- the system can be updated to take a key as input.
- right, it expands by nearly a half; that's used to make it just as secure as the one-time pad, but more practical. [and this is what i want to verify, then optimize].
if you have the time, i'd love to hear more feedback. thank you very much.
No. There is no such thing as "just as secure as the one-time pad but more practical". If you want information-theoretic security you have to pay for it, and if you don't pay for it you don't get it. Like, there are theorems. That's why mention of OTP is a good proxy for not understanding modern cryptography. Everyone who's serious about it knows that not only are the benefits of the OTP not achievable in almost every practical situation (due to key distribution), nobody actually needs that level of security when 256-bit algorithms are available.
my claim is a bit different though; it's a new take on encrypting text that has no properties of existing crypto systems. used OTP as an analogy. i think it's a fallacy to do so.
> - right, it expands by half but i believe it's just as secure as the one-time pad [this is what i want to verify]
This is the easiest bit to critique / attack.
For OTP to work the pad needs to be properly random; the pad needs to be bigger than the plain text.
Expanding something else probably stops it being properly random.
People get hung up on OTP because PROVABLY SECURE. They are secure, but they're also cumbersome to use.
- my bad, the font size in the editor is originally small. will try to fix that.
- problem is that the algorithm itself is what makes the system strong. once revealed in a white paper, the whole thing is useless. what do you recommend to write in a text description for this case?
- it's an imitation of OTP mechanism but has nothing to do with how OTP is conventionally implemented.
This is a deal-breaker. Your system is not strong if you rely on other people not knowing how it works. Nobody will use it because you can't convince them it's worth anything, you can't distribute it in code. I don't mean to sound like a jerk, but again this is literally 19th century stuff: https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle .
thanks a lot for taking the time to discuss it.
That's called a Viginere cipher and people stopped using it in the 19th century.
> i'm not using any traditional math that current encryption relies on; no entropy, discrete logarithms nor prime factorials, etc.
> i'm not using any traditional math
That doesn't get you an out - the theorems don't care how you transform M to C.
http://www.faqs.org/faqs/cryptography-faq/
It might be an idea to read about different attacks - known plaintext etc - and seein if your system is still secure. (It won't be, so if you can't find the flaw you know you need to look more).