cr.yp.to update

[email protected] 28 May 2005 19:09:34 -0000
Newsgroups gmane.comp.djb.announce
Message-ID <[email protected]>
diff -ru .old-crypto/conferences.html cr.yp.to/conferences.html
--- .old-crypto/conferences.html	2005-05-13 07:33:20.000000000 -0400
+++ cr.yp.to/conferences.html	2005-05-28 00:53:07.000000000 -0400
@@ -393,7 +393,7 @@
 Paris.
 Travel funded by conference.
 <p>
-2005.05.22-2005.05.26, refereed, plan to attend:
+2005.05.22-2005.05.26, refereed, attended:
 Eurocrypt 2005.
 <a href="http://www.brics.dk/eurocrypt05/">http://www.brics.dk/eurocrypt05/</a>;
 <a href="conferences/2005-eurocrypt/www.brics.dk/eurocrypt05/index.html">mirror</a>.
@@ -402,7 +402,7 @@
 Have purchased ORD-CPH-ORD. Will take train from CPH.
 Have reserved hotel room for 22 May 2005 to 28 May 2005.)
 <p>
-2005.05.26-2005.05.27, refereed, plan to attend:
+2005.05.26-2005.05.27, refereed, attended:
 ECRYPT STVL Workshop on Symmetric Key Encryption (SKEW).
 <a href="http://www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl/">http://www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl</a>;
 <a href="conferences/2005-skew/www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl/index.html">mirror</a>.
@@ -415,8 +415,8 @@
 Quo Vadis Cryptology? Advances in Cryptanalysis.
 Warsaw, Poland.
 (Registration unnecessary.
+Have purchased AAR-CPH train.
 Have purchased CPH-WAW-CPH.
-Need to arrange AAR-CPH train.
 Organizers have reserved hotel room for 28 May 2005 to 2 June 2005.)
 <p>
 2005.05.31-2005.06.02, invited, plan to attend:
@@ -445,10 +445,12 @@
 Universidad de Cantabria, Santander, Spain.
 (Have registered.
 Have purchased ORD-LHR.
+Have to figure out LHR-STN.
+Have purchased STN-SDR.
 Have to figure out LHR-Santander; probably via Stansted.
-Have reserved hotel room from 28 June to 10 July.)
+Have reserved hotel room from 28 June to 11 July.)
 <p>
-2005.07.14-2005.07.15, contemplating:
+2005.07.14-2005.07.15, plan to attend:
 ECRYPT Workshop on RFID and Lightweight Crypto.
 Graz, Austria.
 <p>
diff -ru .old-crypto/cv.html cr.yp.to/cv.html
--- .old-crypto/cv.html	2005-05-14 04:39:38.000000000 -0400
+++ cr.yp.to/cv.html	2005-05-23 11:05:07.000000000 -0400
@@ -52,6 +52,10 @@
 to Proceedings of the STVL Workshop on Symmetric Key Encryption.
 <li>2005.05.13: Salsa20 has been accepted
 to Proceedings of the STVL Workshop on Symmetric Key Encryption.
+<li>2005.05.19: Gave invited seminar talk at
+<a href="talks.html#2005.05.19">Denmark Technical University</a>.
+<li>2005.05.23: Gave refereed conference talk at
+<a href="talks.html#2005.05.23">Eurocrypt 2005</a>.
 </ul>
 Also a clarification:
 I should have said in Section 4 of activities-20050107
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html	2005-05-21 16:35:24.000000000 -0400
+++ cr.yp.to/streamciphers.html	2005-05-28 06:11:23.000000000 -0400
@@ -13,35 +13,47 @@
 to settle on a new encryption standard
 that simultaneously provides higher confidence and higher speed than AES.
 <p>
-Here are the submissions I've heard about:
+Here are the submissions I've heard about,
+in order of presentation at or after the SKEW workshop:
 <ul>
-<li>Self-Synchronous SOBER (SSS), by Rose, Hawkes, Paddon, and de Vries:
-<a href="http://people.qualcomm.com/ggr/NLS-SSS.html">http://people.qualcomm.com/ggr/NLS-SSS.html</a>.
-<li>Non-Linear SOBER (NLS), by Rose, Hawkes, Paddon, and de Vries:
-<a href="http://people.qualcomm.com/ggr/NLS-SSS.html">http://people.qualcomm.com/ggr/NLS-SSS.html</a>.
+<li>My own <a href="snuffle.html">Salsa20</a>, aka Snuffle 2005.
 <li>Rabbit, by Boesgaard, Vesterager, and Zenner:
 <a href="http://www.cryptico.com/Default.asp?ID=10">http://www.cryptico.com/Default.asp?ID=10</a>.
-<li>My own <a href="snuffle.html">Salsa20</a>, aka Snuffle 2005.
 <li>SOSEMANUK, by Berbain et al.
 <li>Mir-1, by Maximov.
-<li>Phelix, by Whiting, Schneier, Lucks, and Muller.
-<li>TSC-3, by Hong, Lee, Yeom, Han, and Chee.
-<li>F-FCSR-8, by Arnault, Berger, and Lauradoux.
-<li>F-FCSR-H, by Arnault, Berger, and Lauradoux.
-<li>Achterbahn, by Gammel, Goettfert, and Kniffler.
+<li>Phelix, by Whiting, Schneier, Lucks, and Muller:
+<a href="http://www.schneier.com/paper-phelix.html">http://www.schneier.com/paper-phelix.html</a>.
+<li>TSC-3, by Hong, Lee, Yeom, Han, and Chee. Aimed at hardware.
+<li>F-FCSR-8, by Arnault, Berger, and Lauradoux. Aimed at hardware.
+<li>F-FCSR-H, by Arnault, Berger, and Lauradoux. Aimed at hardware.
+<li>Achterbahn, by Gammel, Goettfert, and Kniffler. Aimed at hardware.
 <li>SFINKS, by Braeken, Lano, Mentens, Preneel, and Verbauwhede.
-<li>WG, by Nawaz and Gong.
+Aimed at hardware.
+<li>WG, by Nawaz and Gong. Aimed at hardware.
 <li>Py, by Biham and Seberry.
 <li>Mosquito, by Daemen and Kitsos.
+Aimed at hardware.
+``More of a research object than a standard proposal,'' Daemen says.
 <li>Polar Bear, by Hastad and Naeslund.
 <li>Edon80, by Gligoroski, Markovski, Kocarev, and Gusev.
+Aimed at hardware.
 <li>CJCSG, by Jansen, Helleseth, and Kholosha.
+Aimed at hardware.
 <li>DECIM, by Berbain et al.
+Aimed at hardware.
 <li>MICKEY, by Babbage and Dodd.
+Aimed at hardware.
+<li>MICKEY-128, by Babbage and Dodd.
+Aimed at hardware.
 <li>YAMB, by Lebedev, Ivanov, Starodubtzev, and Kolchkov.
-<li>LEX, by Buryukov.
+<li>LEX, by Biryukov.
 <li>Fubuki, by Matsumoto, Nishimura, Hagita, and Saito.
-<li>ABC, by Anashin, Bogdanov, Kizhvatov, and Bogdanov.
+<li>ABC, by Anashin, Bogdanov, and Kizhvatov.
+<li>DICING, by An-Ping.
+<li>Non-Linear SOBER (NLS), by Rose, Hawkes, Paddon, and de Vries:
+<a href="http://people.qualcomm.com/ggr/NLS-SSS.html">http://people.qualcomm.com/ggr/NLS-SSS.html</a>.
+<li>Self-Synchronous SOBER (SSS), by Rose, Hawkes, Paddon, and de Vries:
+<a href="http://people.qualcomm.com/ggr/NLS-SSS.html">http://people.qualcomm.com/ggr/NLS-SSS.html</a>.
 </ul>
 <p>
 Why is it reasonable to believe that a new design process
@@ -65,6 +77,157 @@
 constant-time high-speed AES software for modern CPUs.
 </ul>
 A new cipher can avoid these structural errors.
+<h2>Notes on Rabbit</h2>
+Authors report, for a Pentium III-1000,
+278 cycles to load a 16-byte key;
+plus 253 cycles to load a nonce;
+plus 3.7 cycles/byte to encrypt a big block.
+For a Pentium 4,
+468 cycles to load a 16-byte key;
+plus 420 cycles to load a nonce;
+plus 5.1 cycles/byte to encrypt a big block.
+Also speed reports for ARM7 and MIPS.
+<p>
+Low-level operations:
+addition;
+addition with carry;
+squaring of a 32-bit input, with the 64-bit output
+folded by xor into a 32-bit result;
+rotation by multiples of 8 bits;
+and some other byte shuffling as part of key setup.
+<p>
+Each 16-byte output block involves 8 squarings and various other operations.
+<h2>Notes on Phelix</h2>
+Authors report,
+for a Pentium M,
+810 cycles to prepare a 32-byte key and a 16-byte nonce;
+plus about 6.6 cycles/byte to encrypt a big block.
+For a Pentium 4,
+1100 cycles to prepare a 32-byte key and a 16-byte nonce;
+plus about 10 cycles/byte to encrypt a big block.
+<p>
+Low-level operations:
+addition;
+xor;
+constant-distance rotation.
+<p>
+Includes authentication.
+Unusual in this respect;
+pretty much everyone else relies on a separate MAC.
+Comparing Phelix speed to the speed of other stream ciphers
+requires quantifying the speed of a separate MAC.
+<p>
+Each Phelix block feeds the input through
+13 adds, 11 xors, and 20 rotations
+to produce a 4-byte block of output.
+Overall 11 operations per byte.
+Key expansion takes a few additional operations per block.
+For comparison, Salsa20 performs 15 operations per byte,
+plus final xoring, plus the cost of authentication.
+<h2>Notes on SOSEMANUK</h2>
+Key length between 16 bytes and 32 bytes.
+Nonce length: 16 bytes.
+Inspired by SNOW 2.0 and SERPENT.
+<p>
+48-byte ``internal state size.''
+4096-byte ``data.''
+<p>
+Authors report, for a Pentium 4,
+900 cycles to load a key,
+and 480 cycles to load a nonce.
+Time, in cycles/byte, to encrypt a big block:
+5.575 Pentium 3;
+6.775 Pentium 4-M;
+7.075 Pentium 4 Prescott;
+4.925 Pentium 4 Nocona;
+4.25 Athlon XP;
+3.15 PowerPC 7450 (G4e);
+5.40 PowerPC 970 (G5);
+3.925 Alpha EV67;
+5.975 UltraSPARC III.
+<h2>Notes on Mir-1</h2>
+16-byte key,
+8-byte nonce,
+48-byte ``internal state size.''
+<p>
+Low-level operations: xor, and, or, addition mod 2^64,
+multiplication mod 2^64.
+Also uses the Rijndael S-boxes in initialization.
+<p>
+Author reports, for a Pentium 4,
+11149 cycles to load a key;
+693 cycles to load a nonce;
+314 cycles per block (39.25 cycles/byte, I believe) to encrypt a big block.
+I think that the same function could be computed at considerably higher speed.
+<h2>Notes on Py</h2>
+Authors report, for a Pentium III,
+2727 cycles to load a key;
+4092 cycles to load a nonce;
+2.85 cycles/byte to encrypt a big block.
+For an UltraSPARC,
+2622 cycles to load a key;
+5492 cycles to load a nonce;
+5.78 cycles/byte to encrypt a big block.
+For a PowerPC (unspecified model),
+2891 cycles to load a key;
+5003 cycles to load a nonce;
+4.1 cycles/byte to encrypt a big block.
+<p>
+The secret indices bother me:
+surely Py is vulnerable to timing attacks.
+The large message-setup time also bothers me:
+low-overhead ciphers such as Salsa20
+will already have finished encrypting an average-size Internet packet
+before Py has finished loading a nonce.
+<h2>Notes on Polar Bear</h2>
+Key length: as large as 16 bytes?
+Nonce length: as large as 32 bytes.
+Authors say ``Significantly faster than RC4 on short packets.
+Longer packets: RC4 is 50-100% faster.''
+<p>
+The paper's speed results are about 58 cycles per byte
+on a 1400MHz Pentium 4, plus about 800 cycles for setup.
+In what fantasy world is this even remotely comparable to RC4 speed?
+<p>
+Low-level operations: kitchen sink.
+Many opportunities for timing attacks.
+<h2>Notes on YAMB</h2>
+Key as large as 32 bytes.
+Nonce as large as 16 bytes.
+380 bytes of memory.
+Authors report 12.5 cycles/byte for Pentium 4.
+<h2>Notes on LEX</h2>
+``Leak extraction'' from AES.
+Specifically, extracts 320 bits from each AES encryption;
+about 2.5 times faster than AES.
+<p>
+Will be vulnerable to timing attacks for the same reason that AES is.
+<h2>Notes on Fubuki</h2>
+Authors report, for a Pentium M,
+489662 cycles for setup,
+plus 133 cycles/byte to encrypt a big block.
+Uses Mersenne Twister, by Matsumoto and Nishimura.
+<h2>Notes on ABC</h2>
+Key length: 16 bytes.
+Nonce length: 16 bytes.
+Authors report Pentium 4 speeds
+under 4 cycles per byte.
+<p>
+Low-level operations:
+addition, xor, and, or, constant-distance shift, dot product.
+The dot product takes bits b_0,b_1,...,b_{31}
+and 32-bit integers e_0,e_1,...,e_{31}
+and computes the sum e_0 b_0 + e_1 b_1 + ... + e_{31} b_{31}.
+Every 4 bytes of output have one dot product and several other operations.
+<p>
+The reported speed of ABC relies on computing the dot product
+by secret-index table lookups,
+exposing ABC to timing attacks.
+<h2>Notes on DICING</h2>
+Author reports, for an 1800MHz Athlon XP,
+918 cycles to load a 16-byte key;
+plus 57600 cycles to load a nonce;
+plus 24 cycles/byte to encrypt a big block.
 <h2>Notes on NLS</h2>
 Page 17 of the NLS document
 reports, for a 1500MHz Centrino,
@@ -80,22 +243,5 @@
 That's twice the time taken by Poly1305.
 <p>
 No speed reports for other CPUs.
-<h2>Notes on Rabbit</h2>
-Authors report, for a Pentium III-1000,
-278 cycles to load a 16-byte key;
-plus 253 cycles to load a nonce;
-plus 3.7 cycles/byte to encrypt a big block.
-<p>
-Low-level operations:
-addition;
-addition with carry;
-64-bit squaring, folded by xor into a 32-bit result;
-rotation by multiples of 8 bits;
-and some other byte shuffling as part of key setup.
-<p>
-Also speed reports for ARM7 and MIPS.
-No speed reports for big CPUs other than the Pentium.
-<p>
-Each 16-byte output block involves 8 squarings and various other operations.
 </body>
 </html>
Binary files .old-crypto/talks/20050519.pdf and cr.yp.to/talks/20050519.pdf differ
Binary files .old-crypto/talks/20050523.pdf and cr.yp.to/talks/20050523.pdf differ
Binary files .old-crypto/talks/20050526.pdf and cr.yp.to/talks/20050526.pdf differ
Binary files .old-crypto/talks/20050527.pdf and cr.yp.to/talks/20050527.pdf differ
diff -ru .old-crypto/talks.html cr.yp.to/talks.html
--- .old-crypto/talks.html	2005-05-21 16:47:12.000000000 -0400
+++ cr.yp.to/talks.html	2005-05-28 01:08:10.000000000 -0400
@@ -1023,27 +1023,27 @@
 <a name="2005.05.23">2005.05.23</a>
 16:10-16:35,
 refereed conference talk
-<a href="talks/20050523.pdf">[tentative PDF slides]</a>:
+<a href="talks/20050523.pdf">[PDF slides]</a>:
 Eurocrypt 2005.
 <a href="http://www.brics.dk/eurocrypt05/">http://www.brics.dk/eurocrypt05/</a>;
 <a href="conferences/2005-eurocrypt/www.brics.dk/eurocrypt05/index.html">mirror</a>.
 Scandinavian Congress Center, Aarhus, Denmark.
 ``Stronger security bounds for Wegman-Carter-Shoup authenticators.''
 <p>
-2005.05.26
-10min,
+<a name="2005.05.26">2005.05.26</a>
+14:15-14:27,
 refereed conference talk
-<a href="talks/20050526.pdf">[tentative PDF slides]</a>:
+<a href="talks/20050526.pdf">[PDF slides]</a>:
 ECRYPT STVL Workshop on Symmetric Key Encryption (SKEW).
 <a href="http://www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl/">http://www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl</a>;
 <a href="conferences/2005-skew/www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl/index.html">mirror</a>.
 Scandinavian Congress Center, Aarhus, Denmark.
 ``The Salsa20 stream cipher.''
 <p>
-2005.05.27
-10min,
+<a name="2005.05.27">2005.05.27</a>
+10:45-10:57,
 refereed conference talk
-<a href="talks/20050527.pdf">[tentative PDF slides]</a>:
+<a href="talks/20050527.pdf">[PDF slides]</a>:
 ECRYPT STVL Workshop on Symmetric Key Encryption (SKEW).
 <a href="http://www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl/">http://www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl</a>;
 <a href="conferences/2005-skew/www2.mat.dtu.dk/people/Lars.R.Knudsen/stvl/index.html">mirror</a>.