cr.yp.to update
[email protected] 1 Aug 2005 06:00:00 -0000
| Newsgroups | gmane.comp.djb.announce |
|---|---|
| Message-ID | <[email protected]> |
Deleted: .old-crypto/bib/2004/wang-md5.bib Deleted: .old-crypto/bib/2004/wang-md5.by Deleted: .old-crypto/bib/2004/wang-md5.incl Deleted: .old-crypto/bib/2004/wang-md5.tex Deleted: .old-crypto/streamciphers/dicing/desc.pdf New: streamciphers/dicing/desc0.pdf New: streamciphers/dicing/desc1.pdf New: streamciphers/dicing/desc2.pdf diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html --- .old-crypto/streamciphers.html 2005-07-20 10:21:44.000000000 -0400 +++ cr.yp.to/streamciphers.html 2005-07-30 12:53:12.000000000 -0400 @@ -28,10 +28,12 @@ Here's my own list of the submissions: <table border> <tr><th>Name</th><th>Key size</th><th>Authors; policy</th><th>Documents</th></tr> -<tr><td>ABC</td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td><a href="streamciphers/abc/abc.c">C</a> <a href="streamciphers/abc/desc.pdf">paper</a>; subsequent change in definition</td></tr> +<tr><td>ABC version 1 <b>withdrawn</b></td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td><a href="streamciphers/abc/abc.c">C</a> <a href="streamciphers/abc/desc.pdf">paper</a></td></tr> +<tr><td>ABC version 2</td><td>16 bytes</td><td>Vladimir Anashin, Andrey Bogdanov, Ilya Kizhvatov, Sandeep Kumar</td><td></td></tr> <tr><td>Achterbahn</td><td>10 bytes</td><td>Berndt Gammel, Rainer Goettfert, Oliver Kniffler</td><td><a href="streamciphers/achterbahn/desc.pdf">paper</a></td></tr> <tr><td>DECIM</td><td>10 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Blandine Debraize, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; <b>patented</b></td><td><a href="streamciphers/decim/desc.pdf">paper</a></td></tr> -<tr><td>DICING</td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc.pdf">paper</a>; subsequent corrections</td></tr> +<tr><td>DICING version 0 <b>withdrawn</b></td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc0.pdf">paper</a></td></tr> +<tr><td>DICING version 1</td><td>16 bytes</td><td>Li An-Ping</td><td><a href="streamciphers/dicing/desc2.pdf">paper</a></td></tr> <tr><td>Dragon-128</td><td>16 bytes</td><td>Ed Dawson, Kevin Chen, Matt Henricksen, William Millan, Leonie Simpson, HoonJae Lee, SangJae Moon</td><td><a href="streamciphers/dragon-128/dragon-ref.c">C</a> <a href="streamciphers/dragon-128/desc.pdf">paper</a></td></tr> <tr><td>Dragon-256</td><td>32 bytes</td><td>Ed Dawson, Kevin Chen, Matt Henricksen, William Millan, Leonie Simpson, HoonJae Lee, SangJae Moon</td><td><a href="streamciphers/dragon-128/dragon-ref.c">C</a> <a href="streamciphers/dragon-128/desc.pdf">paper</a></td></tr> <tr><td>Edon80</td><td>10 bytes</td><td>Danilo Gligoroski, Smile Markovski, Ljupco Kocarev, Marjan Gusev</td><td><a href="streamciphers/edon80/PartB1.pdf">desc</a> <a href="streamciphers/edon80/PartB2.pdf">robustness</a> <a href="streamciphers/edon80/PartB3.pdf">security</a> <a href="streamciphers/edon80/PartB4.pdf">advantages</a> <a href="streamciphers/edon80/PartB5.pdf">design</a> <a href="streamciphers/edon80/PartB6.pdf">speed</a> <a href="streamciphers/edon80/PartB7.pdf">impl</a></td></tr> @@ -57,12 +59,12 @@ <tr><td>Py</td><td>32? bytes</td><td>Eli Biham, Jennifer Seberry; ``No royalty will be necessary for use of Py''</td><td><a href="streamciphers/py/py.c">C</a> <a href="streamciphers/py/desc.pdf">paper</a></td></tr> <tr><td>Rabbit</td><td>16 bytes</td><td>Martin Boesgaard, Mette Vesterager, Thomas Christensen, Erik Zenner; <b>patented</b></td><td><a href="streamciphers/rabbit/rabbit.c">C</a> <a href="streamciphers/rabbit/desc.pdf">paper</a> <a href="http://www.cryptico.com/Default.asp?ID=10">link</a></td> <tr><td>Salsa20 (Snuffle 2005)</td><td>32 bytes</td><td>Daniel J. Bernstein; ``My policy is that Salsa20 is free for everyone to use''</td><td><a href="snuffle/ecrypt.c">C</a> <a href="snuffle/spec.pdf">spec</a> <a href="snuffle/security.pdf">security</a> <a href="snuffle/design.pdf">design</a> <a href="snuffle/speed.pdf">speed</a> <a href="snuffle/robustness.pdf">robustness</a> <a href="snuffle/ip.pdf">IP</a> <a href="snuffle.html">link</a></td></tr> -<tr><td>Self-Synchronous SOBER (SSS) <b>withdrawn by author</b></td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr> +<tr><td>Self-Synchronous SOBER (SSS) <b>withdrawn</b></td><td>16 bytes</td><td>Gregory Rose, Philip Hawkes, Michael Paddon, Miriam Wiggers de Vries; ``QUALCOMM Incorporated allows free and unrestricted use of any of its intellectual property required to exercise the primitive''</td><td><a href="streamciphers/sss/desc.pdf">paper</a> <a href="http://people.qualcomm.com/ggr/NLS-SSS.html">link</a></td></tr> <tr><td>SFINKS</td><td>10 bytes</td><td>An Braeken, Joseph Lano, Nele Mentens, Bart Preneel, Ingrid Verbauwhede</td><td><a href="streamciphers/sfinks/desc.pdf">paper</a></td></tr> <tr><td>SOSEMANUK</td><td>32 bytes</td><td>Come Berbain, Olivier Billet, Anne Canteaut, Nicolas Courtois, Henri Gilbert, Louis Goubin, Aline Gouget, Louis Granboulan, Cedric Lauradoux, Marine Minier, Thomas Pornin, Herve Sibert; ``Permission is granted to anyone to use this software for any purpose, including commercial applications''</td><td><a href="streamciphers/sosemanuk/SOSEMANUK.C">C</a> <a href="streamciphers/sosemanuk/desc.pdf">paper</a></td></tr> <tr><td>TRBDK3 YAEA</td><td></td><td>Timothy Brigham</td><td><a href="streamciphers/trbdk3-yaea/desc.ps">paper</a></td></tr> <tr><td>Trivium</td><td>10 bytes</td><td>Christophe De Canniere, Bart Preneel</td><td><a href="streamciphers/trivium/desc.pdf">paper</a></td></tr> -<tr><td>TSC-3 <b>withdrawn by author</b></td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr> +<tr><td>TSC-3 <b>withdrawn</b></td><td>10 bytes</td><td>Jin Hong, Dong Hoon Lee, Yongjin Yeom, Daewan Han, Seongtaek Chee</td><td><a href="streamciphers/tsc-3/desc.pdf">paper</a></td></tr> <tr><td>VEST-4</td><td>10 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman; <b>patented</b></td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr> <tr><td>VEST-16</td><td>16 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman; <b>patented</b></td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr> <tr><td>VEST-32</td><td>32 bytes</td><td>Claude Bigeard, Sean O'Neil, Benjamin Gittins, Howard Landman; <b>patented</b></td><td><a href="streamciphers/vest-16/desc.pdf">paper</a></td></tr> @@ -196,7 +198,15 @@ e.g., the Motorola PowerPC 7450 (G4e), which takes a cycle less if the input is between -131072 and 131071. How much speed does Rabbit lose if this timing leak is eliminated? -<h2>Notes on ABC</h2> +<h2>Notes on ABC version 1 (withdrawn)</h2> +Berbain and Gilbert write: +``We present an attack against ABC ... The attack requires +2^95 operations and 2^32 32-bit keystream words.'' +Authors write: +``We sent the ECRYPT stream cipher project committee an update. ... +We would like the cryptographical community to regard the updated version +of ABC as the basic one.'' +<h2>Notes on ABC version 2</h2> Key length: 16 bytes. Nonce length: 16 bytes. Authors report Pentium 4 speeds @@ -213,12 +223,6 @@ The reported speed of ABC relies on computing the dot product by secret-index table lookups, creating timing-attack problems. -<p> -Berbain and Gilbert write: -``We present an attack against ABC ... The attack requires -2^95 operations and 2^32 32-bit keystream words.'' -Authors write: -``We sent the ECRYPT stream cipher project committee an update.'' <h2>Notes on SOSEMANUK</h2> Key length between 16 bytes and 32 bytes. Nonce length: 16 bytes. @@ -327,7 +331,17 @@ Initial impression: Timing-attack problems, like RC4. <hr> -<h2>Notes on DICING</h2> +<h2>Notes on DICING version 0 (withdrawn)</h2> +Author reports, for an 1800MHz Athlon XP, +918 cycles to load a 16-byte key; +plus 57600 cycles to load a nonce; +plus 24 cycles/byte to encrypt a big block. +<p> +Gilles Piret writes: +``We describe practical distinguishing and key recovery +attacks ... a keystream of about 128 words ... +2^22 hash table lookups.'' +<h2>Notes on DICING version 1</h2> Author reports, for an 1800MHz Athlon XP, 918 cycles to load a 16-byte key; plus 57600 cycles to load a nonce; @@ -395,7 +409,7 @@ <h2>Notes on Mosquito</h2> ``More of a research object than a standard proposal,'' Daemen said in his SKEW presentation. -<h2>Notes on TSC-3 (withdrawn by author)</h2> +<h2>Notes on TSC-3 (withdrawn)</h2> 10-byte key. Authors report, for a Pentium 4, 1500 cycles to load a key and nonce, @@ -471,7 +485,7 @@ <p> Initial impression: Timing-attack problems. -<h2>Notes on SSS (withdrawn by author)</h2> +<h2>Notes on SSS (withdrawn)</h2> Joan Daemen writes: ``Below a simple key-retrieval on SSS encryption requiring about 3100 bytes of chosen ciphertext and computational complexity 2^24. I did not @@ -500,6 +514,11 @@ <h2>Notes on MAG</h2> Initial impression: Paper needs to be cleaned up. +<p> +Kuenzli and Meier write: +``We present a very simple distinguishing attack ... on MAG, +requiring only 129 successive bytes of known keystream, +computation and memory are negligible.'' <h2>Notes on ZK-Crypt (patented)</h2> No software speed reports. </body>