY converge with CORA, and become THE FUTURE of data security.

CORA stands for Context Ordered Replacement Algorithm.

While the 'magic of CORA' temporarily remains a trade secret, the following expose makes for an acceptable 'letter of introduction' to CORA.
 Context Ordered infers that the same CORA bloc (key in the Venona project cited above) will always be created anew when 'CORAfying' data.
Replacement Algorithm infers that each CORA bloc's relevant data (perfect encryption cited above) should span a proportionate size that exceeds the relative data.

Bottom Line

A CORAfied solution at its worst, is far more than a 'googol' times stronger than military grade encryption, at its best.

CORAfied - at its worst:

  • 3 CORA blocs in the solution.
  • 2 out of the 3 blocs are stolen.
  • The blocs are at the minimum size required for CORAfication.
  • The hacker has:
    • the catalog file.
    • the chaos maps.
  • The thief knows:
    • there are only 3 blocs in the solution.
    • the size of the 3rd bloc.
    • the relevant order of blocs including boundary conditions.
Giving this scenario in which the CORAfied data is horribly compromised, a brute force attack would take no more than 102400 attempts to obtain the CORAfied data.

Contrast this to military grade encryption that uses a 256 bit key which would take no more than 2256 1078 attempts to obtain the encrypted data.

Hence CORA at its worst is 102322 times stronger  - a step beyond encryption! 
I prefer to refer to this as "astronomically stronger" or "unbreakable"!

Addendum (4 Dec 2016)


It should be noted that patterns in random number generators, and optimization routines based upon frequency distributions in the byte structures will result in the potential for optimizations. Taking a smarter approach based on these patterns might pragmatically decrease this complexity of the attack pathway by 20%, which could result in as little as 101926  attempts, or 101848 times stronger than military based encryption.
The enormity of this number is still astronomical unbreakable

Sunday, 3 July 2016

IoT needs unbreakable


ZDNet just published an article “The first big Internet of Things security breach is just around the corner”.

The IoT is projected to be worth in excess of 3 trillion dollars by 2020. Therefore, it should be obvious that it isn’t going away. Smart devices and chips will be everywhere. Yes, this is a security risk.


The challenge to the cyber security industry is to become “unbreakable”. 


Imagine the hundreds of thousands of hackers and unscrupulous employees who are spending ungodly numbers of hours and days trying to steal what doesn’t belong to them. Next imagine how many would continue to do so if they weren’t getting a piece of the $400,000,000,000 being stolen from you and me each and every year.


Unbreakable - the concept - is simple. 


Make it too costly and time intensive to “risk failing at the hack”! 
Risk money, time and potential criminal consequences, without getting “the prize” – who is going to do it? Ok, maybe the odd duck, but that is far better than the hundreds of thousands globally attempting to, and succeeding at stealing “our money”. Yes, it is our money, even if we don’t realize it. The big boys and girls aren’t going to lose 400 + billion a year without passing those losses onto the rest of us – not if they want to keep their jobs.

This is exactly why CORAcsi is unbreakable. Is it conceivable that someone might discover where all the CORA packages are stored throughout the Cloud, then breach each of the servers and networks involved, within a short window – say 5 minutes? 

Perhaps it is conceivable – and if they did, CORA would be no better than encryption. This may be conceivable, however, it is totally improbable, and will reduce the numbers attempting to succeed significantly, as failures clutter their landscape. 
Unbreakable = too costly and time intensive to risk failing at - the hack.
Unbreakable = leaving a trail (such as an employee who has access to “the catalog”).
Unbreakable = too many networks and servers to violate before a single package has been deleted.
Unbreakable = too many unknowns to warrant the cost while risking the consequences.