Labels

Pressefreiheit (178) Wirtschaft (167) Österreich (132) IT (125) code (78) Staatsschulden (41) EZB (28) Geopolitik (22) Pensionssystem (17)
Posts mit dem Label IT werden angezeigt. Alle Posts anzeigen
Posts mit dem Label IT werden angezeigt. Alle Posts anzeigen

2026-09-28

Linux: ipv4 ipsec server with roadworrior behind SNAT wlan


This describes a scenario of an ipsec server with public ip and a client behind a NAT gateway.
Server uses self signed ROOT CA and a signed ipsec certificate with public/private key for authentication.
Client uses Pre-Shared-Key PSK and servers certificate public RSA key.

ipsec server

Generate ROOT CA and ipsec rsa priv keys and certificates

#/usr/bin/bash
# delete all old certs priv keys and certificate requests rm -f strongswanKey.pem strongswanCert.pem ipsecKey.pem ipsecReq.pem ipsecCert.pem *.pem
# generate snake oil ROOT CA pki --gen --type ed25519 --outform pem > strongswanKey.pem pki --self --ca --lifetime 3652 --in strongswanKey.pem \ --dn "C=CH, O=strongSwan, CN=strongSwan Root CA" \ --outform pem > strongswanCert.pem # print snakeoil ROOT CA pki --print --in strongswanCert.pem
# generate ipsec private key and certificate pki --gen --type rsa --size 3072 --outform pem > ipsecKey.pem # pki --gen --type ed25519 --outform pem > ipsecKey.pem pki --req --type priv --in ipsecKey.pem \ --dn "C=AT, O=area23, CN=ipsec.area23.at" \ --san ipsec.area23.at --outform pem > ipsecReq.pem pki --issue --cacert strongswanCert.pem --cakey strongswanKey.pem \ --type pkcs10 --in ipsecReq.pem --serial 01 --lifetime 1826 \ --outform pem > ipsecCert.pem # print ipsec certificate pki --print --in ipsecCert.pem # copy certs and priv keys cp strongswanCert.pem /etc/ipsec.d/cacerts/. cp *Cert.pem /etc/ipsec.d/certs/. cp *Key.pem /etc/ipsec.d/private/.

server: add virtual interface to eth0

ifconfig eth0:1 10.160.0.4  netmask 255.255.255.0 broadcast 10.160.0.255 up

/etc/ipsec.conf # server

# ipsec.conf - strongSwan IPsec configuration file

# basic configuration
config setup
        strictcrlpolicy=no
        charondebug="all"
        uniqueids=no

ca strongswan  #define alternative CRL distribution point
        cacert=strongswanCert.pem  # self snake oil generated ROOT CA
        auto=add

conn %default
       keyingtries=1
       keyexchange=ikev2
conn ipsec-ikev2-vpn
        auto=add
        authby=xauthrsasig
        xauth=server
        compress=no
        type=tunnel
        keyexchange=ikev2
        fragmentation=yes
        forceencaps=yes
        # ike=aes256-sha1-modp1024,3des-sha1-modp1024!
        # esp=aes256-sha1,3des-sha1!
        dpdaction=clear                 # configure dead-peer detection
        dpddelay=300s
        rekey=no
        # configure the server (left) side IPSec parameters
        left=%any
        leftid=ipsec.area23.at
        leftcert=/etc/ipsec.d/certs/ipsecCert.pem # ipsecCert generated from ROOT CA
        leftsendcert=always
        leftsubnet=10.160.0.4/24
        # configure the client (right) side IPSec parameters like private IPs
        rightid=%any
        # rightid="C=AT, O=area23, CN=ipsec.area23.at"
        # rightauth=eap-mschapv2       
        # rightauth=pubkey
        rightauth=secret                # pre shared key
        # rightcert=strongswanCert.pem
        rightsourceip=10.160.1.0/24     # opposite subnet
        rightsubnet=10.160.1.0/24       # (IP address pool for clients)
        rightdns=8.8.8.8,8.8.4.4                    #(DNS for clients)
        rightsendcert=never

/etc/ipsec.secrets  # server

# This file holds shared secrets or RSA private keys for authentication.

# RSA private key for this host, authenticating it to any other host 
# which knows the public part. : RSA "ipsecKey.pem" : RSA "strongswanKey.pem" # EAP bra : EAP "bra@ipsec.area23.at" # Pre Shared key : PSK "wonder_bra123$%&789=0AsdFJkl#"

ipsec client

client: add virtual interface to wlp1s0

ifconfig wlp1s0:1 10.160.1.4 netmask 255.255.255.0 broadcast 10.160.1.255 up

/etc/ipsec.conf # client

# ipsec.conf - strongSwan IPsec configuration file
# basic configuration

config setup
    strictcrlpolicy=no
    uniqueids = no
    charondebug="all"

conn sample-with-ca-cert
    # general 
    keyexchange=ikev2
    auto=start
    # this side of tunnel
    leftauth=secret      # Pre Shared key 
    leftid=10.16.235.154
    leftsourceip=%config
    # right other side of tunnel 
    right=187.33.151.48
    rightsubnet=10.160.0.4/24
    rightid=ipsec.area23.at
    rightauth=pubkey     # certificate pzblic rsa key

/etc/ipsec.secrets # client

#  This file holds shared secrets or RSA private keys for authentication.
# RSA private key for this host, authenticating it to any other host 
: RSA "ipsecKey.pem"
: RSA "strongswanKey.pem"
# EAP
bra : EAP "bra@ipsec.area23.at"
# Pre Shared key
: PSK "wonder_bra123$%&789=0AsdFJkl#"

 

YouTube very fast step through: https://www.youtube.com/watch?v=xw8wUxepvJ8

2026-09-24

SID (Space Intrusion Detection)

 

SID (Space Intrusion Detection)

Heinrich Elsigan

September 2026

Download pdf   LaTeX

Introduction

SID is a concept for an intrusion detection system for linux servers in internet or local network including cloud linux servers,

  1. SID daily monitors (and highlights changes to yesterday)

    • all mounted data file systems in detail (except log files, caches, /var/sppol/*)

    • installed kernel, kernel modules lsmod, kernel config and boot (initrd image)

    • current kernel and system settings (/proc file system)

    • attached and registered devices

    • network interfaces and netfilter iptables ip6tables rules

    • all running daemons especially those who allocate listening network tcp/udp socket descriptors

  2. SID hourly monitors

    • available free disk space

    • load average

    • currently active users and daemons

    • all system inter-process communications ipcs lsipc

    • all file descriptors, locks, ... lsfd lslocks,

    • ...

  3. SID permanently monitors

    • successful and failed authentications

    • errors with hints of critical intrusion in all logfiles

    • heavy process or CPU load, which could be an internal privilege escalation or brute force attack

…

Prequel

In UFO TV Series 1970s a SID Space Intrusion Detection, that scans permanently for unidentified flight objects, detects and tracks them and probabilistic calculates most possible ufo’s attack vectors. Ufo series intro & outro

UFO series: SID Space Intrusion Detection

Actions

Regular monitoring activities

SID writes a daily report and highlites all changes to yesterday. filesystem files changed content (sha512), special permissions and all filesystem date time entry changes are emphasized too.

When a concern or intrusion rule matches at daily changes, SID sends additionally an email or SMS. (We don’t want to have too many SPAMs for sysadmin / manager like in Nagios.) Nevertheless SID should send a weekly or montly ’all well and alive’ email message, so that you know, that SID is still operating.

YELLOW and RED alerts intrusion triggers

SID sends immediate an email / sms or Endpoint Service message in case of yellow / red alert at intrusion detection.

… …

SID protection

SID binaries are launched from a readonly not modifyable squash fs mounted image e.g. by snapcraft, a hardware protected usb stick, a LUKS encrypted readonly mounted filesystem or cd / dvd. SID config files should also only mounted rw, when changing them. SID reports could be signed, symmetric or asymmetric encrypted (with passwd or key or X509 certificate).

… …

Epilog

Good luck!

We hope you find SID useful and good luck. To contact me, use the contacts at https://heinrichelsigan.area23.at.

2026-09-02

Better registered® trademarks™ instead of software patents

An addendum to software patents and a discussion with Dr. Paul Rübig on LinkedIn

Software is a composition of many individual components and different algorithms.


Prefer registered® trademark™ over software patents

Nevertheless, it is highly advisable to handle software patents with extreme cautio, as someone else may have already created this or a similar combination of identical algorithms, or someone else may create them without being aware of the patented work.

It is recommended to register complete products or product suites as registered trademarks ™ rather than  via software patents.
Registered trademarks offer better protection against virtually identical copies where only minor layout changes have been made and a code scrambler has been used.

Registered ® trademarks ™ prevent imitation of trademarks, but not of competing products, see

https://www.microsoft.com/en/microsoft-365

https://www.openoffice.org/en/


Authors (in case of humans, companies, NGOs...)
of source code always retain © copyright


Code Snippets

In my opinion, code snippets, such as those used on Stack Overflow, Git, and in various API references, can be copied 1:1 into any source code if they atomic explanations, e.g.:

https://stackoverflow.com/questions/5754879/usage-of-mutex-in-c-sharp



https://learn.microsoft.com/de-de/dotnet/api/system.threading.mutex?view=net-10.0


Basic statements, that are often used identically

switch (pid = fork())

https://man.freebsd.org/cgi/man.cgi?fork(2)

see all Google results for switch (pid = fork())

Last but not least,
limit patent (intelectual property) rights in time

Unlimited IP rights on patents would lead to monopols, which are dangerous for a developing innovative economy.

Pharma drugs have patent and Intelectual property right for some years, later generic pharma products are allowed to enter the market:

https://www.orionpharma.com/newsroom/all-news/articles/science-and-partnering/what-is-a-generic-medicine--and-what-is-good-to-know-about-it/
https://www.fda.gov/drugs/generic-drugs/generic-drugs-questions-answers
https://www.ema.europa.eu/en/glossary-terms/generic-medicine


Term of protection in Austria:
A patent is valid for a maximum of 20 years from the date of application.

2026-09-01

Mathemathische Modellierung

Angenommen es gibt diverse Dinge, die mit einander verknüpft sind und scharfe, unscharfe Zusammenhänge, wie diese auf einander wirken, dann wäre ein Tool nett, dass echt gut mathematisch modellieren kann.

Ich meine ein Tool, dass mehrere plausible mathematische Lösungsmodelle offenbart, sobald man diverse Daten und Formeln eingibt, nach heuristischer Priorität sortiert.

man kann ja wechselseitige Gleichgewichtssysteme durch unterschiedliche Methoden der Mathematik modellieren, wie

  • Polynome n-ten Grades
  • Simplex (lineare Optimierung)
  • Differenzengleichungen
  • Differntialgleichungen
  • Neuronale Netze
  • Gleichgewichtsgleichungen (mit oder ohne resusirven Elemente)
  • Geometrische Modellierung
  • ...
Dabei kann man scharfe oder unscharfe Scopes vorgeben, wie 

Ist wahrscheinlich,
  • dass die Anzahl der zugelassenen Kraftfahrzeuge im Normalfall nicht die Anzahl der Bürger eines Staates übersteigt.
  • dass es zumindest ¼ Geburten pro Jahr gibt im Vergleich zu Todesfällen
  • dass die Strahlkraft der Sonne langsam abnimmt (sehr kleines epsilon)
  • dass Photovoltaikanlagen an Effizienz minimal gewinnen (sehr kleines epsilon)
  • dass die Flussgeschwindigkeit der Flüsse abnimmt
  • dass Turbinen besser optimiert werden können, mehr als die Flußgeschwindigkeit der Flüsse abnimmt
  • dass Computer alle 5 Jahre die doppelte Prozessorleistung bei ¾ der ursprünglichen Eingangsleistung
  • dass man auf jeder neuen Prozessor Hardware nur ein Unix/Linux System innerhalb von 6 Monaten nach Launch hinbekommt....
  • ...
Weiters könnte man exakte Modellierung wählen, oder unscharfe, wo die Daten innerhalb einer gewissen größeres Epsilon Varianz, liegen dürfen.

Zusätzlich können semantiche und pragmastische Regeln eingeben werden, wo das Tool checkt,
Lebewesen => Fortpflanzung 99% Cloning 1% wahrscheinlich
HF Spektrum emitierende Objekte (Radioaktiv, Sterne, Pulsare, ...) => hängt von Masse des Objekts und Emissionsmenge (Halbwertszeit) ab.
Durch semantische Regeln kann das Tool erkennen, ob Datenfehler vorhanden sind, oder kritische ausufernde Datenreihen odeer Formeln als WARNING markieren.

2026-08-25

Personal open cloud VPN box


Personal Cloud VPN is an easy to implement idea

  • to avoid breaking SSL via transparent bluecoat or squid bump
  • to monitor all your input / output traffic
  • to keep 100% control over your input / output traffic

Personal Cloud VPN could be implemented with
...

https://www.f5.com/go/ebook/secure-multicloud-networking-for-dummies


Blue Coat Proxy (now Broadcom Edge SWG / ProxySG) performs SSL/TLS inspection by terminating the encrypted client connection, decrypting and analyzing the traffic, and establishing a new connection to the destination server.


Squid Bump

https://wiki.squid-cache.org/Features/SslBump

https://github.com/satishweb/squid-ssl-proxy

https://support.kaspersky.com/de/kwts/6.1/166244


2026-08-18

Mobile Devices → end of Flash, Silverlight, Moonlight, Java Applets, ActiveX

When it comes to browser plugin technologies like Flash, Silverlight, Moonlight or even old Java Applets, I claimed today in the early morn, that those tehcnologies began to die with the raise of mobile devices (most with a unix kernel) and mobile browsers. 


In fact it was the <object>...</object> tag in html, that whose full implementation of all technologies subsequently implied an excessively long and complicated process for mobile device and browser developers.


Died arround 2020 or earlier


https://en.wikipedia.org/wiki/Adobe_Flash

There may exist some flash browser under android, 
but the came too late:
https://play.google.com/store/apps/details?id=com.axio.axiobrowserNew

https://www.ibm.com/docs/en/i/7.5.0?topic=platform-java-applets-applications


https://en.wikipedia.org/wiki/Microsoft_Silverlight



https://en.wikipedia.org/wiki/ActiveX





Html5 + Css with Javascript (TypeScript, Angular) remains


There isn't really an alternative for browser plugin languages we had.  Html5 + Css with Javascript and all derived JS Framrworks like Node.js, TypeScript, Angular cannot map all features of Flash or Java Applets.

2026-08-14

linux encrypting security

This blog article concerns linux encrypting security with public/private key (gpg, RSA, ...) mechanism and X509 certificates hierarchical security.

 

Levels of linux security  

 

UEFI Secure boot










Encrypted filesystem 

Linux Unified Key Setup 

Full Disk Encryption on Linux with LUKS

  

 https://www.linux.com/training-tutorials/how-encrypt-linux-file-system-dm-crypt/ 


filesystem mounting options: fstab

security options: readonly nonexecutable nosuid nosgid 

You can mount /usr as readonly filesystem and remount it rw on updates.

mount -o remount rw  /usr
apt-get update; apt-get distupgrade 
mount -o remount=ro=recursive  /usr

https://unix.stackexchange.com/questions/807127/securing-linux-filesystem-with-mount-options

ro=recursive,noexec=recursive,nosuid  

mount -o remount=noexec=recursive,nosuid  /mnt/{mountpoint}

# /etc/fstab: static file system information.
#
# Use 'blkid' to print the universally unique identifier for a
# device; See fstab(5).
#
# <file system> <mount point>   <type>  <options>  <dump>  <pass>
# / was on /dev/sda4 during installation
UUID=07ceda95-80a7-486c-930b-e9facdf1c073 /        ext4    errors=remount-ro 0       1
# /boot was on /dev/sda2 during installation
UUID=58570ac7-0698-4755-81b7-cc6d59e09f60 /boot    ext4    defaults          0       2
# /boot/efi was on /dev/sda1 during installation
UUID=8B4E-B934  /boot/efi       vfat    umask=0077      0       1
/dev/mapper/sda3_crypt /home           ext4    discard,commit=30,noexec=recursive,nosuid,errors=remount-ro         0       2

snapcraft.io

configure snaps  

using verifiable and updateable readonly snapshots,
instead of installing packages / binaries under /usr

mounting snapshots loopback squashfs (ro,nodev,relatime,errors=continue,threads=single)

                                                                                       

Signing containers, kernel images, packages,repositories

https://www.qcecuring.com/blog/code-signing-linux-guide


Signed executables under linux (unix)

 

https://stackoverflow.com/questions/1732927/signed-executables-under-linux 

Since Solaris 10 & 11 OS perspective all binaries were signed:

https://sourceforge.net/projects/signelf/ 

Linux kernel sign-file.c 

https://github.com/torvalds/linux/scripts/sign-file.c

 

Signed interpreter scripts under linux


TODO ;(

 

Verify signed executables at kernel level


TODO ;(

Verify / Validate instruction at hardware level

 

fetch, add, load, move, jump 

TODO ;(

2026-08-02

C# JetBrains Rider on Ubuntu Linux Wayland X11.

I tried JetBrains Rider on Ubuntu Linux Wayland X11.

 

Console Application

 

It's easy to publish a console application.
You must install in any way this Nuget package:
https://www.nuget.org/packages/System.Runtime.Extensions 

You might install additional Nuget packages, when using Resources.resx files and System.Drawing.Bitmap:
https://www.nuget.org/packages/System.Resources.Extensions
https://www.nuget.org/packages/System.Drawing.Common
 

 You can publish the application native x64 linux with that settings

 

or portable framework dependent. 

 

Asp.Net Blazor Application

 

But you can also build, publish, and launch an Asp.Net Blazor application. This animation shows you how to:     


 

2026-08-01

Market competition - where it's useful and where it's definitely not

Market competition among mobile network providers

There are several mobile network operators in the Austrian market. 

In the past (before year 2000), the market was mainly dominated by Mobilkom, 
a subsidiary of Telekom Austria, which was itself a subsidiary of Austrian Post. 


When we look at the market shares of mobile network operators, some only see the job cuts at the former Mobilkom. However, nobody calculates the number of new jobs created by the competition or considers whether there are now more jobs overall for mobile network operators in the Austrian market than during the near-monopoly era.

 

precarious jobs 

There are always people, including rarely some german economists, who call for more competition in the precarious job sector. 

Simple moving companies with small trucks charge at least €38-€50 per hour and don't work for less than an hour. You can only book them for one hour or more.

Distributing printed advertising flyers costs €0.11 per piece at the post office.
Private distribution agencies in Vienna often charge between €39 and €60 per 1,000 pieces for distribution alone. It's nearly impossible to find a reputable offer below that price. 
Lowering prices in the precarious segment risks poor or no service at all. (Some advertising leaflets end up in the trash and there is no legal company at all behind it.)

Trying to cut prices in the lowest price segment almost never works; there, the key is to offer better guaranteed performance and quality. Customers in the lowest price segment are almost always interested in guaranteed performance and quality, and rarely in a price reduction of 0.01 cents. 

Prices that are too low often cause customers to fear that the required service will actually be provided or not. 

2026-07-02

Useful find commands

Unix

last 2 days or newer than file

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var /tmp -daystart -mtime -2  

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var -cnewer /etc/mailcap  

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var -anewer /etc/shadow  

execute permission or setuid or/and setgid

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var /tmp -perm -u+x -type f  

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var /tmp -perm -4000 -o -perm -2000  

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var /tmp -perm -6000  

last 7 days and execute permission

find /bin /boot /etc /home /li* /m[en]* /opt /root /s[bnr]* /usr /var /tmp -daystart -mtime -7 -perm -u+x -type f  

find / -daystart -mtime -7 -perm -u+x -type f  


Windows Powershell

last 7 days recursive

Get-ChildItem -Path c:\*.* -Recurse| ? {$_.LastWriteTime -gt (Get-Date<).AddDays(-7)}

last 7 days recursive and filter on extension (.exe, .dll, .bat)

Get-ChildItem -Path c:\*.* -Filter *.exe -Recurse|? {$_.LastWriteTime -gt (Get-Date<).AddDays(-7)}

Get-ChildItem -Path c:\*.* -Filter *.dll -Recurse|? {$_.LastWriteTime -gt (Get-Date<).AddDays(-7)}

Get-ChildItem -Path c:\*.* -Filter *.bat -Recurse|? {$_.LastWriteTime -gt (Get-Date<).AddDays(-7)}


2026-04-27

lets encrypt acme certificates in windows IIS

If you want a secure let's encrypt SSL certificate for your windows IIS (internet information services), then there a multiple ways to get it.
See https://letsencrypt.org/docs/client-options/#clients-windows-/-iis

Let’s Encrypt uses the ACME protocol to verify that you control a given domain name and to issue you a certificate. To get a Let’s Encrypt certificate, you’ll need to choose a piece of ACME client software to use.

IIS pre configuration

Run %windir%\system32\inetsrv\InetMgr.exe and add a hostname based http (:80) website first.


Test your hostname website from a different location in the internet (your smartphone or Tor Onion).
win-acme will later detect that hostname based website and offer https alternative.

win-acme

Go to win-acme.com and download zip file.

Alternatively, you can also go to the win-acme git repository and get the latest tagged release there.

Extract the win-acme zip file and then run wacs.exe


IIS post configuration

Run %windir%\system32\inetsrv\InetMgr.exe and remove the hostname based http (:80) website.
Then add the https (:443) hostname based website.

Select SSL certificate.

View SSL certificate and verify let's encrypt certificate issuer, chain and valid from / to dates.

Test your ssl website

Test https connection to website from a different location in the internet (smartphone or Tor Onion).

2025-12-12

DB scenarios with heavy load and a lot of idle time

When it comes to distributing the load between database and application server, web server, and internal report servers, often various approaches were discussed some purely by ideology driven.
Some realistic real world examples:

  1. Nearly all load should be in the memory of application and web servers
    with many dynamic objects, and almost NO load should hammer the database.
  2. Only Entity Framework Core
  3. No EFCore at all, because only Stroed Procedures can be administrated more secure. and last but not least can guarantee atomicity, fetch of reduced result sets, that you really need and NOT huge views from the entire database.
  4. Optimized stored procedures with execution plan sniffing will solve heavy load problem.
  5. Entity Framework Core with stored procedures is also must have for 4.
  6. EFCore SProcs is only a nuget package of unknown origin, I only trust Microsoft.
  7. Can you search git please: https://github.com/verdie-g/StoredProcedureEFCore
    Ah, origin seems to be very clear for me.
  8. This package is archived since 22.10. MS can do it directly:
    https://stackoverflow.com/questions/28599404/how-to-run-stored-procedures-in-entity-framework-core
  9. Reducing wait time of (dead-)locks in case of only read access
    by uncommittable reads, that totally avoid table and row locks
  10. Fast memcaches to partially buffer the database
    only write-through  works
    must implement lazy loading strategies
    clever buffering, instead fully write through 
  11. ...
To understand the situation better, I draw 2 different scenarios and you will immediately see why the database in Scenario 1 is always under heavy load and further load is critical,
while the database in Scenario 2 is almost always idle.


What I mean you really must take care to avoid any further huge db load in scenario 1,
but not in scenario 2.


If you want for your external business application in a scenario 2 (most cloud databases are optimized on relational data and databases are stored often on a seperated optimized disk in raw format, so this is already a performance advantage to c:\*.mdf;*,ldf, where all windows services and system programs permantly have high IO, see https://youtu.be/ybNXf4t4zT4)
then contact cloud pilots to see your database in azured mediterranean sea or tech racer to get more amazon power, instead under heavy violent high-pressure thunderstorms.

If you like more european clouds, I found https://clouding.io/ in Barcelona and transfered Paris amazon location to it. Spanish cloud in Madrid and US in west virginia is still amazon.

You know why?

Because a lot of companies with 1-2 business application mostley hammer their own database from inside and produce them self a lot of traffic and database load, because they want to keep their business important. 
Moving an application and database to the cloud is truly truthfulness,because it allows you to better understand attitudes of customers, internal users and bots, who visit your application. A realisitc view is better to plan for the future and rethink strategies of re-.growing your business. If you want to make direct SQL-Queries like in scenario 1 from your local network, you could easy build a VPN to synced database in the cloud.
If you want to grow, you can dynamically and quickly scale up CPUs, memory, and disk space in the cloud.

2025-10-20

Die Anzahl der Anordnungen der Elemente einer endlichen Menge

Prolog

Wenn Studenten im Sommersemster 1992 in der Vorlesung Graphentheorie und Kombinatorik von Prof. Gerd Baron lauter wurden, nebenbei am Laptop für andere Übungen zu koodieren begannen oder sich zu unterhalten oder zu Essen begannen, dann wiederholte Professor Baron mit lauter Stimme:

Wir haben hier ein Universum und es geht um 
die Anzahl der Anordnungen der Elemente einer endlichen Menge.

We have a universe here and 
it's all about of the number of combinations of items in a finite set.

Professor Baron war für die Entstehung der Vorlesung + Übung Graphentheorie und Kombinatorik als zusätliches Fach zu Analysis, Algebra und linearer Algebra  für Informatiker mitentscheidend. Prof. Baron war der Meinung, dass Graphentheorie (inklusive gewichteter Pfade + Adjazenzmatrix Darstellung) für Informatiker wegen Verständnis von Routing Tabellen ip routing graph und Suche nach dem kürzestem Routing Pfad und Algorithmen wie dem traveling salesmen essentliell seien und Kombinatorik für Informatiker wegen oft vieler fast gleichwertiger Lösungsmöglichkeiten essentiell sei:


In den Jahren 2021-2023 [ CV ] implementierte ich nach der Idea von Georg Toth mit ihm gemeinsam SUPU (SUdocu PUzzle). Für das Feature "Game Automation", wo der Computer die Hälte des Spielbretts automatisch vorlegt und der Spieler nur noch die obere Hälfte selbst setzen muss. brauchte ich eine heuristischen einfachen, aber genügend performanten Algorithmus mit lauter unterschiedlichen Kombinationen pro Durchlauf für den Computer und ich erinnerte mich an Professor Baron.


Nach einem Treffen mit meinem alten Freund, dem Mathematik- und Physikprofessor Michael F. (der ebenfalls im Finanzsektor in der Londoner City tätig war), und unserem Gespräch über invertierbare Matrizen, wurde ich nachts mit einigen technischen Hilfsmittlen penetriert und äußerte meine Idee laut. Anstatt die Information jedoch nur Unbekannten (vielleicht russischen oder rechtsextremen Spionen) zukommen zu lassen, verfasste ich diesen Artikel, damit jeder, auch alle Partner in den USA, davon Kenntnis nimmt.

Einfachste Art AES nach oben zu skalieren:
Kombinieren mehrerer Blockciphers mit Permutation

Verschlüsselung: plain text ⟶ 3DES PBox → AES → 2-fish ⟶ cipher bytes
Entschlüsselung: cipher bytes ⟶ 2-fish → AES → 3DES SBox ⟶ plain text

Verschlüsselung: (zuletzt base64 mime kodieren oder uuencode für ASCII Cipher Text)
plain text ⟶ AES ⟶ 2-fish⟶ 3DES PBox (scrambled) ⟶ base64 ⟶ cipher ascii

Entschlüsselung: (zuerst base64 oder uudecode und dann symmetrische Entschlüsselung)
cipher 
ascii⟶ base64 ⟶ 3DES  SBox(scrambled) → 2-fish→ AES ⟶ plain text

Man kann jetzt natürlich durch Enumerierung der einzelnen Symmetrischen Cipher Algorithmen eine Pipe skizzieren:
3DES = 0x1
AES = 0x2
2Fish = 0x4
Serpent = 0x8

Hexedezimal 0x148 für Verschlüsseln bedeuted 0x841 für Entschlüsseln.
plain ⟶ (3DES→
2Fish→Serpent) ⟶⟶ encrypted
encrypted ⟶ (Serpent→2Fish→3DES) ⟶ plain 

Beispiele für Kombinationen von mehreren symmetrischen Ciffrier-Algoríthmen:

Mathematisches Lemma (Funktionentheorie) lautet in etwa:

Angenommen, es ∃ ein-ein-deutige deterministische umkehrbare Funktionen, wo es zu jeder Funktion y=F(x,...) eine entsprechende Umkehrfunktion x =f(y,..) gibt =>, 
dann ∃ zur Funktionenkette y = F( G( H( I( J( K( L( M( N(x, ...))))))))) 
die Umkehrfunktion x = n( m( l( k( j( i( h( g( f(y,...))))))))).

Ansatz eines mathematischen Beweises

Man kann jede Abbildung von ascii8 → ascii8 
immer auch als Matrix vom R256 ➝ R256 betrachten.

8-fache umkehrbare blockweise ver-/ent-schlüsselnde  Funktionskette:

Probier einmal mein Online Webformular aus:
https://area23.at/net/Crypt/CoolCrypt.aspx

Github repository: github.com/heinrichelsigan/area23.at/


Ein einfacher Matrixverschlüsselungsalgorithmus von mir selbst:

Ich habe einen einfachen symmetrischen Matrixverschlüsselungsalgorithmus gefunden, der als einfache symmetrische Chiffre funktioniert mit NxN-Matrix-Transformation, nachdem ich diese Frage hier auf math.stackexchange.com/questions/4915786/  gestellt hatte.

Später entwickelte ich einen sehr einfachen Blockchiffre-Algorithmus namens ZenMatrix (um zu zeigen, dass ich selbst eine sehr einfache symmetrische Blockchiffre für die Ver- und Entschlüsselung schreiben kann)

R3 ➝ R3: v(3) x M(3,3) = v(3)

⎡ 1 ⎤    ⎡ 0 1 0 ⎤    ⎡ 2 ⎤ 
⎢ 2 ⎥ x  ⎢ 0 0 1 ⎥ =  ⎢ 3 ⎥  
⎣ 3 ⎦    ⎣ 1 0 0 ⎦    ⎣ 1 ⎦ 
Inverse Matrix für umgekehrte symmetrische Verschlüsselung wäre:
⎡ 2 ⎤    ⎡ 0 0 1 ⎤    ⎡ 1 ⎤ 
⎢ 3 ⎥ x  ⎢ 1 0 0 ⎥ =  ⎢ 2 ⎥  
⎣ 1 ⎦    ⎣ 0 1 0 ⎦    ⎣ 3 ⎦ 
ZenMatrix symetric chiffre encryption

Es stehen nun weitere symmetrische Verschlüsselungsalgorithmen zur Verfügung!

Zuerst wollte ich die symmetrische Verschlüsselungspipeline nur mit AES, Blowfish, 2-Fish, 3-DES und ZenMatrix realisieren. Dann stieß ich jedoch auf die Legion von Bouncy-Castle, die mehrere Verschlüsselungen in einer Open-Source-Bibliothek anbietet, die auch hier auf GitHub verfügbar ist: https://github.com/bcgit. Daraufhin habe ich Area23.At.Mono mit dem Bouncy-Castle-Wrapper für 3DES, 2FISH, 3FISH, AES, Rijndael (entspricht AES) und Serpent neu geschrieben.

Später fügte ich der symmetrischen Verschlüsselungspipeline die folgenden Algorithmen hinzu, da ich sie im Bouncy-Castle-Paket gesehen hatte: Camellia, Cast[56], Gost28147, Idea, RC[26], RC532, Seed, Skipjack, Tea, Tnepres und XTea.

CryptPipe [WinForm Demo]

Ich schrieb eine einfache WinForm-Anwendung mit reduziertem Framework-Code, um die grundlegende SymmCipher-Pipe-Verschlüsselung zu verstehen. Sie ist hier auf GitHub zu finden: https://github.com/heinrichelsigan/CryptPipe

https://github.com/heinrichelsigan/PermAgainCrypt

Wie viele Variationen sind möglich?

Bei zwei symmetrischen Verschlüsselungsalgorithmen
ohne Wiederverwendung wäre der Wert 2! =
2, 
bei Wiederverwendung (z. B. Blowfish => Blowfish =>) 2² = 4. 

Bei acht symmetrischen Verschlüsselungsalgorithmen ohne Wiederverwendung wäre der Wert 8! = 40,320, bei Wiederverwendung 8⁸ = 16,777,216.

In der oben beschriebenen symmetrischen Verschlüsselungspipeline mit nun 21 symmetrischen Verschlüsselungsalgorithmen wäre der Wert 2¹⁸ = 37,822,859,361,
da die Pipeline-Länge auf acht Stufen begrenzt ist.

Warum veröffentliche ich diesen Artikel?

Leider neige ich seit meiner Diagnose einer schizoaffektiven Störung im Jahr 2007 manchmal dazu, laut zu sprechen und habe oft Angst, abgehört zu werden. Selbst größere Unternehmen, bei denen ich angestellt war (ich habe ihnen seit 2007 von meinem Problem erzählt), meinten, ich hätte in diesem Fall nicht gegen die Vorschriften verstoßen, da ich davon ausgehe, dass wir hier nicht die DDR mit der Stasi haben und das laute Wiederholen von Betrugserkennungsregeln zu Hause kein Verbrechen ist. Einmal fühlte ich mich sehr unwohl und sprach laut meine Idee für ein besseres AES aus. Um zu vermeiden, dass nur einige Leute sie verstehen würden, schrieb ich einen einfachen Prototyp und schickte diesen Artikel dann an alte Freunde, die in US-Unternehmen arbeiten.