cr.yp.to update

[email protected] 17 Sep 2005 19:21:21 -0000
Newsgroups gmane.comp.djb.announce
Message-ID <[email protected]>
 conferences.html                                                              |    2 
 conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html      |   31 +-
 conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/38.ppt          |binary
 conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html |   12 
 ecdh.html                                                                     |  121 ++++++++--
 hardware/assembly.html                                                        |   30 ++
 streamciphers.html                                                            |    3 
 7 files changed, 151 insertions(+), 48 deletions(-)
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/10.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/11.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/12.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/13.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/14.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/16.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/17.pps
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/18.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/19.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/5.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/6.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/7.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/8.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/9.pdf
diff -ru .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html
--- .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html	2005-08-29 22:20:00.000000000 -0400
+++ cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html	2005-09-06 08:34:41.000000000 -0400
@@ -322,7 +322,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Krzysztof Pietrzak</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/8.pdf">Presentation</a> </td>
   </tr>
 
 
@@ -405,7 +405,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Robert Granger and Fr&eacute;derik Vercauteren</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/18.pdf">Presentation</a></td>
   </tr>
  
 
@@ -443,7 +443,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Yi Lu, Willi Meier, and Serge Vaudenay</td>
-	<td class=xl35><a href="p/1.pdf">Presentation</a></td>
+	<td class=xl35><a href="p/16.pdf">Presentation</a></td>
   </tr>
 
 <tr> <td height=13> </tr>
@@ -508,7 +508,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Jo&euml;l Alwen, Giuseppe Persiano, and Ivan Visconti</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/14.ppt">Presentation</a></td>
   </tr>
  
 
@@ -628,7 +628,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange, John Malone-Lee, Gregory Neven, Pascal Paillier, and Haixia Shi</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/11.ppt">Presentation</a></td>
   </tr>
 
 
@@ -695,7 +695,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Lea Kissner and Dawn Song</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/10.pdf">Presentation</a></td>
   </tr>
 
 
@@ -749,7 +749,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Jung Yeon Hwang, Dong Hoon Lee, and Jongin Lim</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/6.ppt">Presentation</a></td>
   </tr>
 
 
@@ -912,7 +912,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Serge Vaudenay</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/1.pdf">Presentation</a></td>
   </tr>
 
 
@@ -958,7 +958,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Ronald Cramer, Vanesa Daza, Ignacio Gracia, Jorge Jim&eacute;gnez Urroz, Gregor Leander, Jaume Mart&iacute;-Farr&eacute;, and Carles Padr&oacute;</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/13.pdf">Presentation</a></td>
   </tr>
  
 
@@ -977,7 +977,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Ronald Cramer, Serge Fehr, and Martijn Stam</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/5.pdf">Presentation</a></td>
   </tr>
 
 
@@ -1077,7 +1077,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Ivan Damg&aring;rd and Yuval Ishai</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="r/15.ppt">Presentation</a></td>
   </tr>
  
 
@@ -1096,7 +1096,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Omer Barkol and Yuval Ishai</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/19.ppt">Presentation</a></td>
   </tr>
 
 
@@ -1161,7 +1161,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Jean-S&eacute;bastien Coron, Yevgeniy Dodis, C&eacute;cile Malinaud, and Prashant Puniya</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/17.pps">Presentation</a></td>
   </tr>
  
 
@@ -1317,6 +1317,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Thomas Holenstein and Renato Renner</td>
+	<td class=xl35><a href="p/12.pdf">Presentation</a></td>
   </tr>
  
 
@@ -1335,7 +1336,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Ivan Damg&aring;rd, Thomas B. Pedersen, and Louis Salvail</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/9.pdf">Presentation</a></td>
   </tr>
 
 <tr> <td height=13> </tr>
@@ -1400,7 +1401,7 @@
     <td align="center" class=xl33></td>
     <td class=xl34></td>
     <td class=xl35>Mihir Bellare, Krzysztof Pietrzak, and Phillip Rogaway</td>
-	<td class=xl35>&nbsp;</td>
+	<td class=xl35><a href="p/7.pdf">Presentation</a></td>
   </tr>
  
 
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/12.mov
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/12.pdf
Binary files .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/38.ppt and cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/38.ppt differ
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/4.mov
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/4.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/6.mov
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/6.ppt
diff -ru .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html
--- .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html	2005-08-29 10:36:27.000000000 -0400
+++ cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html	2005-08-31 20:53:20.000000000 -0400
@@ -163,8 +163,8 @@
       <td>&nbsp;</td>
       <td>&nbsp;</td>
       <td>Antoine Joux and Reynald Lercier</td>
-      <td></td>
-      <td></td>
+      <td><a href="r/4.pdf">Presentation</a></td>
+      <td><a href="r/4.mov">Video</a></td>
     </tr>
     <tr valign="top">
       <td>&nbsp;</td>
@@ -219,8 +219,8 @@
       <td>20:03</td>
       <td><strong>Full AES key extraction in 65 milliseconds using cache
         attacks</strong></td>
-      <td></td>
-      <td></td>
+      <td><a href="r/6.ppt">Presentation</a></td>
+      <td><a href="r/6.mov">Video</a></td>
     </tr>
     <tr valign="top">
       <td>&nbsp;</td>
@@ -387,8 +387,8 @@
       <td>&nbsp;</td>
       <td>&nbsp;</td>
       <td>Dan Bernstein</td>
-      <td>&nbsp;</td>
-      <td><a href="r/12.pdf">Video</a></td>
+      <td><a href="r/12.pdf">Presentation</a></td>
+      <td><a href="r/12.mov">Video</a></td>
     </tr>
     <tr valign="top">
       <td>&nbsp;</td>
New: conferences/2005-ecc
diff -ru .old-crypto/conferences.html cr.yp.to/conferences.html
--- .old-crypto/conferences.html	2005-08-28 23:13:59.000000000 -0400
+++ cr.yp.to/conferences.html	2005-09-16 04:10:12.000000000 -0400
@@ -472,6 +472,8 @@
 <p>
 2005.09.19-2005.09.21, invited, plan to attend:
 Elliptic Curve Cryptography (ECC) 2005.
+<a href="http://www.cacr.math.uwaterloo.ca/conferences/2005/ecc2005/announcement.html">http://www.cacr.math.uwaterloo.ca/conferences/2005/ecc2005/announcement.html</a>;
+<a href="conferences/2005-ecc/www.cacr.math.uwaterloo.ca/conferences/2005/ecc2005/announcement.html">mirror</a>.
 Denmark Technical University, Copenhagen.
 <p>
 2005.10.15-2005.10.15:
New: ecdh/FILES
New: ecdh/FILES.lib
New: ecdh/Makefile
New: ecdh/Makefile.lib
New: ecdh/cpucycles.a.do
New: ecdh/cpucycles.h.do
New: ecdh/cpucycles_athlon.h
New: ecdh/cpucycles_athlon.s
New: ecdh/curve25519-20050915.tar.gz
New: ecdh/curve25519-speed.c
New: ecdh/curve25519.a.do
New: ecdh/curve25519.h.do
New: ecdh/curve25519.impl.check.c
New: ecdh/curve25519.impl.do
New: ecdh/curve25519_athlon.c
New: ecdh/curve25519_athlon.h
New: ecdh/curve25519_athlon_const.s
New: ecdh/curve25519_athlon_fromdouble.s
New: ecdh/curve25519_athlon_init.s
New: ecdh/curve25519_athlon_mainloop.s
New: ecdh/curve25519_athlon_mult.s
New: ecdh/curve25519_athlon_square.s
New: ecdh/curve25519_athlon_todouble.s
New: ecdh/speed-20050915-frobenius.txt
New: ecdh/speed-20050915-silverton.txt
New: ecdh/speed-20050915-thoth.txt
New: ecdh/speed-20050915-whisper.txt
New: ecdh/speedreport.do
New: ecdh/test-curve25519.c
New: ecdh/togp
New: ecdh/x86cpuid.c
diff -ru .old-crypto/ecdh.html cr.yp.to/ecdh.html
--- .old-crypto/ecdh.html	2005-09-12 07:31:19.000000000 -0400
+++ cr.yp.to/ecdh.html	2005-09-16 02:50:44.000000000 -0400
@@ -15,22 +15,107 @@
 Curve25519 computes a 32-byte secret shared by the two users.
 This secret can then be used to authenticate and encrypt messages
 between the two users.
+<h2><a name="use"></a>How do I use Curve25519 in my own software?</h2>
+My <tt>curve25519</tt> library computes the Curve25519 function
+at very high speed.
+The library is in the public domain.
+You can and should include it in your own programs,
+rather than going to the effort of linking to a shared library;
+the compiled code is around 16 kilobytes, depending on the CPU.
+<p>
+To get started, download and unpack the <tt>curve25519</tt> library:
+<pre>
+     wget <a href="ecdh/curve25519-20050915.tar.gz">http://cr.yp.to/ecdh/curve25519-20050915.tar.gz</a>
+     gunzip &lt; curve25519-20050915.tar.gz | tar -xf -
+</pre>
+<p>
+To get an idea of how the library is structured, compile it:
+<pre>
+     cd curve25519-20050915
+     env CC='gcc -O2' make
+</pre>
+Make sure to use appropriate compiler options for your platform,
+such as <tt>-m64</tt> for the UltraSPARC.
+The library will refuse to compile
+if it doesn't pass some stringent internal tests;
+this normally means that your CPU or OS is currently unsupported.
+(This is a very early <tt>curve25519</tt> release:
+it supports only x86 chips, such as the Pentium and Athlon,
+and it isn't fully optimized for those chips.
+But it does hold a bunch of speed records already.)
+<p>
+Copy the library source files into your project:
+<pre>
+     cp `cat FILES.lib` yourproject/
+     cat Makefile.lib &gt;&gt; yourproject/Makefile
+</pre>
+For any C program that will use Curve25519,
+modify the program to include <tt>curve25519.h</tt>;
+also modify your <tt>Makefile</tt>
+to link the program with <tt>curve25519.a</tt>
+and to declare that the program depends on
+<tt>curve25519.a</tt> and <tt>curve25519.h</tt>.
+<p>
+Inside the program,
+to generate a 32-byte Curve25519 secret key,
+start by generating 32 secret random bytes
+from a cryptographically safe source:
+<tt>s[0]</tt>, <tt>s[1]</tt>, ..., <tt>s[31]</tt>.
+Then do
+<pre>
+     s[0] &= 248;
+     s[31] &= 127;
+     s[31] |= 64;
+</pre>
+to create a 32-byte Curve25519 secret key
+<tt>s[0]</tt>, <tt>s[1]</tt>, ..., <tt>s[31]</tt>.
+<p>
+To generate the corresponding 32-byte Curve25519 public key
+<tt>P[0]</tt>, <tt>P[1]</tt>, ..., <tt>P[31]</tt>,
+call
+<pre>
+     curve25519(P,s,basepoint);
+</pre>
+where the constant <tt>basepoint</tt> is 9 followed by all zeros:
+<pre>
+     const unsigned char basepoint[32] = {9};
+</pre>
+<p>
+Given someone else's Curve25519 public key
+<tt>Q[0]</tt>, <tt>Q[1]</tt>, ..., <tt>Q[31]</tt>,
+call
+<pre>
+     curve25519(u,s,Q);
+</pre>
+to generate a 32-byte secret
+<tt>u[0]</tt>, <tt>u[1]</tt>, ..., <tt>u[31]</tt>.
+The other user can compute the same secret
+by applying his secret key to your public key.
+Both of you can then hash this shared secret
+and use the result as a key for, e.g.,
+<a href="mac.html">Poly1305-AES</a>.
+<p>
+Please make sure to set up a Googleable web page
+identifying your program and saying that it is ``powered by Curve25519.''
 <h2>Technical details: the Curve25519 function</h2>
-Define p as the prime 2^255 - 19.
+Define p as the prime 2^{255} - 19.
 Define A = 486662.
 Define E as the elliptic curve y^2 = x^3 + Ax^2 + x over the field F_p.
-For each integer n,
-define Curve25519(n) in {0,1,...,p-1,infinity}
-as the x-coordinate of the nth multiple of the point
-(9,14781619447589544791020593568409986887264606134616475288964881837755586237401)
-on E.
-<p>
-More generally, for each integer n
-and each K in {0,1,...,p-1,infinity},
-define Curve25519(n,K) in {0,1,...,p-1,infinity}
-as the x-coordinate of the nth multiple of the point (K,...)
-on E over F_(p^2).
-There are usually two points (K,...),
+The Curve25519 function has two inputs:
+<ol>
+<li>a 32-byte string representing, in little-endian form,
+an integer n in 2^{254}+8{0,1,2,3,...,2^{251}-1};
+and
+<li>a 32-byte string representing, in little-endian form,
+an integer K in {0,1,2,3,...,2^{256}-1}.
+</ol>
+The output of Curve25519 is the 32-byte string
+representing, in little-endian form, an integer in {0,1,2,3,...,p-1}:
+namely,
+the x-coordinate of the nth multiples of the points (K,+-sqrt{K^3+AK^2+K})
+on E over F_{p^2},
+or 0 if nth multiples are the point at infinity.
+There are usually two different points (K,+-sqrt{K^3+AK^2+K}),
 but their nth multiples always have the same x-coordinates.
 <p>
 Security notes:
@@ -50,15 +135,5 @@
 0,
 -1,
 and infinity.
-<h2>Technical details: Diffie-Hellman</h2>
-A user's secret key is a uniform random element
-U of {2^254,2^254+8,2^254+16,2^254+24,...,2^255-8}.
-The user's public key is Curve25519(U).
-<p>
-Given another user's public key Curve25519(V),
-this user can compute Curve25519(U,Curve25519(V)) = Curve25519(UV),
-a secret shared by the two users.
-This secret is then hashed and used as a key
-for, e.g., <a href="mac.html">Poly1305-AES</a>.
 </body>
 </html>
diff -ru .old-crypto/hardware/assembly.html cr.yp.to/hardware/assembly.html
--- .old-crypto/hardware/assembly.html	2005-08-24 04:49:00.000000000 -0400
+++ cr.yp.to/hardware/assembly.html	2005-09-17 02:09:19.000000000 -0400
@@ -6,6 +6,7 @@
 <h1>Assembling a computer from components</h1>
 <h2>Assembling the 2005.05.14 standard workstation</h2>
 The instructions below are for the 2004.10.10 standard workstation.
+<p>
 The 2005.05.14 standard workstation has the following changes:
 <ul>
 <li>The UATA hard drive (and cable) have been replaced by a SATA hard drive
@@ -22,8 +23,31 @@
 Effects on assembly:
 none, but slightly different pictures.
 </ul>
-The 2005.08.23 standard workstation has more changes,
-not reflected here yet.
+<p>
+The 2005.08.23 standard workstation has more changes.
+There turns out to be a serious bug
+in the motherboard BIOS in the 2005.08.23 workstation,
+and fixing that bug requires the following extra steps
+once the computer has beeped:
+<ul>
+<li>On a working computer, download the file <tt>A8V-ASUS-0213.ROM</tt>
+from the Asus A8V download page.
+This file has MD5 checksum 9c44e207cb3e37a6dc797aa6e1b99f5e.
+<li>On a working computer, rename the file as <tt>A8VB.ROM</tt>
+and burn that file to a CD.
+<li>On the standard workstation,
+as soon as the initial boot screen appears,
+press Alt-F2 to enter the BIOS EZ Flash utility,
+and then insert the CD.
+The EZ Flash utility will read <tt>A8VB.ROM</tt> from CD,
+erase the system's BIOS,
+and copy <tt>A8VB.ROM</tt> to the system's BIOS;
+don't turn the computer off while this is happening!
+<li>After reboot, don't worry about the bad-checksum message;
+simply press F2 to continue.
+</ul>
+Other changes in the 2005.08.23 standard workstation
+are not reflected here yet.
 <h2>Assembling the 2004.10.10 standard workstation</h2>
 The 2004.10.10 standard workstation
 is a very nice x86 (Intel-compatible) computer:
@@ -237,7 +261,7 @@
 Watch the CPU fan, and press the front power button on the case.
 If the CPU fan doesn't start spinning, turn power off immediately;
 you have a problem.
-If the computer doesn't beep within ten seconds, turn power off;
+If the computer doesn't beep within thirty seconds, turn power off;
 you have a problem.
 If the CPU fan starts spinning and the computer beeps, turn power off;
 you have a working computer.
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html	2005-09-13 01:48:18.000000000 -0400
+++ cr.yp.to/streamciphers.html	2005-09-13 15:57:58.000000000 -0400
@@ -274,7 +274,8 @@
 ``If a key is used with about 2^61 random IVs,
 and 20,000 keystream bytes are generated from each IV,
 then the key could be recovered easily.''
-<b>No response yet from the author.</b>
+Author's response is that this does not have
+better price-performance ratio than brute force.
 <h2>Notes on YAMB</h2>
 Key as large as 32 bytes.
 Nonce as large as 16 bytes.