cr.yp.to update

[email protected] 1 Aug 2005 06:00:00 -0000
Newsgroups gmane.comp.djb.announce
Message-ID <[email protected]>
Deleted: .old-crypto/bib/2004/wang-md5.bib
Deleted: .old-crypto/bib/2004/wang-md5.by
Deleted: .old-crypto/bib/2004/wang-md5.incl
Deleted: .old-crypto/bib/2004/wang-md5.tex
Deleted: .old-crypto/streamciphers/dicing/desc.pdf
New: streamciphers/dicing/desc0.pdf
New: streamciphers/dicing/desc1.pdf
New: streamciphers/dicing/desc2.pdf
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html	2005-07-20 10:21:44.000000000 -0400
+++ cr.yp.to/streamciphers.html	2005-07-30 12:53:12.000000000 -0400
@@ -28,10 +28,12 @@
 Here's my own list of the submissions:
 <table border>
 <tr><th>Name</th><th>Key size</th><th>Authors; policy</th><th>Documents</th></tr>
-<tr><td>ABC</td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td><a href="streamciphers/abc/abc.c">C</a> <a href="streamciphers/abc/desc.pdf">paper</a>; subsequent change in definition</td></tr>
+<tr><td>ABC version 1 <b>withdrawn</b></td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td><a href="streamciphers/abc/abc.c">C</a> <a href="streamciphers/abc/desc.pdf">paper</a></td></tr>
+<tr><td>ABC version 2</td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td></td></tr>
 <tr><td>Achterbahn</td><td>10 bytes</td><td>Berndt Gammel, Rainer Goettfert, Oliver Kniffler</td><td><a href="streamciphers/achterbahn/desc.pdf">paper</a></td></tr>
 <tr><td>DECIM</td><td>10 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Blandine Debraize, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; <b>patented</b></td><td><a href="streamciphers/decim/desc.pdf">paper</a></td></tr>
-<tr><td>DICING</td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc.pdf">paper</a>; subsequent corrections</td></tr>
+<tr><td>DICING version 0 <b>withdrawn</b></td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc0.pdf">paper</a></td></tr>
+<tr><td>DICING version 1</td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc2.pdf">paper</a></td></tr>
 <tr><td>Dragon-128</td><td>16 bytes</td><td>Ed Dawson, Kevin Chen, Matt Henricksen, William Millan, Leonie Simpson, HoonJae Lee, SangJae Moon</td><td><a href="streamciphers/dragon-128/dragon-ref.c">C</a> <a href="streamciphers/dragon-128/desc.pdf">paper</a></td></tr>
 <tr><td>Dragon-256</td><td>32 bytes</td><td>Ed Dawson, Kevin Chen, Matt Henricksen, William Millan, Leonie Simpson, HoonJae Lee, SangJae Moon</td><td><a href="streamciphers/dragon-128/dragon-ref.c">C</a> <a href="streamciphers/dragon-128/desc.pdf">paper</a></td></tr>
 <tr><td>Edon80</td><td>10 bytes</td><td>Danilo Gligoroski, Smile Markovski, Ljupco Kocarev, Marjan Gusev</td><td><a href="streamciphers/edon80/PartB1.pdf">desc</a> <a href="streamciphers/edon80/PartB2.pdf">robustness</a> <a href="streamciphers/edon80/PartB3.pdf">security</a> <a href="streamciphers/edon80/PartB4.pdf">advantages</a> <a href="streamciphers/edon80/PartB5.pdf">design</a> <a href="streamciphers/edon80/PartB6.pdf">speed</a> <a href="streamciphers/edon80/PartB7.pdf">impl</a></td></tr>
@@ -57,12 +59,12 @@
 <tr><td>Py</td><td>32? bytes</td><td>Eli Biham, Jennifer Seberry; ``No royalty will be necessary for use of Py''</td><td><a href="streamciphers/py/py.c">C</a> <a href="streamciphers/py/desc.pdf">paper</a></td></tr>
 <tr><td>Rabbit</td><td>16 bytes</td><td>Martin Boesgaard, Mette Vesterager, Thomas Christensen, Erik Zenner; <b>patented</b></td><td><a href="streamciphers/rabbit/rabbit.c">C</a> <a href="streamciphers/rabbit/desc.pdf">paper</a> <a href="http://www.cryptico.com/Default.asp?ID=10">link</a></td>
 <tr><td>Salsa20 (Snuffle 2005)</td><td>32 bytes</td><td>Daniel J. Bernstein; ``My policy is that Salsa20 is free for everyone to use''</td><td><a href="snuffle/ecrypt.c">C</a> <a href="snuffle/spec.pdf">spec</a> <a href="snuffle/security.pdf">security</a> <a href="snuffle/design.pdf">design</a> <a href="snuffle/speed.pdf">speed</a> <a href="snuffle/robustness.pdf">robustness</a> <a href="snuffle/ip.pdf">IP</a> <a href="snuffle.html">link</a></td></tr>
-<tr><td>Self-Synchronous SOBER (SSS) <b>withdrawn by author</b></td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr>
+<tr><td>Self-Synchronous SOBER (SSS) <b>withdrawn</b></td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr>
 <tr><td>SFINKS</td><td>10 bytes</td><td>An Braeken, Joseph Lano, Nele Mentens, Bart Preneel, Ingrid Verbauwhede</td><td><a href="streamciphers/sfinks/desc.pdf">paper</a></td></tr>
 <tr><td>SOSEMANUK</td><td>32 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; ``Permission is granted to anyone to use this software for any purpose, including commercial applications''</td><td><a href="streamciphers/sosemanuk/SOSEMANUK.C">C</a> <a href="streamciphers/sosemanuk/desc.pdf">paper</a></td></tr>
 <tr><td>TRBDK3 YAEA</td><td></td><td>Timothy Brigham</td><td><a href="streamciphers/trbdk3-yaea/desc.ps">paper</a></td></tr>
 <tr><td>Trivium</td><td>10 bytes</td><td>Christophe De Canniere, Bart Preneel</td><td><a href="streamciphers/trivium/desc.pdf">paper</a></td></tr>
-<tr><td>TSC-3 <b>withdrawn by author</b></td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr>
+<tr><td>TSC-3 <b>withdrawn</b></td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr>
 <tr><td>VEST-4</td><td>10 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman; <b>patented</b></td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
 <tr><td>VEST-16</td><td>16 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman; <b>patented</b></td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
 <tr><td>VEST-32</td><td>32 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman; <b>patented</b></td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr>
@@ -196,7 +198,15 @@
 e.g., the Motorola PowerPC 7450 (G4e),
 which takes a cycle less if the input is between -131072 and 131071.
 How much speed does Rabbit lose if this timing leak is eliminated?
-<h2>Notes on ABC</h2>
+<h2>Notes on ABC version 1 (withdrawn)</h2>
+Berbain and Gilbert write:
+``We present an attack against ABC ... The attack requires
+2^95 operations and 2^32 32-bit keystream words.''
+Authors write:
+``We sent the ECRYPT stream cipher project committee an update. ...
+We would like the cryptographical community to regard the updated version
+of ABC as the basic one.''
+<h2>Notes on ABC version 2</h2>
 Key length: 16 bytes.
 Nonce length: 16 bytes.
 Authors report Pentium 4 speeds
@@ -213,12 +223,6 @@
 The reported speed of ABC relies on computing the dot product
 by secret-index table lookups,
 creating timing-attack problems.
-<p>
-Berbain and Gilbert write:
-``We present an attack against ABC ... The attack requires
-2^95 operations and 2^32 32-bit keystream words.''
-Authors write:
-``We sent the ECRYPT stream cipher project committee an update.''
 <h2>Notes on SOSEMANUK</h2>
 Key length between 16 bytes and 32 bytes.
 Nonce length: 16 bytes.
@@ -327,7 +331,17 @@
 Initial impression:
 Timing-attack problems, like RC4.
 <hr>
-<h2>Notes on DICING</h2>
+<h2>Notes on DICING version 0 (withdrawn)</h2>
+Author reports, for an 1800MHz Athlon XP,
+918 cycles to load a 16-byte key;
+plus 57600 cycles to load a nonce;
+plus 24 cycles/byte to encrypt a big block.
+<p>
+Gilles Piret writes:
+``We describe practical distinguishing and key recovery
+attacks ... a keystream of about 128 words ...
+2^22 hash table lookups.''
+<h2>Notes on DICING version 1</h2>
 Author reports, for an 1800MHz Athlon XP,
 918 cycles to load a 16-byte key;
 plus 57600 cycles to load a nonce;
@@ -395,7 +409,7 @@
 <h2>Notes on Mosquito</h2>
 ``More of a research object than a standard proposal,''
 Daemen said in his SKEW presentation.
-<h2>Notes on TSC-3 (withdrawn by author)</h2>
+<h2>Notes on TSC-3 (withdrawn)</h2>
 10-byte key.
 Authors report, for a Pentium 4,
 1500 cycles to load a key and nonce,
@@ -471,7 +485,7 @@
 <p>
 Initial impression:
 Timing-attack problems.
-<h2>Notes on SSS (withdrawn by author)</h2>
+<h2>Notes on SSS (withdrawn)</h2>
 Joan Daemen writes:
 ``Below a simple key-retrieval on SSS encryption requiring about 3100
 bytes of chosen ciphertext and computational complexity 2^24. I did not
@@ -500,6 +514,11 @@
 <h2>Notes on MAG</h2>
 Initial impression:
 Paper needs to be cleaned up.
+<p>
+Kuenzli and Meier write:
+``We present a very simple distinguishing attack ... on MAG,
+requiring only 129 successive bytes of known keystream,
+computation and memory are negligible.''
 <h2>Notes on ZK-Crypt (patented)</h2>
 No software speed reports.
 </body>