cr.yp.to update

[email protected] 10 Jul 2005 05:59:19 -0000
Newsgroups gmane.comp.djb.announce
Message-ID <[email protected]>
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html	2005-06-24 21:22:34.000000000 -0400
+++ cr.yp.to/streamciphers.html	2005-07-07 00:55:28.000000000 -0400
@@ -1,4 +1,7 @@
 <html>
+<head>
+<title>Notes on the ECRYPT Stream Cipher project</title>
+</head>
 <body>
 <a href="djb.html">D. J. Bernstein</a>
 <br><a href="hash.html">Hash functions and ciphers</a>
@@ -54,16 +57,16 @@
 <tr><td>Py</td><td>32? bytes</td><td>Eli Biham, Jennifer Seberry; ``No royalty will be necessary for use of Py''</td><td><a href="streamciphers/py/py.c">C</a> <a href="streamciphers/py/desc.pdf">paper</a></td></tr>
 <tr><td>Rabbit</td><td>16 bytes</td><td>Martin Boesgaard, Mette Vesterager, Thomas Christensen, Erik Zenner</td><td><a href="streamciphers/rabbit/rabbit.c">C</a> <a href="streamciphers/rabbit/desc.pdf">paper</a> <a href="http://www.cryptico.com/Default.asp?ID=10">link</a></td>
 <tr><td>Salsa20 (Snuffle 2005)</td><td>32 bytes</td><td>Daniel J. Bernstein; ``My policy is that Salsa20 is free for everyone to use''</td><td><a href="snuffle/ecrypt.c">C</a> <a href="snuffle/spec.pdf">spec</a> <a href="snuffle/security.pdf">security</a> <a href="snuffle/design.pdf">design</a> <a href="snuffle/speed.pdf">speed</a> <a href="snuffle/robustness.pdf">robustness</a> <a href="snuffle/ip.pdf">IP</a> <a href="snuffle.html">link</a></td></tr>
-<tr><td>Self-Synchronous SOBER (SSS)</td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr>
+<tr><td>Self-Synchronous SOBER (SSS) <b>withdrawn by author</b></td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr>
 <tr><td>SFINKS</td><td>10 bytes</td><td>An Braeken, Joseph Lano, Nele Mentens, Bart Preneel, Ingrid Verbauwhede</td><td><a href="streamciphers/sfinks/desc.pdf">paper</a></td></tr>
 <tr><td>SOSEMANUK</td><td>32 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; ``Permission is granted to anyone to use this software for any purpose, including commercial applications''</td><td><a href="streamciphers/sosemanuk/SOSEMANUK.C">C</a> <a href="streamciphers/sosemanuk/desc.pdf">paper</a></td></tr>
 <tr><td>TRBDK3 YAEA</td><td></td><td>Timothy Brigham</td><td><a href="streamciphers/trbdk3-yaea/desc.ps">paper</a></td></tr>
 <tr><td>Trivium</td><td>10 bytes</td><td>Christophe De Canniere, Bart Preneel</td><td><a href="streamciphers/trivium/desc.pdf">paper</a></td></tr>
-<tr><td>TSC-3</td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr>
+<tr><td>TSC-3 <b>withdrawn by author</b></td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr>
 <tr><td>VEST-4</td><td>10 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
 <tr><td>VEST-16</td><td>16 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
 <tr><td>VEST-32</td><td>32 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
-<tr><td>WG</td><td>16 bytes</td><td>Guang Gong, Yassir Nawaz</td><td><a href="streamciphers/wg/desc.pdf">paper</a>; subsequent corrections</td></tr>
+<tr><td>WG</td><td>16 bytes</td><td>Guang Gong, Yassir Nawaz</td><td><a href="streamciphers/wg/desc.pdf">paper</a>; subsequent corrections; subsequent asm; subsequent change in definition (slower setup) in response to attack</td></tr>
 <tr><td>YAMB</td><td>32 bytes</td><td>Anatoly N. Lebedev, Alexander Ivanov, Sergey Starodubtzev, Alexey Kolchkov</td><td><a href="streamciphers/yamb/yamb.c">C</a> <a href="streamciphers/yamb/desc.pdf">paper</a></td></tr>
 <tr><td>ZK-Crypt</td><td></td><td>Carmi Gressel, Ran Granot, Gabi Vago</td><td></td></tr>
 </table>
@@ -378,12 +381,15 @@
 plus 100 cycles per byte to encrypt a big block;
 for the PowerPC 7457 (G4e),
 about 20 cycles per byte to encrypt a big block.
+<p>
+Jaulmes and Muller report several attacks,
+such as a distinguishing attack using 2^34 nonces.
 <h2>Notes on F-FCSR-H</h2>
 10-byte key.
 <h2>Notes on Mosquito</h2>
 ``More of a research object than a standard proposal,''
 Daemen said in his SKEW presentation.
-<h2>Notes on TSC-3</h2>
+<h2>Notes on TSC-3 (withdrawn by author)</h2>
 10-byte key.
 Authors report, for a Pentium 4,
 1500 cycles to load a key and nonce,
@@ -404,6 +410,14 @@
 Authors don't report software speeds.
 <h2>Notes on WG</h2>
 Authors report insanely slow software speeds.
+<p>
+Hongjun Wu and Bart Preneel report various attacks on WG.
+Authors write:
+``We admit that 22 clock cycles for key/IV setup phased as suggested by
+us in the original WG paper was too optimistic. ...
+We therefore recommend the key/IV setup phase of the WG cipher
+to be 88 clock cycles.
+No design changes are required.''
 <h2>Notes on Edon80</h2>
 10-byte key.
 10-byte nonce.
@@ -419,6 +433,8 @@
 10-byte nonce.
 Authors report approximately 1400 cycles/byte on a 3400MHz Pentium 4,
 and call this ``reasonably efficient.''
+<p>
+Jin Hong asks how much entropy is lost by the MICKEY state update.
 <h2>Notes on MICKEY-128</h2>
 16-byte key.
 16-byte nonce.
@@ -438,16 +454,24 @@
 Steve Babbage writes:
 ``... if we assume known plaintext ... it's clear that we can deduce
 the entire contents of Key Register very efficiently.''
+<p>
+Author writes: ``I've closed this `backdoor'...
+Please, have a look on the improved version.''
 <h2>Notes on Hermes8-128</h2>
 16-byte key.
 <p>
 Initial impression:
 Timing-attack problems.
-<h2>Notes on SSS</h2>
+<h2>Notes on SSS (withdrawn by author)</h2>
 Joan Daemen writes:
 ``Below a simple key-retrieval on SSS encryption requiring about 3100
 bytes of chosen ciphertext and computational complexity 2^24. I did not
 experimentally verify whether it actually works so it may contain errors.''
+<p>
+Author writes:
+``A neat attack, thanks.
+I confess that trying a self-synchronous stream cipher
+was a departure from anything that we really knew how to do...''
 <h2>Notes on VEST-4</h2>
 10-byte key.
 No software speed reports.
New: talks/2005.07.08/slides.pdf
diff -ru .old-crypto/talks.html cr.yp.to/talks.html
--- .old-crypto/talks.html	2005-06-26 03:04:19.000000000 -0400
+++ cr.yp.to/talks.html	2005-07-07 20:01:37.000000000 -0400
@@ -7,7 +7,7 @@
 <ul>
 <li>95 lectures.
 91 done.
-50 with slides online here.
+51 with slides online here.
 <li>77 invited lectures
 (47 at conferences);
 6 refereed lectures;
@@ -1749,7 +1749,7 @@
 <td>conference</td>
 <td>Spain</td>
 </tr><tr><td colspan="5">
-
+<a href="talks/2005.07.08/slides.pdf">[PDF slides]</a>
 
 Computational Number Theory Workshop;
 Foundations of Computational Mathematics (FoCM) 2005.
diff -ru .old-crypto/unix/feedme.html cr.yp.to/unix/feedme.html
--- .old-crypto/unix/feedme.html	2004-12-18 18:56:50.000000000 -0500
+++ cr.yp.to/unix/feedme.html	2005-06-27 04:43:25.000000000 -0400
@@ -14,6 +14,9 @@
 <p>
 Some features of the standard workstation
 that are relevant to this installation: Athlon 64 CPU; K8V-X motherboard.
+<p>
+If you have assembled the 2005.05.14 standard workstation instead,
+skip the disable-SATA instructions.
 <h2>Prerequisites</h2>
 Acquire the FreeBSD 5.3 amd64 CD:
 5.3-RELEASE-amd64-disc1.iso,