...
首页> 外文期刊>International Journal of Information Security >On the security of the WinRAR encryption feature
【24h】

On the security of the WinRAR encryption feature

机译:关于WinRAR加密功能的安全性

获取原文
获取原文并翻译 | 示例

摘要

Originally written to provide the file compression feature, computer software such as WinRAR and WinZip now also provide encryption features due to the rising need for security and privacy protection of files within a computer system or for sharing within a network. However, since compression has been much in use well before users saw the need for security, most are more familiar with compression software than they are with security ones. Therefore, encryption-enabled compression software such as WinRAR and WinZip tend to be more widely used for security than a dedicated security software. In this paper, we present several attacks on the encryption feature provided by the WinRAR compression software. These attacks are possible due to the subtlety in developing security software based on the integration of multiple cryptographic primitives. In other words, no matter how securely designed each primitive is, using them especially in association with other primitives does not always guarantee secure systems. Instead, time and again such a practice has shown to result in flawed systems. Our results, compared to recent attacks on WinZip by Kohno, show that WinRAR appears to offer slightly better security features.
机译:最初为提供文件压缩功能而编写的软件,例如WinRAR和WinZip,由于对计算机系统内文件或网络内共享文件的安全性和隐私保护的需求不断增加,现在也提供了加密功能。但是,由于压缩在用户看到安全需求之前就已经被广泛使用,因此与安全软件相比,大多数用户更熟悉压缩软件。因此,比起专用的安全软件,诸如WinRAR和WinZip之类的具有加密功能的压缩软件往往更广泛地用于安全性。在本文中,我们介绍了对WinRAR压缩软件提供的加密功能的几种攻击。由于基于多个密码原语的集成开发安全软件的精妙之处,可能导致这些攻击。换句话说,无论每个原语的设计有多安全,特别是与其他原语结合使用时,并不总是保证系统安全。取而代之的是,这种做法一次又一次地导致了系统的缺陷。与Kohno最近对WinZip进行的攻击相比,我们的结果表明WinRAR似乎提供了更好的安全功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号