Keystream Reuse

Also known as:Two-Time Pad

Keystream Reuse: Reusing the same keystream, making the encrypted messages recoverable. The mistake completely removes the security of stream ciphers and counter modes.

How it works and where it fits

Stream ciphers and modes such as CTR combine plaintext with a keystream via XOR. If the same stream is used for two messages, XORing the two ciphertexts cancels the key and yields the XOR of the plaintexts. If just one message is known or partly predictable — a fixed prefix, a timestamp format, a recurring header — the other can be reconstructed directly. If the attacker knows a complete plaintext–ciphertext pair, the keystream itself follows immediately.

Practical security relevance

The cause is almost always a repeated initialization vectorInitialization VectorStarting value for a block cipher mode that makes identical plaintexts produce different ciphertexts. or nonce, for instance because it is derived from a category, a user ID, or a constant. It becomes especially critical when an interface returns both plaintext and ciphertext — then no statistical analysis is needed at all. Remedies are unique per-message nonces, authenticated encryption, and a clearly defined key rollover before the nonce space is exhausted.

  • Initialization VectorInitialization VectorStarting value for a block cipher mode that makes identical plaintexts produce different ciphertexts.: Starting value for a block cipher mode that makes identical plaintexts produce different ciphertexts.
  • CryptographyCryptographyMethods for protecting information through encryption, signatures, and hash functions.: Methods for protecting information through encryption, signatures, and hash functions.
  • EncryptionEncryptionConverts plaintext into unreadable ciphertext using a key.: Converts plaintext into unreadable ciphertext using a key.
  • Nonce ReuseNonce ReuseRepeated use of a one-time value, disclosing plaintexts or private keys depending on the scheme.: Repeated use of a one-time value, disclosing plaintexts or private keys depending on the scheme.