Quantcast
Channel: When did Kerckhoffs's principle become fully accepted in design and practice of modern ciphers? - Cryptography Stack Exchange
Viewing all articles
Browse latest Browse all 2

When did Kerckhoffs's principle become fully accepted in design and practice of modern ciphers?

$
0
0

Kerckhoffs's principle is named after a publication over 130 years old. Yet it is still something that is commonly misunderstood and challenged by newcomers to cryptography. This question from Open Source Stack Exchange seems typical, and one answer to it implies that at some point, cryptographers in general "got it" and it has become a cornerstone of modern cipher design.

This seemed interesting to me - was the principle for Kerckhoffs's original paper (originally design principle 2 from a list of 6 according to Wikipedia) broadly accepted from the moment of publishing, or has it taken time, specific events and/or the failure of many electronic designs before attaining its current importance?

I searched for "violations of Kerckhoffs's principle" and found a few modern examples (e.g. MiFare being hacked), where essentially the cipher was weak - and easily understood to be weak at the time it was made - but kept secret in the vain hope that reverse-engineering it would be too much of a challenge. However, I didn't find anything I could relate to history such as a series of "secret" ciphers failing badly in the 1990s for instance. So I'm starting to think the principle really has been well-understood ever since it was published, just not followed in practice by some institutions that should have known better had they asked any cryptanalyst. Therefore one way re-framing my question might be "Has there ever been a time in modern (computer-based) cryptographic practice where Kerckhoffs's principle was not considered as important as it is today?"


I tried to use Google ngrams to get a sense of when terms may have become popular, and didn't notice any spiking, but a steady rise in term frequency for e.g. "security through obscurity" from 1970's to present day. Does that point to use of Kerckhoff's principle as a norm (or even just as a label), due to increased academic study of cryptography? This has been suggested in comments. Is there better evidence for that than my ad-hoc searching?


Viewing all articles
Browse latest Browse all 2

Latest Images

Trending Articles



Latest Images