Analysis of RC4 Stream Cipher and Microsoft Office Document Security
Kejing He · Jisuanji gongcheng · 2009
According to the open information from the Microsoft official documents, the OpenOffice documents and the wvWare project, this paper studies the RC4 stream cipher and its implementation in the Office 97~2003.The analysis discovers that the default 40 bit encryption method used by Office 97-2003 is very weak and insecure.Coupling rainbow precomputation attack, the encryption can be broken in 1 min~2 min.This paper suggests users do not rely on the default 40 bitOffice 97/2000 Compatibleencryption to protect your confidential information.On the contrary, the 128 bitMicrosoft Enhanced Cryptographic Provideris preferred.It also recommends that users adopt the stronger encryption algorithm provided by compression softwares better when better security is necessary.