The Encryption Method That Could Protect Sensitive Information Forever
Researchers from BIU developed an encryption method designed to protect against adversaries attempting to decrypt confidential communications, even decades after the information was intercepted.
Imagine locking a confidential document inside a safe and sending it to its destination. What would happen if someone obtained the key to that safe ten years later?
In the world of cybersecurity, this scenario raises a critical question: If a digital encryption key is suddenly exposed years later, does the sensitive information transmitted in the past remain secure?
This troubling possibility lies at the heart of research conducted by Prof. Eylon Yogev and doctoral student Shani Ben-David from Bar-Ilan University’s Department of Computer Science and Artificial Intelligence.
“Suppose a hostile actor records Israel’s internet traffic over a period of many years,” Prof. Yogev explains. “Ten years later, the details of the key protecting that information are exposed because of a malfunction, a cyberattack, or even the emergence of a quantum computer. That actor could then attempt to retrospectively decrypt every message sent during the previous decade and search for sensitive information, such as the secret location of a nuclear weapon.”
How Can Information Remain Secure Indefinitely?
The volume of internet traffic generated by an entire country or organization is so enormous that no adversary could realistically store every encrypted message in its entirety for decades. The storage resources required would be vast and impractical.
“The primary concern is therefore that an attacker might find a way to compress the encrypted communication, store only a shortened version requiring significantly less memory, and wait patiently for the day when the encryption key is exposed,” the researchers explain.
To address this threat, their study, presented at the 2025 Theory of Cryptography Conference, introduces an innovative solution: “incompressible” encryption that can provide security for an unlimited period of time.
“Our paper examines precisely this scenario,” the researchers say. “It demonstrates that certain forms of encryption can prevent such an attack. Even if the key is exposed in the future, the attacker would have no choice but to retain all the encrypted messages in their entirety, because there would be no way to compress the communication without losing essential information.”
One of the study’s central discoveries is that achieving long-term security does not necessarily require new technologies. The researchers proved that any standard encryption method implemented with a sufficiently high security parameter can already provide this form of protection.
For example, widely used encryption systems such as AES, as implemented today, already offer a certain degree of protection against compression and future decryption, although there are limitations on the volume of information that can be protected in this way.
Like Discovering That Your Car Is Bulletproof
“At the beginning of the study, we tried to prove that security that is both incompressible and everlasting did not exist,” says doctoral student Shani Ben-David. “We were extremely surprised to discover that not only does it exist, but it can also be found in standard encryption systems that we already use every day. It is like driving an ordinary car and suddenly discovering that it is bulletproof.”
“This gives us a certain level of protection against future threats, even many years after the information was originally transmitted,” she adds.
The implications of the research extend far beyond theoretical cryptography. Yogev and Ben-David’s solution offers genuine protection against a threat known as “Harvest Now, Decrypt Later,” a strategy in which adversaries collect encrypted communications today in the hope of decrypting them in the future, once quantum computers become available or encryption keys are exposed.
The study also proposes a new way of defining efficiency in encryption systems by focusing on the “storage rate”: the relationship between the amount of information an attacker must retain and the total size of the encrypted communication.
In an era in which sensitive data may remain relevant for decades, this research introduces an important new tool to the information-security arsenal.