cr.yp.to update

[email protected] 31 May 2005 06:10:01 -0000
Newsgroups gmane.comp.djb.announce
Message-ID <[email protected]>
diff -ru .old-crypto/conferences.html cr.yp.to/conferences.html
--- .old-crypto/conferences.html	2005-05-28 00:53:07.000000000 -0400
+++ cr.yp.to/conferences.html	2005-05-29 14:09:02.000000000 -0400
@@ -390,6 +390,8 @@
 <p>
 2005.02.24-2005.02.25, invited, attended:
 Special-purpose Hardware for Attacking Cryptographic Systems (SHARCS).
+<a href="http://www.sharcs.org">http://www.sharcs.org</a>;
+mirror.
 Paris.
 Travel funded by conference.
 <p>
@@ -413,6 +415,8 @@
 <p>
 2005.05.30-2005.05.30, invited, plan to attend:
 Quo Vadis Cryptology? Advances in Cryptanalysis.
+<a href="http://ece.gmu.edu/quovadis/quovadis3/quovadis3.htm">http://ece.gmu.edu/quovadis/quovadis3/quovadis3.htm</a>;
+mirror.
 Warsaw, Poland.
 (Registration unnecessary.
 Have purchased AAR-CPH train.
diff -ru .old-crypto/cv.html cr.yp.to/cv.html
--- .old-crypto/cv.html	2005-05-23 11:05:07.000000000 -0400
+++ cr.yp.to/cv.html	2005-05-30 18:15:09.000000000 -0400
@@ -17,13 +17,13 @@
 <a href="papers.html#easycbc">easycbc</a>.
 <li>2005.01.10:
 <a href="papers.html#poly1305">poly1305</a>
-has been accepted to Proceedings of FSE 2005.
+has been accepted to FSE 2005.
 <li>2005.01.13: Posted revision of poly1305.
 <li>2005.01.19: Posted 2004.11.13 revision of
 <a href="papers.html#powers2">powers2</a>.
 <li>2005.01.28:
 <a href="papers.html#securitywcs">securitywcs</a>
-has been accepted to Proceedings of Eurocrypt 2005.
+has been accepted to Eurocrypt 2005.
 <li>2005.02.06:
 <a href="papers.html#quartic">quartic</a>
 has been accepted to Mathematics of Computation.
@@ -48,14 +48,18 @@
 <a href="snuffle.html">Salsa20</a> documentation.
 <li>2005.05.04: Corrected publisher errors in poly1305.
 <li>2005.05.09: Posted revision of powers2.
-<li>2005.05.13: bruteforce has been accepted
-to Proceedings of the STVL Workshop on Symmetric Key Encryption.
-<li>2005.05.13: Salsa20 has been accepted
-to Proceedings of the STVL Workshop on Symmetric Key Encryption.
+<li>2005.05.13: bruteforce has been accepted to SKEW 2005.
+<li>2005.05.13: Salsa20 has been accepted to SKEW 2005.
 <li>2005.05.19: Gave invited seminar talk at
 <a href="talks.html#2005.05.19">Denmark Technical University</a>.
 <li>2005.05.23: Gave refereed conference talk at
 <a href="talks.html#2005.05.23">Eurocrypt 2005</a>.
+<li>2005.05.26: Gave refereed conference talk at
+<a href="talks.html#2005.05.26">SKEW 2005</a>.
+<li>2005.05.27: Gave another refereed conference talk at
+<a href="talks.html#2005.05.27">SKEW 2005</a>.
+<li>2005.05.30: Gave invited conference talk at
+<a href="talks.html#2005.05.30">Quo Vadis Cryptology</a>.
 </ul>
 Also a clarification:
 I should have said in Section 4 of activities-20050107
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html	2005-05-28 12:23:37.000000000 -0400
+++ cr.yp.to/streamciphers.html	2005-05-30 09:04:15.000000000 -0400
@@ -31,6 +31,7 @@
 Aimed at hardware.
 <li>WG, by Nawaz and Gong. Aimed at hardware.
 <li>Py, by Biham and Seberry.
+<li>Py6, by Biham and Seberry.
 <li>Mosquito, by Daemen and Kitsos.
 Aimed at hardware.
 ``More of a research object than a standard proposal,'' Daemen says.
@@ -190,6 +191,7 @@
 2622 cycles to load a key;
 5492 cycles to load a nonce;
 5.78 cycles/byte to encrypt a big block.
+(I think this can be improved by nearly a factor of 2.)
 For a PowerPC (unspecified model),
 2891 cycles to load a key;
 5003 cycles to load a nonce;
@@ -201,6 +203,10 @@
 low-overhead ciphers such as Salsa20
 will already have finished encrypting an average-size Internet packet
 before Py has finished loading a nonce.
+<h2>Notes on Py6</h2>
+Scaled-down version of Py.
+Smaller key-loading time and nonce-loading time;
+same cycles/byte to encrypt a big block.
 <h2>Notes on Polar Bear</h2>
 Key length: as large as 16 bytes?
 Nonce length: as large as 32 bytes.
@@ -221,6 +227,9 @@
 Nonce as large as 16 bytes.
 380 bytes of memory.
 Authors report 12.5 cycles/byte for Pentium 4.
+<p>
+Initial impression:
+Timing-attack problems, like RC4.
 <h2>Notes on LEX</h2>
 ``Leak extraction'' from AES.
 Specifically, extracts 320 bits from each AES encryption;
@@ -233,6 +242,8 @@
 489662 cycles for setup,
 plus 133 cycles/byte to encrypt a big block.
 Uses Mersenne Twister, by Matsumoto and Nishimura.
+<p>
+Initial impression: So slow that nobody will look at it.
 <h2>Notes on ABC</h2>
 Key length: 16 bytes.
 Nonce length: 16 bytes.
New: talks/20050530.pdf
diff -ru .old-crypto/talks.html cr.yp.to/talks.html
--- .old-crypto/talks.html	2005-05-28 01:08:10.000000000 -0400
+++ cr.yp.to/talks.html	2005-05-30 09:16:34.000000000 -0400
@@ -994,6 +994,8 @@
 invited conference talk
 <a href="talks/20050225.pdf">[PDF slides]</a>:
 Special-purpose Hardware for Attacking Cryptographic Systems (SHARCS).
+<a href="http://www.sharcs.org">http://www.sharcs.org</a>;
+mirror.
 ``Building circuits for integer factorization.''
 Abstract: ``I'll present my latest work on <i>verifiable</i>
 upper bounds for the money and time needed to factor 1024-bit integers.
@@ -1053,8 +1055,10 @@
 <a name="2005.05.30-1">2005.05.30</a>
 11:00-12:30,
 invited conference talk
-[PDF slides not available yet]:
+<a href="talks/20050530.pdf">[PDF slides]</a>:
 Quo Vadis Cryptology? Advances in Cryptanalysis.
+<a href="http://ece.gmu.edu/quovadis/quovadis3/quovadis3.htm">http://ece.gmu.edu/quovadis/quovadis3/quovadis3.htm</a>;
+mirror.
 Warsaw, Poland.
 ``The power of parallel computation.''
 Abstract:
@@ -1068,8 +1072,11 @@
 <p>
 <a name="2005.05.30-2">2005.05.30</a>
 16:00-17:30,
-invited panelist.
+invited panelist
+[no slides].
 Quo Vadis Cryptology? Advances in Cryptanalysis.
+<a href="http://ece.gmu.edu/quovadis/quovadis3/quovadis3.htm">http://ece.gmu.edu/quovadis/quovadis3/quovadis3.htm</a>;
+mirror.
 Warsaw, Poland.
 ``Advances in factorization.''
 <p>