Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7596523
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 30, 20262026-05-30T21:56:13+00:00 2026-05-30T21:56:13+00:00

How hard is it for a given ciphertext generated by a given (symmetric or

  • 0

How hard is it for a given ciphertext generated by a given (symmetric or asymmetric) encryption algorithm working on a plaintext/key pair, to find a different plaintext/key pair that yields the same cyphertext?

And how hard is it two find two plaintext/key pairs lead to the same cyphertext?

What led to this question, is another question that might turn out to have nothing to do with the above questions:

If you have a ciphertext and a key and want to decrypt it using some decryption routine, the routine usually tells you, if the key was correct. But how does it know it? Does it look for some pattern in the resulted plaintext, that indicates, that the decryption was successful? Does there exists another key results in some different plaintext, that contains the pattern and is also reported “valid” by the routine?

Follow-up question inspired by answers and comments:

If the allowed plaintext/key pairs where restricted in the on of the following (or both) way(s):

1) The plaintext starts with the KCV (Key check value) of the key.

2) The plaintext starts with a hash value of some plaintext/key combination

Would this make the collision finding infeasible? Is it even clear, that such a plaintext/key exists=

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-30T21:56:14+00:00Added an answer on May 30, 2026 at 9:56 pm

    The answer to your question the way you phrased it, is that there is no collision resistance what so ever.

    Symmetric case
    Let’s presume you got a plain text PT with a length that is a multiple of the block length of the underlying block cipher. You generate a random IV and encrypt the plain text using a key K, CBC mode and no padding.

    Producing a plain text PT’ and key K’ that produces the same cipher text CT is easy. Simply select K’ at random, decrypt CT using key K’ and IV, and you get your colliding PT’.

    This gets a bit more complicated if you also use padding, but it is still possible. If you use PKCS#5/7 padding, just keep generating keys until you find one such that the last octet of your decrypted text PT’ is 0x01. This will take on average 128 attempts.

    To make such collision finding infeasible, you have to use a message authentication code (MAC).

    Asymmetric case
    Something similar applies to RSA public key encryption. If you use no padding (which obviously isn’t recommended and possibly not even supported by most cryptographic libraries), and use a public key (N,E) for encrypting PT into CT, simply generate a second key pair (N’,E’,D’) such that N’ > N, then PT’ = CT^D’ (mod N) will encrypt into CT under (N’,E’).

    If you are using PKCS#1 v1.5 padding for your RSA encryption, the most significant octet after the RSA private key operation has to be 0x02, which it will be with a probability of approximately one in 256. Furthermore the first 0x00 valued octet has to occur no sooner than at index 9, which will happen with a high probability (approximately 0,97). Hence, on average you will have to generate on average some 264 random RSA key pairs of the same bit size, before you hit one that for some plain text could have produced the same cipher text.

    If your are using RSA-OAEP padding, the private key decryption is however guaranteed to fail unless the cipher text was generated using the the corresponding public key.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Given that: SSD’s are now [high end] mainstream Two+ cores are not hard to
Given an array A of integers, find any 3 of them that sum to
im given a hard copy of a form that is used by a hospital
Given that there appears to be no hard and fast rule as to what
edited Given that the words uncertain and uncertainty are fairly ubiquitous, it's hard to
Given a set of n points, can we find three points that describe a
Kinda hard to explain, but i'll try. I have a datalist that is populated
The hard drive on one of my PCs crashed that had the installers for
Just having a hard time adding a certain bit of given code to add
I know that peripheral devices such as a hard driver, a floppy driver, etc

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.