Can an OpenPGP public and private key pair can have different key ID (short key ID)?

Viewed 1303

Can an OpenPGP public and a private key pair, which can be used for encryption and decryption successfully, have different key IDs (short key IDs)?

What I have tried:

  1. I have used Bouncy Castle (C#) to get the short key id for a test OpenPGP public and private key pair provided to me, the key ID for the OpenPGP key pair always comes as the same.
  2. I have Checked on GPG4Win Kleopatra with the same observation.
  3. I have Gone through the PGP FAQ but could not get the answer.

It seems logical to have the same key ID for an OpenPGP key pair but is there any possibility/way to have different key IDs for a single key pair?

I need this information, as I need to save the OpenPGP key ID in the database table for the OpenPGP key pair.If it's the same, I can have only one column for storing the Key ID.

2 Answers

Public and Private Keys of a Key Pair Share Their Fingerprint

RFC 4880, OpenPGP, 12.2. Key IDs and Fingerprints defines:

A V4 fingerprint is the 160-bit SHA-1 hash of the octet 0x99, followed by the two-octet packet length, followed by the entire Public-Key packet starting with the version field.

With other words, all fingerprints are calculated from the public key material only. Key IDs (both long and short) are derived from the fingerprint by cutting off the lower bytes.

fingerprint: 0D69 E11F 12BD BA07 7B37  26AB 4E1F 799A A4FF 2279
long id:                                    4E1F 799A A4FF 2279
short id:                                             A4FF 2279

OpenPGP Short Key ID Collision Attacks

Important note: short key IDs are vulnerable to collision attacks. When handling key IDs, especially for programmatic access and storing references to keys, never use short key IDs but the full fingerprint.

According to:

https://datatracker.ietf.org/doc/rfc4880/?include_text=1

that might give you some insight on how the Id is formed. From

3.3. Key IDs

A Key ID is an eight-octet scalar that identifies a key.
Implementations SHOULD NOT assume that Key IDs are unique. The
section "Enhanced Key Formats" below describes how Key IDs are
formed.

I would presume that storing this ID is futile, as they are NOT unique - you can have collisions of different keys using the same keyId.

12.2. Key IDs and Fingerprints

For a V3 key, the eight-octet Key ID consists of the low 64 bits of the public modulus of the RSA key.

The fingerprint of a V3 key is formed by hashing the body (but not the two-octet length) of the MPIs that form the key material (public
modulus n, followed by exponent e) with MD5. Note that both V3 keys
and MD5 are deprecated.

A V4 fingerprint is the 160-bit SHA-1 hash of the octet 0x99,
followed by the two-octet packet length, followed by the entire
Public-Key packet starting with the version field. The Key ID is the low-order 64 bits of the fingerprint.

Both V3 and V4 use the public part into account for the id, so it should be same for Public and Private key part.

BUT: If you reuse the data to create the same key (V4) over and over again it will have different KeyIDs because the creation time stamp is part of the Fingerprint which lower 64 bits form the KeyID and still be able to decipher stuff.

If you upgade a V3 to V4 they will have different IDs but decrypt same stuff.

Different Keys might have KeyIDs that are identical but not be able to decrypt the same stuff.

The KeyID is no "ID" in an absulute sense.

So answer would be : "For a PAIR - the keyID is identical as is ist based on length and public parts of the key only".

It is NOT an absolute identifier (aka - reading the public key KeyId, looking up a matching privates Key KeyID and deciphering something with that). The Fingerprint would be better suited for that - but still not 100%:

Note that it is possible for there to be collisions of Key IDs -- two different keys with the same Key ID. Note that there is a much smaller, but still non-zero, probability that two different keys have the same fingerprint.

Also note that if V3 and V4 format keys share the same RSA key material, they will have different Key IDs as well as different fingerprints.

Related