cr.yp.to update
[email protected] 16 Jun 2005 05:59:34 -0000
| Newsgroups | gmane.comp.djb.announce |
|---|---|
| Message-ID | <[email protected]> |
New: streamciphers/abc
New: streamciphers/achterbahn
New: streamciphers/decim
New: streamciphers/dicing
New: streamciphers/dragon-128
New: streamciphers/dragon-256
New: streamciphers/edon80
New: streamciphers/f-fcsr-8
New: streamciphers/f-fcsr-h
New: streamciphers/frogbit
New: streamciphers/fubuki
New: streamciphers/grain
New: streamciphers/hc-256
New: streamciphers/hermes8-128
New: streamciphers/hermes8-80
New: streamciphers/lex
New: streamciphers/mag
New: streamciphers/mickey
New: streamciphers/mickey-128
New: streamciphers/mir-1
New: streamciphers/mosquito
New: streamciphers/nls
New: streamciphers/phelix
New: streamciphers/polar-bear
New: streamciphers/pomaranch
New: streamciphers/py
New: streamciphers/py6
New: streamciphers/rabbit
New: streamciphers/salsa20
New: streamciphers/sfinks
New: streamciphers/sosemanuk
New: streamciphers/sss
New: streamciphers/trbdk3-yaea
New: streamciphers/trivium
New: streamciphers/tsc-3
New: streamciphers/vest-16
New: streamciphers/vest-32
New: streamciphers/vest-4
New: streamciphers/wg
New: streamciphers/yamb
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html 2005-06-14 12:31:14.000000000 -0400
+++ cr.yp.to/streamciphers.html 2005-06-16 01:09:04.000000000 -0400
@@ -8,88 +8,58 @@
ECRYPT
(<a href="http://www.ecrypt.eu.org">www.ecrypt.eu.org</a>),
a consortium of European research organizations,
-has issued a
-Call for Stream Cipher Primitives:
+issued a Call for Stream Cipher Primitives in November 2004:
<a href="http://www.ecrypt.eu.org/stream/">www.ecrypt.eu.org/stream</a>.
This is an exciting opportunity for the cryptographic community
to settle on a new encryption standard
that simultaneously provides higher confidence and higher speed than AES.
<p>
-Here are the submissions I've heard about,
-in order of presentation at or after the SKEW workshop:
-<ul>
-<li>My own <a href="snuffle.html">Salsa20</a>, aka Snuffle 2005.
-<li>Rabbit, by
-Martin Boesgaard, Mette Vesterager, Thomas Christensen, Erik Zenner:
-<a href="http://www.cryptico.com/Default.asp?ID=10">http://www.cryptico.com/Default.asp?ID=10</a>.
-<li>SOSEMANUK, by
-Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois,
-Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan,
-Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert.
-<li>Mir-1, by Alexander Maximov.
-<li>Phelix, by
-Doug Whiting, Bruce Schneier, Stephan Lucks, Frederic Muller:
-<a href="http://www.schneier.com/paper-phelix.html">http://www.schneier.com/paper-phelix.html</a>.
-<li>TSC-3, by
-Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee.
-<li>F-FCSR-8, by
-Thierry Berger, Francois Arnault, Cedric Lauradoux.
-<li>F-FCSR-H, by
-Thierry Berger, Francois Arnault, Cedric Lauradoux.
-<li>Achterbahn, by Berndt Gammel, Rainer Goettfert, Oliver Kniffler.
-<li>SFINKS, by
-An Braeken, Joseph Lano, Nele Mentens, Bart Preneel, Ingrid Verbauwhede.
-<li>WG, by Guang Gong, Yassir Nawaz.
-<li>Py, by Eli Biham, Jennifer Seberry.
-<li>Py6, by Eli Biham, Jennifer Seberry.
-<li>Mosquito, by Joan Daemen, Paris Kitsos.
-<li>Polar Bear, by Johan Haastad, Mats Naeslund.
-<li>Edon80, by
-Danilo Gligoroski, Smile Markovski, Ljupco Kocarev, Marjan Gusev.
-<li>CJCSG (POMARANCH), by Cees Jansen, Tor Helleseth, Alexander Kholosha.
-<li>DECIM, by
-Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois,
-Blandine Debraize, Henri Gilbert, Louis Goubin, Aline Gouget,
-Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin,
-Herve Sibert.
-<li>MICKEY, by Steve Babbage, Matthew Dodd.
-<li>MICKEY-128, by Steve Babbage, Matthew Dodd.
-<li>YAMB, by Lebedev, Ivanov, Starodubtzev, Kolchkov.
-<li>LEX, by Alex Biryukov.
-<li>Fubuki, by Makoto Matsumoto, Hagita Mariko, Takuji Nishimura, Matsuo Saito.
-<li>ABC, by Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar.
-<li>DICING, by Li An-Ping.
-<li>Dragon-128, by
-Ed Dawson, Kevin Chen, Matt Henricksen, William Millan,
-Leonie Simpson, HoonJae Lee, SangJae Moon.
-<li>Dragon-256, by
-Ed Dawson, Kevin Chen, Matt Henricksen, William Millan,
-Leonie Simpson, HoonJae Lee, SangJae Moon.
-<li>Frogbit, by Thierry Moreau.
-<li>Grain, by Martin Hell, Thomas Johansson, Willi Meier.
-<li>HC-256, by Hongjun Wu.
-<li>Hermes8-80, by Ulrich Kaiser.
-<li>Hermes8-128, by Ulrich Kaiser.
-<li>MAG, by Rade Vuckovac.
-<li>Non-Linear SOBER (NLS), by
-Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries:
-<a href="http://people.qualcomm.com/ggr/NLS-SSS.html">http://people.qualcomm.com/ggr/NLS-SSS.html</a>.
-<li>Self-Synchronous SOBER (SSS), by
-Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries:
-<a href="http://people.qualcomm.com/ggr/NLS-SSS.html">http://people.qualcomm.com/ggr/NLS-SSS.html</a>.
-<li>TRBDK3 YAEA, by
-Timothy Brigham.
-<li>Trivium, by
-Christophe De Canniere.
-<li>VEST-4, by
-Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman.
-<li>VEST-16, by
-Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman.
-<li>VEST-32, by
-Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman.
-<li>ZK-Crypt, by
-Carmi Gressel, Ran Granot, Gabi Vago.
-</ul>
+Over the next several months,
+a huge number of stream ciphers were submitted to ECRYPT:
+<table border>
+<tr><th>Name</th><th>Key size</th><th>Authors; policy</th><th>Documents</th></tr>
+<tr><td>ABC</td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td><a href="streamciphers/abc/abc.c">C</a> <a href="streamciphers/abc/desc.pdf">paper</a></td></tr>
+<tr><td>Achterbahn</td><td>10 bytes</td><td>Berndt Gammel, Rainer Goettfert, Oliver Kniffler</td><td><a href="streamciphers/achterbahn/desc.pdf">paper</a></td></tr>
+<tr><td>DECIM</td><td>10 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Blandine Debraize, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert</td><td><a href="streamciphers/decim/desc.pdf">paper</a></td></tr>
+<tr><td>DICING</td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc.pdf">paper</a></td></tr>
+<tr><td>Dragon-128</td><td>16 bytes</td><td>Ed Dawson, Kevin Chen, Matt Henricksen, William Millan, Leonie Simpson, HoonJae Lee, SangJae Moon</td><td><a href="streamciphers/dragon-128/dragon-ref.c">C</a> <a href="streamciphers/dragon-128/desc.pdf">paper</a></td></tr>
+<tr><td>Dragon-256</td><td>32 bytes</td><td>Ed Dawson, Kevin Chen, Matt Henricksen, William Millan, Leonie Simpson, HoonJae Lee, SangJae Moon</td><td><a href="streamciphers/dragon-128/dragon-ref.c">C</a> <a href="streamciphers/dragon-128/desc.pdf">paper</a></td></tr>
+<tr><td>Edon80</td><td>10 bytes</td><td>Danilo Gligoroski, Smile Markovski, Ljupco Kocarev, Marjan Gusev</td><td><a href="streamciphers/edon80/PartB1.pdf">desc</a> <a href="streamciphers/edon80/PartB2.pdf">robustness</a> <a href="streamciphers/edon80/PartB3.pdf">security</a> <a href="streamciphers/edon80/PartB4.pdf">advantages</a> <a href="streamciphers/edon80/PartB5.pdf">design</a> <a href="streamciphers/edon80/PartB6.pdf">speed</a> <a href="streamciphers/edon80/PartB7.pdf">impl</a></td></tr>
+<tr><td>F-FCSR-H</td><td>10 bytes</td><td>Thierry Berger, Francois Arnault, Cedric Lauradoux</td><td><a href="streamciphers/f-fcsr-8/B_SPECIF.PDF">paper</a></td></tr>
+<tr><td>F-FCSR-8</td><td>16 bytes</td><td>Thierry Berger, Francois Arnault, Cedric Lauradoux</td><td><a href="streamciphers/f-fcsr-8/B_SPECIF.PDF">paper</a></td></tr>
+<tr><td>Frogbit</td><td>16 bytes</td><td>Thierry Moreau</td><td><a href="streamciphers/frogbit/frogbit.pdf">paper</a></td></tr>
+<tr><td>Fubuki</td><td>16? bytes</td><td>Makoto Matsumoto, Hagita Mariko, Takuji Nishimura, Matsuo Saito</td><td><a href="streamciphers/fubuki/desc.pdf">paper</a></td></tr>
+<tr><td>Grain</td><td>10 bytes</td><td>Martin Hell, Thomas Johansson, Willi Meier</td><td><a href="streamciphers/grain/desc.pdf">paper</a></td></tr>
+<tr><td>HC-256</td><td>32 bytes</td><td>Hongjun Wu</td><td><a href="streamciphers/hc-256/desc.pdf">paper</a></td></tr>
+<tr><td>Hermes8-80</td><td>10 bytes</td><td>Ulrich Kaiser</td><td><a href="streamciphers/hermes8-128/desc.pdf">paper</a></td></tr>
+<tr><td>Hermes8-128</td><td>16 bytes</td><td>Ulrich Kaiser</td><td><a href="streamciphers/hermes8-128/desc.pdf">paper</a></td></tr>
+<tr><td>LEX</td><td>16 bytes</td><td>Alex Biryukov</td><td><a href="streamciphers/lex/desc.pdf">paper</a></td></tr>
+<tr><td>MAG</td><td></td><td>Rade Vuckovac</td><td><a href="streamciphers/mag/desc.pdf">paper</a></td></tr>
+<tr><td>MICKEY</td><td>10 bytes</td><td>Steve Babbage, Matthew Dodd</td><td><a href="streamciphers/mickey/desc.pdf">paper</a></td></tr>
+<tr><td>MICKEY-128</td><td>16 bytes</td><td>Steve Babbage, Matthew Dodd</td><td><a href="streamciphers/mickey/desc.pdf">paper</a></td></tr>
+<tr><td>Mir-1</td><td>16 bytes</td><td>Alexander Maximov</td><td><a href="streamciphers/mir-1/desc.pdf">paper</a></td></tr>
+<tr><td>Mosquito</td><td>12 bytes</td><td>Joan Daemen, Paris Kitsos</td><td><a href="streamciphers/mosquito/desc.pdf">paper</a></td></tr>
+<tr><td>Non-Linear SOBER (NLS)</td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/nls/nlsref.c">C</a> <a href="streamciphers/nls/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr>
+<tr><td>Phelix</td><td>32 bytes</td><td>Doug Whiting, Bruce Schneier, Stephan Lucks, Frederic Muller; ``We hereby explicitly release any intellectual property rights to Phelix into the public domain''</td><td><a href="streamciphers/phelix/phelix.c">C</a> <a href="streamciphers/phelix/desc.pdf">paper</a> <a href="http://www.schneier.com/paper-phelix.html">link</a></td></tr>
+<tr><td>Polar Bear</td><td>16? bytes</td><td>Johan Haastad, Mats Naeslund</td><td><a href="streamciphers/polar-bear/desc.pdf">paper</a></td></tr>
+<tr><td>POMARANCH (CJCSG)</td><td>16 bytes</td><td>Cees Jansen, Tor Helleseth, Alexander Kholosha</td><td><a href="streamciphers/pomaranch/desc.pdf">paper</a></td></tr>
+<tr><td>Py6</td><td>32? bytes</td><td>Eli Biham, Jennifer Seberry; ``No royalty will be necessary for use of Py''</td><td><a href="streamciphers/py6/py6.c">C</a> <a href="streamciphers/py/desc.pdf">paper</a></td></tr>
+<tr><td>Py</td><td>32? bytes</td><td>Eli Biham, Jennifer Seberry; ``No royalty will be necessary for use of Py''</td><td><a href="streamciphers/py/py.c">C</a> <a href="streamciphers/py/desc.pdf">paper</a></td></tr>
+<tr><td>Rabbit</td><td>16 bytes</td><td>Martin Boesgaard, Mette Vesterager, Thomas Christensen, Erik Zenner</td><td><a href="streamciphers/rabbit/rabbit.c">C</a> <a href="streamciphers/rabbit/desc.pdf">paper</a> <a href="http://www.cryptico.com/Default.asp?ID=10">link</a></td>
+<tr><td>Salsa20 (Snuffle 2005)</td><td>32 bytes</td><td>Daniel J. Bernstein; ``My policy is that Salsa20 is free for everyone to use''</td><td><a href="snuffle/ecrypt.c">C</a> <a href="snuffle/spec.pdf">spec</a> <a href="snuffle/security.pdf">security</a> <a href="snuffle/design.pdf">design</a> <a href="snuffle/speed.pdf">speed</a> <a href="snuffle/robustness.pdf">robustness</a> <a href="snuffle/ip.pdf">IP</a> <a href="snuffle.html">link</a></td></tr>
+<tr><td>Self-Synchronous SOBER (SSS)</td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr>
+<tr><td>SFINKS</td><td>10 bytes</td><td>An Braeken, Joseph Lano, Nele Mentens, Bart Preneel, Ingrid Verbauwhede</td><td><a href="streamciphers/sfinks/desc.pdf">paper</a></td></tr>
+<tr><td>SOSEMANUK</td><td>32 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; ``Permission is granted to anyone to use this software for any purpose, including commercial applications.''</td><td><a href="streamciphers/sosemanuk/SOSEMANUK.C">C</a> <a href="streamciphers/sosemanuk/desc.pdf">paper</a></td></tr>
+<tr><td>TRBDK3 YAEA</td><td></td><td>Timothy Brigham</td><td><a href="streamciphers/trbdk3-yaea/desc.ps">paper</a></td></tr>
+<tr><td>Trivium</td><td></td><td>Christophe De Canniere</td><td></td></tr>
+<tr><td>TSC-3</td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr>
+<tr><td>VEST-4</td><td>10 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
+<tr><td>VEST-16</td><td>16 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
+<tr><td>VEST-32</td><td>32 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
+<tr><td>WG</td><td>16 bytes</td><td>Guang Gong, Yassir Nawaz</td><td><a href="streamciphers/wg/desc.pdf">paper</a></td></tr>
+<tr><td>YAMB</td><td>32 bytes</td><td>Anatoly N. Lebedev, Alexander Ivanov, Sergey Starodubtzev, Alexey Kolchkov</td><td><a href="streamciphers/yamb/yamb.c">C</a> <a href="streamciphers/yamb/desc.pdf">paper</a></td></tr>
+<tr><td>ZK-Crypt</td><td></td><td>Carmi Gressel, Ran Granot, Gabi Vago</td><td></td></tr>
+</table>
<p>
Why is it reasonable to believe that a new design process
will produce better results than the AES design process?
@@ -112,40 +82,49 @@
constant-time high-speed AES software for modern CPUs.
</ul>
A new cipher can avoid these structural errors.
+<h2>Notes on authentication speed</h2>
+Most stream ciphers are purely for encryption.
+Applications need authentication,
+so these stream ciphers need to be combined with authentication mechanisms,
+adding some number of cycles per byte.
+Other stream ciphers <i>include</i> authentication,
+hoping to obtain better speed
+than can be obtained from separate encryption and authentication.
+<p>
+To figure out the encryption+authentication speed
+of a pure-encryption stream cipher,
+one must select an authentication mechanism,
+and add the authentication time to the encryption time.
+Here's a quick summary of authentication speeds:
+<ul>
+<li>AES-based authenticators such as AES-CBC-MAC are around 15 cycles/byte
+plus a few hundred cycles.
+<li>HMAC-MD5 is around 5 cycles/byte
+plus a thousand or so cycles.
+<li>Wegman-Carter (e.g., my Poly1305) is around 4 cycles/byte
+plus a few hundred cycles plus encrypting 16 additional bytes.
+This is unbreakable if the encryption is strong.
+<li>MAC speeds as low as 1 cycle/byte plus various overheads
+have been reported, although only for 64-bit security levels.
+</ul>
+We don't have to worry about authentication speed
+if we're comparing speeds of pure-encryption stream ciphers;
+but not all stream ciphers are pure-encryption stream ciphers.
+<p>
+Among the stream-cipher submissions,
+Frogbit, NLS, Phelix, SFINKS, SSS, and Vest
+are labelled as incorporating authentication mechanisms.
+My impression is that both NLS and SFINKS are actually
+pure-encryption stream ciphers attached to separate authenticators;
+in both cases, the separate authenticators are slower than (e.g.) Poly1305,
+so they should be ignored,
+and the underlying pure-encryption stream cipher
+should be evaluated on its own merits.
<h2>Notes on Salsa20</h2>
My own submission.
Quite conservative.
Salsa20 is faster than AES,
but I was expecting it to be the slowest stream-cipher submission.
-<h2>Notes on Rabbit</h2>
-Authors report, for a Pentium III-1000,
-278 cycles to load a 16-byte key;
-plus 253 cycles to load a nonce;
-plus 3.7 cycles/byte to encrypt a big block.
-For a Pentium 4,
-468 cycles to load a 16-byte key;
-plus 420 cycles to load a nonce;
-plus 5.1 cycles/byte to encrypt a big block.
-Also speed reports for ARM7 and MIPS.
-<p>
-Low-level operations:
-addition;
-addition with carry;
-squaring of a 4-byte input, with the 8-byte output
-folded by xor into a 4-byte result;
-rotation by multiples of 8 bits;
-and some other byte shuffling as part of key setup.
-<p>
-Each 16-byte output block involves 8 squarings and various other operations.
-<p>
-Initial impression:
-The multiplier means large price-performance ratio for hardware,
-but Rabbit's software speed is quite attractive.
-From a timing-attack perspective,
-I'm concerned about Rabbit's use of integer squaring on,
-e.g., the Motorola PowerPC 7450 (G4e),
-which takes a cycle less if the input is between -131072 and 131071.
-How much speed does Rabbit lose if this timing leak is eliminated?
<h2>Notes on Phelix</h2>
Authors report,
for a Pentium M,
@@ -160,12 +139,6 @@
xor;
constant-distance rotation.
<p>
-Includes authentication.
-Unusual in this respect;
-pretty much everyone else relies on a separate MAC.
-Comparing Phelix speed to the speed of other stream ciphers
-requires quantifying the speed of a separate MAC.
-<p>
Each Phelix block feeds the input through
13 adds, 11 xors, and 20 rotations
to produce a 4-byte block of output.
@@ -183,29 +156,6 @@
Exceptions:
Salsa20 is faster than Phelix when the hardware offers more parallelism,
and (in conjunction with Poly1305) is faster at rejecting forged packets.
-<h2>Notes on TSC-3</h2>
-Key is only 10 bytes.
-Authors report, for a Pentium 4,
-1500 cycles to load a key and nonce,
-plus 50 cycles/byte to encrypt a big block.
-<h2>Notes on F-FCSR-8</h2>
-16-byte key.
-Authors report,
-for the Pentium 3 and 4,
-about 10000 cycles to load a key and nonce,
-plus 100 cycles per byte to encrypt a big block;
-for the PowerPC 7457 (G4e),
-about 20 cycles per byte to encrypt a big block.
-<h2>Notes on F-FCSR-H</h2>
-10-byte key.
-<h2>Notes on Achterbahn</h2>
-10-byte key.
-Authors don't report software speeds.
-<h2>Notes on SFINKS</h2>
-10-byte key.
-Authors don't report software speeds.
-<h2>Notes on WG</h2>
-Authors report insanely slow software speeds.
<h2>Notes on SOSEMANUK</h2>
Key length between 16 bytes and 32 bytes.
Nonce length: 16 bytes.
@@ -227,24 +177,88 @@
5.40 PowerPC 970 (G5);
3.925 Alpha EV67;
5.975 UltraSPARC III.
-<h2>Notes on Mir-1</h2>
-16-byte key,
-8-byte nonce,
-48-byte ``internal state size.''
+<h2>Notes on Rabbit</h2>
+Authors report, for a Pentium III-1000,
+278 cycles to load a 16-byte key;
+plus 253 cycles to load a nonce;
+plus 3.7 cycles/byte to encrypt a big block.
+For a Pentium 4,
+468 cycles to load a 16-byte key;
+plus 420 cycles to load a nonce;
+plus 5.1 cycles/byte to encrypt a big block.
+Also speed reports for ARM7 and MIPS.
<p>
-Low-level operations: xor, and, or, addition mod 2^64,
-multiplication mod 2^64.
-Also uses the Rijndael S-boxes in initialization.
+Low-level operations:
+addition;
+addition with carry;
+squaring of a 4-byte input, with the 8-byte output
+folded by xor into a 4-byte result;
+rotation by multiples of 8 bits;
+and some other byte shuffling as part of key setup.
<p>
-Author reports, for a Pentium 4,
-11149 cycles to load a key;
-693 cycles to load a nonce;
-314 cycles per block (39.25 cycles/byte, I believe) to encrypt a big block.
+Each 16-byte output block involves 8 squarings and various other operations.
<p>
Initial impression:
-The reported speeds are too slow to attract any interest.
-On the other hand,
-I think that this function could be computed at considerably higher speed.
+The multiplier means large price-performance ratio for hardware,
+but Rabbit's software speed is quite attractive.
+From a timing-attack perspective,
+I'm concerned about Rabbit's use of integer squaring on,
+e.g., the Motorola PowerPC 7450 (G4e),
+which takes a cycle less if the input is between -131072 and 131071.
+How much speed does Rabbit lose if this timing leak is eliminated?
+<h2>Notes on ABC</h2>
+Key length: 16 bytes.
+Nonce length: 16 bytes.
+Authors report Pentium 4 speeds
+under 4 cycles per byte.
+<p>
+Low-level operations:
+addition, xor, and, or, constant-distance shift, dot product.
+The dot product takes bits b_0,b_1,...,b_{31}
+and 32-bit integers e_0,e_1,...,e_{31}
+and computes the sum e_0 b_0 + e_1 b_1 + ... + e_{31} b_{31}.
+Every 4 bytes of output have one dot product and several other operations.
+<p>
+The reported speed of ABC relies on computing the dot product
+by secret-index table lookups.
+<p>
+Initial impression:
+Timing attacks will be a big problem here.
+<h2>Notes on Dragon-128</h2>
+Authors report, for a 3200MHz Pentium 4,
+1395 cycles to load a 16-byte key (and nonce?),
+plus 6.74 cycles/byte to encrypt a big block.
+<p>
+Initial impression:
+Timing-attack problems, like AES.
+<h2>Notes on Dragon-256</h2>
+Authors report, for a 3200MHz Pentium 4,
+1395 cycles to load a 32-byte key (and nonce?),
+plus 6.74 cycles/byte to encrypt a big block.
+<p>
+Initial impression:
+Timing-attack problems, like AES.
+<h2>Notes on NLS</h2>
+Page 17 of the NLS document
+reports, for a 1500MHz Centrino,
+952 cycles to load a 16-byte key;
+plus 763 cycles to load a nonce;
+plus 6.983 cycles/byte to encrypt a big block.
+<p>
+Low-level operations (page 18):
+addition, xor, constant-distance shift, table lookups.
+<p>
+Initial impression:
+Timing-attack problems.
+The designers claim, incorrectly, that table lookup takes constant time.
+<h2>Notes on LEX</h2>
+``Leak extraction'' from AES.
+Specifically, extracts 40 bytes from each AES encryption;
+about 2.5 times faster than AES.
+<p>
+Initial impression:
+Timing-attack problems, like AES.
+Also looks like a great target for algebraic attacks.
<h2>Notes on Py</h2>
Authors report, for a Pentium III,
2727 cycles to load a key;
@@ -261,7 +275,7 @@
4.1 cycles/byte to encrypt a big block.
<p>
Initial impression:
-Py looks like a disaster from a timing-attack perspective.
+Timing-attack problems, like RC4.
The large message-setup time also bothers me:
low-overhead ciphers such as Salsa20
will already have finished encrypting an average-size Internet packet
@@ -270,9 +284,43 @@
Scaled-down version of Py.
Smaller key-loading time and nonce-loading time;
same cycles/byte to encrypt a big block.
-<h2>Notes on Mosquito</h2>
-``More of a research object than a standard proposal,''
-Daemen said in his SKEW presentation.
+<h2>Notes on YAMB</h2>
+Key as large as 32 bytes.
+Nonce as large as 16 bytes.
+380 bytes of memory.
+Authors report 12.5 cycles/byte for Pentium 4.
+<p>
+Initial impression:
+Timing-attack problems, like RC4.
+<h2>Notes on DICING</h2>
+Author reports, for an 1800MHz Athlon XP,
+918 cycles to load a 16-byte key;
+plus 57600 cycles to load a nonce;
+plus 24 cycles/byte to encrypt a big block.
+<p>
+Initial impression:
+What advantages is DICING supposed to have over AES?
+The paper says ``DICING is faster than AES about two times'';
+in fact, even if we ignore nonce-load costs,
+24 cycles/byte is slower than AES.
+<h2>Notes on Mir-1</h2>
+16-byte key,
+8-byte nonce,
+48-byte ``internal state size.''
+<p>
+Low-level operations: xor, and, or, addition mod 2^64,
+multiplication mod 2^64.
+Also uses the Rijndael S-boxes in initialization.
+<p>
+Author reports, for a Pentium 4,
+11149 cycles to load a key;
+693 cycles to load a nonce;
+314 cycles per block (39.25 cycles/byte, I believe) to encrypt a big block.
+<p>
+Initial impression:
+The reported speeds are too slow to attract any interest.
+On the other hand,
+I think that this function could be computed at considerably higher speed.
<h2>Notes on Polar Bear</h2>
Key length: as large as 16 bytes?
Nonce length: as large as 32 bytes.
@@ -288,10 +336,44 @@
The cycles-per-byte count isn't even on the same scale as RC4;
the authors are wildly misrepresenting RC4 speed.
What advantages is Polar Bear supposed to have over AES?
+<h2>Notes on Fubuki</h2>
+Authors report, for a Pentium M,
+489662 cycles for setup,
+plus 133 cycles/byte to encrypt a big block.
+Uses Mersenne Twister, by Matsumoto and Nishimura.
+<p>
+Initial impression: So slow that nobody will look at it.
+What advantages is Fubuki supposed to have over AES?
+<h2>Notes on F-FCSR-8</h2>
+16-byte key.
+Authors report,
+for the Pentium 3 and 4,
+about 10000 cycles to load a key and nonce,
+plus 100 cycles per byte to encrypt a big block;
+for the PowerPC 7457 (G4e),
+about 20 cycles per byte to encrypt a big block.
+<h2>Notes on F-FCSR-H</h2>
+10-byte key.
+<h2>Notes on Mosquito</h2>
+``More of a research object than a standard proposal,''
+Daemen said in his SKEW presentation.
+<h2>Notes on TSC-3</h2>
+10-byte key.
+Authors report, for a Pentium 4,
+1500 cycles to load a key and nonce,
+plus 50 cycles/byte to encrypt a big block.
+<h2>Notes on Achterbahn</h2>
+10-byte key.
+Authors don't report software speeds.
+<h2>Notes on SFINKS</h2>
+10-byte key.
+Authors don't report software speeds.
+<h2>Notes on WG</h2>
+Authors report insanely slow software speeds.
<h2>Notes on Edon80</h2>
10-byte key.
10-byte nonce.
-<h2>Notes on CJCSG</h2>
+<h2>Notes on POMARANCH</h2>
16-byte key.
14-byte nonce.
Authors report approximately 1400 cycles/byte on a 2800MHz Pentium 4.
@@ -308,74 +390,7 @@
16-byte nonce.
Authors report approximately 1500 cycles/byte on a 3400MHz Pentium 4,
and call this ``reasonably efficient.''
-<h2>Notes on YAMB</h2>
-Key as large as 32 bytes.
-Nonce as large as 16 bytes.
-380 bytes of memory.
-Authors report 12.5 cycles/byte for Pentium 4.
-<p>
-Initial impression:
-Timing-attack problems, like RC4.
-<h2>Notes on LEX</h2>
-``Leak extraction'' from AES.
-Specifically, extracts 40 bytes from each AES encryption;
-about 2.5 times faster than AES.
-<p>
-Initial impression:
-Will be a disaster from a timing-attack perspective, just like AES.
-<h2>Notes on Fubuki</h2>
-Authors report, for a Pentium M,
-489662 cycles for setup,
-plus 133 cycles/byte to encrypt a big block.
-Uses Mersenne Twister, by Matsumoto and Nishimura.
-<p>
-Initial impression: So slow that nobody will look at it.
-What advantages is Fubuki supposed to have over AES?
-<h2>Notes on ABC</h2>
-Key length: 16 bytes.
-Nonce length: 16 bytes.
-Authors report Pentium 4 speeds
-under 4 cycles per byte.
-<p>
-Low-level operations:
-addition, xor, and, or, constant-distance shift, dot product.
-The dot product takes bits b_0,b_1,...,b_{31}
-and 32-bit integers e_0,e_1,...,e_{31}
-and computes the sum e_0 b_0 + e_1 b_1 + ... + e_{31} b_{31}.
-Every 4 bytes of output have one dot product and several other operations.
-<p>
-The reported speed of ABC relies on computing the dot product
-by secret-index table lookups.
-<p>
-Initial impression:
-Timing attacks will be a big problem here.
-<h2>Notes on DICING</h2>
-Author reports, for an 1800MHz Athlon XP,
-918 cycles to load a 16-byte key;
-plus 57600 cycles to load a nonce;
-plus 24 cycles/byte to encrypt a big block.
-<p>
-Initial impression:
-What advantages is DICING supposed to have over AES?
-The paper says ``DICING is faster than AES about two times'';
-in fact, even if we ignore nonce-load costs,
-24 cycles/byte is slower than AES.
-<h2>Notes on Dragon-128</h2>
-Authors report, for a 3200MHz Pentium 4,
-1395 cycles to load a 16-byte key (and nonce?),
-plus 6.74 cycles/byte to encrypt a big block.
-<p>
-Initial impression:
-Timing-attack problems.
-<h2>Notes on Dragon-256</h2>
-Authors report, for a 3200MHz Pentium 4,
-1395 cycles to load a 32-byte key (and nonce?),
-plus 6.74 cycles/byte to encrypt a big block.
-<p>
-Initial impression:
-Timing-attack problems.
<h2>Notes on Frogbit</h2>
-Includes authentication.
No speed reports.
<h2>Notes on Grain</h2>
10-byte key.
@@ -390,29 +405,6 @@
<p>
Initial impression:
Timing-attack problems.
-<h2>Notes on MAG</h2>
-Initial impression:
-Paper needs to be cleaned up.
-<h2>Notes on NLS</h2>
-Page 17 of the NLS document
-reports, for a 1500MHz Centrino,
-952 cycles to load a 16-byte key;
-plus 763 cycles to load a nonce;
-plus 6.983 cycles/byte to encrypt a big block.
-<p>
-Low-level operations (page 18):
-addition, xor, constant-distance shift, table lookups.
-The designers claim, incorrectly, that table lookup takes constant time.
-<p>
-Initial impression:
-Timing-attack problems.
-<h2>Notes on TRBDK3 YAEA</h2>
-Author says:
-``It requires approximately 423 cycles per byte in operation,
-which is quite similar to AES based on what I have read. ...
-Key creation for this system
-is definitely slow compared to AES,
-taking approximately 26,000,000 cycles.''
<h2>Notes on VEST-4</h2>
10-byte key.
No software speed reports.
@@ -422,6 +414,16 @@
<h2>Notes on VEST-32</h2>
32-byte key.
No software speed reports.
+<h2>Notes on TRBDK3 YAEA</h2>
+Author says:
+``It requires approximately 423 cycles per byte in operation,
+which is quite similar to AES based on what I have read. ...
+Key creation for this system
+is definitely slow compared to AES,
+taking approximately 26,000,000 cycles.''
+<h2>Notes on MAG</h2>
+Initial impression:
+Paper needs to be cleaned up.
<h2>Notes on ZK-Crypt</h2>
No software speed reports.
</body>