cr.yp.to update
[email protected] 10 Jul 2005 05:59:19 -0000
| Newsgroups | gmane.comp.djb.announce |
|---|---|
| Message-ID | <[email protected]> |
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html --- .old-crypto/streamciphers.html 2005-06-24 21:22:34.000000000 -0400 +++ cr.yp.to/streamciphers.html 2005-07-07 00:55:28.000000000 -0400 @@ -1,4 +1,7 @@ <html> +<head> +<title>Notes on the ECRYPT Stream Cipher project</title> +</head> <body> <a href="djb.html">D. J. Bernstein</a> <br><a href="hash.html">Hash functions and ciphers</a> @@ -54,16 +57,16 @@ <tr><td>Py</td><td>32? bytes</td><td>Eli Biham, Jennifer Seberry; ``No royalty will be necessary for use of Py''</td><td><a href="streamciphers/py/py.c">C</a> <a href="streamciphers/py/desc.pdf">paper</a></td></tr> <tr><td>Rabbit</td><td>16 bytes</td><td>Martin Boesgaard, Mette Vesterager, Thomas Christensen, Erik Zenner</td><td><a href="streamciphers/rabbit/rabbit.c">C</a> <a href="streamciphers/rabbit/desc.pdf">paper</a> <a href="http://www.cryptico.com/Default.asp?ID=10">link</a></td> <tr><td>Salsa20 (Snuffle 2005)</td><td>32 bytes</td><td>Daniel J. Bernstein; ``My policy is that Salsa20 is free for everyone to use''</td><td><a href="snuffle/ecrypt.c">C</a> <a href="snuffle/spec.pdf">spec</a> <a href="snuffle/security.pdf">security</a> <a href="snuffle/design.pdf">design</a> <a href="snuffle/speed.pdf">speed</a> <a href="snuffle/robustness.pdf">robustness</a> <a href="snuffle/ip.pdf">IP</a> <a href="snuffle.html">link</a></td></tr> -<tr><td>Self-Synchronous SOBER (SSS)</td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr> +<tr><td>Self-Synchronous SOBER (SSS) <b>withdrawn by author</b></td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr> <tr><td>SFINKS</td><td>10 bytes</td><td>An Braeken, Joseph Lano, Nele Mentens, Bart Preneel, Ingrid Verbauwhede</td><td><a href="streamciphers/sfinks/desc.pdf">paper</a></td></tr> <tr><td>SOSEMANUK</td><td>32 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; ``Permission is granted to anyone to use this software for any purpose, including commercial applications''</td><td><a href="streamciphers/sosemanuk/SOSEMANUK.C">C</a> <a href="streamciphers/sosemanuk/desc.pdf">paper</a></td></tr> <tr><td>TRBDK3 YAEA</td><td></td><td>Timothy Brigham</td><td><a href="streamciphers/trbdk3-yaea/desc.ps">paper</a></td></tr> <tr><td>Trivium</td><td>10 bytes</td><td>Christophe De Canniere, Bart Preneel</td><td><a href="streamciphers/trivium/desc.pdf">paper</a></td></tr> -<tr><td>TSC-3</td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr> +<tr><td>TSC-3 <b>withdrawn by author</b></td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr> <tr><td>VEST-4</td><td>10 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr> <tr><td>VEST-16</td><td>16 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr> <tr><td>VEST-32</td><td>32 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman</td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr> -<tr><td>WG</td><td>16 bytes</td><td>Guang Gong, Yassir Nawaz</td><td><a href="streamciphers/wg/desc.pdf">paper</a>; subsequent corrections</td></tr> +<tr><td>WG</td><td>16 bytes</td><td>Guang Gong, Yassir Nawaz</td><td><a href="streamciphers/wg/desc.pdf">paper</a>; subsequent corrections; subsequent asm; subsequent change in definition (slower setup) in response to attack</td></tr> <tr><td>YAMB</td><td>32 bytes</td><td>Anatoly N. Lebedev, Alexander Ivanov, Sergey Starodubtzev, Alexey Kolchkov</td><td><a href="streamciphers/yamb/yamb.c">C</a> <a href="streamciphers/yamb/desc.pdf">paper</a></td></tr> <tr><td>ZK-Crypt</td><td></td><td>Carmi Gressel, Ran Granot, Gabi Vago</td><td></td></tr> </table> @@ -378,12 +381,15 @@ plus 100 cycles per byte to encrypt a big block; for the PowerPC 7457 (G4e), about 20 cycles per byte to encrypt a big block. +<p> +Jaulmes and Muller report several attacks, +such as a distinguishing attack using 2^34 nonces. <h2>Notes on F-FCSR-H</h2> 10-byte key. <h2>Notes on Mosquito</h2> ``More of a research object than a standard proposal,'' Daemen said in his SKEW presentation. -<h2>Notes on TSC-3</h2> +<h2>Notes on TSC-3 (withdrawn by author)</h2> 10-byte key. Authors report, for a Pentium 4, 1500 cycles to load a key and nonce, @@ -404,6 +410,14 @@ Authors don't report software speeds. <h2>Notes on WG</h2> Authors report insanely slow software speeds. +<p> +Hongjun Wu and Bart Preneel report various attacks on WG. +Authors write: +``We admit that 22 clock cycles for key/IV setup phased as suggested by +us in the original WG paper was too optimistic. ... +We therefore recommend the key/IV setup phase of the WG cipher +to be 88 clock cycles. +No design changes are required.'' <h2>Notes on Edon80</h2> 10-byte key. 10-byte nonce. @@ -419,6 +433,8 @@ 10-byte nonce. Authors report approximately 1400 cycles/byte on a 3400MHz Pentium 4, and call this ``reasonably efficient.'' +<p> +Jin Hong asks how much entropy is lost by the MICKEY state update. <h2>Notes on MICKEY-128</h2> 16-byte key. 16-byte nonce. @@ -438,16 +454,24 @@ Steve Babbage writes: ``... if we assume known plaintext ... it's clear that we can deduce the entire contents of Key Register very efficiently.'' +<p> +Author writes: ``I've closed this `backdoor'... +Please, have a look on the improved version.'' <h2>Notes on Hermes8-128</h2> 16-byte key. <p> Initial impression: Timing-attack problems. -<h2>Notes on SSS</h2> +<h2>Notes on SSS (withdrawn by author)</h2> Joan Daemen writes: ``Below a simple key-retrieval on SSS encryption requiring about 3100 bytes of chosen ciphertext and computational complexity 2^24. I did not experimentally verify whether it actually works so it may contain errors.'' +<p> +Author writes: +``A neat attack, thanks. +I confess that trying a self-synchronous stream cipher +was a departure from anything that we really knew how to do...'' <h2>Notes on VEST-4</h2> 10-byte key. No software speed reports. New: talks/2005.07.08/slides.pdf diff -ru .old-crypto/talks.html cr.yp.to/talks.html --- .old-crypto/talks.html 2005-06-26 03:04:19.000000000 -0400 +++ cr.yp.to/talks.html 2005-07-07 20:01:37.000000000 -0400 @@ -7,7 +7,7 @@ <ul> <li>95 lectures. 91 done. -50 with slides online here. +51 with slides online here. <li>77 invited lectures (47 at conferences); 6 refereed lectures; @@ -1749,7 +1749,7 @@ <td>conference</td> <td>Spain</td> </tr><tr><td colspan="5"> - +<a href="talks/2005.07.08/slides.pdf">[PDF slides]</a> Computational Number Theory Workshop; Foundations of Computational Mathematics (FoCM) 2005. diff -ru .old-crypto/unix/feedme.html cr.yp.to/unix/feedme.html --- .old-crypto/unix/feedme.html 2004-12-18 18:56:50.000000000 -0500 +++ cr.yp.to/unix/feedme.html 2005-06-27 04:43:25.000000000 -0400 @@ -14,6 +14,9 @@ <p> Some features of the standard workstation that are relevant to this installation: Athlon 64 CPU; K8V-X motherboard. +<p> +If you have assembled the 2005.05.14 standard workstation instead, +skip the disable-SATA instructions. <h2>Prerequisites</h2> Acquire the FreeBSD 5.3 amd64 CD: 5.3-RELEASE-amd64-disc1.iso,