cr.yp.to update
[email protected] 17 Sep 2005 19:21:21 -0000
| Newsgroups | gmane.comp.djb.announce |
|---|---|
| Message-ID | <[email protected]> |
conferences.html | 2
conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html | 31 +-
conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/38.ppt |binary
conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html | 12
ecdh.html | 121 ++++++++--
hardware/assembly.html | 30 ++
streamciphers.html | 3
7 files changed, 151 insertions(+), 48 deletions(-)
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/10.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/11.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/12.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/13.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/14.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/16.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/17.pps
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/18.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/19.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/5.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/6.ppt
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/7.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/8.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/p/9.pdf
diff -ru .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html
--- .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html 2005-08-29 22:20:00.000000000 -0400
+++ cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/program.html 2005-09-06 08:34:41.000000000 -0400
@@ -322,7 +322,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Krzysztof Pietrzak</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/8.pdf">Presentation</a> </td>
</tr>
@@ -405,7 +405,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Robert Granger and Fréderik Vercauteren</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/18.pdf">Presentation</a></td>
</tr>
@@ -443,7 +443,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Yi Lu, Willi Meier, and Serge Vaudenay</td>
- <td class=xl35><a href="p/1.pdf">Presentation</a></td>
+ <td class=xl35><a href="p/16.pdf">Presentation</a></td>
</tr>
<tr> <td height=13> </tr>
@@ -508,7 +508,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Joël Alwen, Giuseppe Persiano, and Ivan Visconti</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/14.ppt">Presentation</a></td>
</tr>
@@ -628,7 +628,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange, John Malone-Lee, Gregory Neven, Pascal Paillier, and Haixia Shi</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/11.ppt">Presentation</a></td>
</tr>
@@ -695,7 +695,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Lea Kissner and Dawn Song</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/10.pdf">Presentation</a></td>
</tr>
@@ -749,7 +749,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Jung Yeon Hwang, Dong Hoon Lee, and Jongin Lim</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/6.ppt">Presentation</a></td>
</tr>
@@ -912,7 +912,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Serge Vaudenay</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/1.pdf">Presentation</a></td>
</tr>
@@ -958,7 +958,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Ronald Cramer, Vanesa Daza, Ignacio Gracia, Jorge Jimégnez Urroz, Gregor Leander, Jaume Martí-Farré, and Carles Padró</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/13.pdf">Presentation</a></td>
</tr>
@@ -977,7 +977,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Ronald Cramer, Serge Fehr, and Martijn Stam</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/5.pdf">Presentation</a></td>
</tr>
@@ -1077,7 +1077,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Ivan Damgård and Yuval Ishai</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="r/15.ppt">Presentation</a></td>
</tr>
@@ -1096,7 +1096,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Omer Barkol and Yuval Ishai</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/19.ppt">Presentation</a></td>
</tr>
@@ -1161,7 +1161,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Jean-Sébastien Coron, Yevgeniy Dodis, Cécile Malinaud, and Prashant Puniya</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/17.pps">Presentation</a></td>
</tr>
@@ -1317,6 +1317,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Thomas Holenstein and Renato Renner</td>
+ <td class=xl35><a href="p/12.pdf">Presentation</a></td>
</tr>
@@ -1335,7 +1336,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Ivan Damgård, Thomas B. Pedersen, and Louis Salvail</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/9.pdf">Presentation</a></td>
</tr>
<tr> <td height=13> </tr>
@@ -1400,7 +1401,7 @@
<td align="center" class=xl33></td>
<td class=xl34></td>
<td class=xl35>Mihir Bellare, Krzysztof Pietrzak, and Phillip Rogaway</td>
- <td class=xl35> </td>
+ <td class=xl35><a href="p/7.pdf">Presentation</a></td>
</tr>
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/12.mov
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/12.pdf
Binary files .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/38.ppt and cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/38.ppt differ
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/4.mov
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/4.pdf
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/6.mov
New: conferences/2005-crypto/www.iacr.org/conferences/crypto2005/r/6.ppt
diff -ru .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html
--- .old-crypto/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html 2005-08-29 10:36:27.000000000 -0400
+++ cr.yp.to/conferences/2005-crypto/www.iacr.org/conferences/crypto2005/rumpSchedule.html 2005-08-31 20:53:20.000000000 -0400
@@ -163,8 +163,8 @@
<td> </td>
<td> </td>
<td>Antoine Joux and Reynald Lercier</td>
- <td></td>
- <td></td>
+ <td><a href="r/4.pdf">Presentation</a></td>
+ <td><a href="r/4.mov">Video</a></td>
</tr>
<tr valign="top">
<td> </td>
@@ -219,8 +219,8 @@
<td>20:03</td>
<td><strong>Full AES key extraction in 65 milliseconds using cache
attacks</strong></td>
- <td></td>
- <td></td>
+ <td><a href="r/6.ppt">Presentation</a></td>
+ <td><a href="r/6.mov">Video</a></td>
</tr>
<tr valign="top">
<td> </td>
@@ -387,8 +387,8 @@
<td> </td>
<td> </td>
<td>Dan Bernstein</td>
- <td> </td>
- <td><a href="r/12.pdf">Video</a></td>
+ <td><a href="r/12.pdf">Presentation</a></td>
+ <td><a href="r/12.mov">Video</a></td>
</tr>
<tr valign="top">
<td> </td>
New: conferences/2005-ecc
diff -ru .old-crypto/conferences.html cr.yp.to/conferences.html
--- .old-crypto/conferences.html 2005-08-28 23:13:59.000000000 -0400
+++ cr.yp.to/conferences.html 2005-09-16 04:10:12.000000000 -0400
@@ -472,6 +472,8 @@
<p>
2005.09.19-2005.09.21, invited, plan to attend:
Elliptic Curve Cryptography (ECC) 2005.
+<a href="http://www.cacr.math.uwaterloo.ca/conferences/2005/ecc2005/announcement.html">http://www.cacr.math.uwaterloo.ca/conferences/2005/ecc2005/announcement.html</a>;
+<a href="conferences/2005-ecc/www.cacr.math.uwaterloo.ca/conferences/2005/ecc2005/announcement.html">mirror</a>.
Denmark Technical University, Copenhagen.
<p>
2005.10.15-2005.10.15:
New: ecdh/FILES
New: ecdh/FILES.lib
New: ecdh/Makefile
New: ecdh/Makefile.lib
New: ecdh/cpucycles.a.do
New: ecdh/cpucycles.h.do
New: ecdh/cpucycles_athlon.h
New: ecdh/cpucycles_athlon.s
New: ecdh/curve25519-20050915.tar.gz
New: ecdh/curve25519-speed.c
New: ecdh/curve25519.a.do
New: ecdh/curve25519.h.do
New: ecdh/curve25519.impl.check.c
New: ecdh/curve25519.impl.do
New: ecdh/curve25519_athlon.c
New: ecdh/curve25519_athlon.h
New: ecdh/curve25519_athlon_const.s
New: ecdh/curve25519_athlon_fromdouble.s
New: ecdh/curve25519_athlon_init.s
New: ecdh/curve25519_athlon_mainloop.s
New: ecdh/curve25519_athlon_mult.s
New: ecdh/curve25519_athlon_square.s
New: ecdh/curve25519_athlon_todouble.s
New: ecdh/speed-20050915-frobenius.txt
New: ecdh/speed-20050915-silverton.txt
New: ecdh/speed-20050915-thoth.txt
New: ecdh/speed-20050915-whisper.txt
New: ecdh/speedreport.do
New: ecdh/test-curve25519.c
New: ecdh/togp
New: ecdh/x86cpuid.c
diff -ru .old-crypto/ecdh.html cr.yp.to/ecdh.html
--- .old-crypto/ecdh.html 2005-09-12 07:31:19.000000000 -0400
+++ cr.yp.to/ecdh.html 2005-09-16 02:50:44.000000000 -0400
@@ -15,22 +15,107 @@
Curve25519 computes a 32-byte secret shared by the two users.
This secret can then be used to authenticate and encrypt messages
between the two users.
+<h2><a name="use"></a>How do I use Curve25519 in my own software?</h2>
+My <tt>curve25519</tt> library computes the Curve25519 function
+at very high speed.
+The library is in the public domain.
+You can and should include it in your own programs,
+rather than going to the effort of linking to a shared library;
+the compiled code is around 16 kilobytes, depending on the CPU.
+<p>
+To get started, download and unpack the <tt>curve25519</tt> library:
+<pre>
+ wget <a href="ecdh/curve25519-20050915.tar.gz">http://cr.yp.to/ecdh/curve25519-20050915.tar.gz</a>
+ gunzip < curve25519-20050915.tar.gz | tar -xf -
+</pre>
+<p>
+To get an idea of how the library is structured, compile it:
+<pre>
+ cd curve25519-20050915
+ env CC='gcc -O2' make
+</pre>
+Make sure to use appropriate compiler options for your platform,
+such as <tt>-m64</tt> for the UltraSPARC.
+The library will refuse to compile
+if it doesn't pass some stringent internal tests;
+this normally means that your CPU or OS is currently unsupported.
+(This is a very early <tt>curve25519</tt> release:
+it supports only x86 chips, such as the Pentium and Athlon,
+and it isn't fully optimized for those chips.
+But it does hold a bunch of speed records already.)
+<p>
+Copy the library source files into your project:
+<pre>
+ cp `cat FILES.lib` yourproject/
+ cat Makefile.lib >> yourproject/Makefile
+</pre>
+For any C program that will use Curve25519,
+modify the program to include <tt>curve25519.h</tt>;
+also modify your <tt>Makefile</tt>
+to link the program with <tt>curve25519.a</tt>
+and to declare that the program depends on
+<tt>curve25519.a</tt> and <tt>curve25519.h</tt>.
+<p>
+Inside the program,
+to generate a 32-byte Curve25519 secret key,
+start by generating 32 secret random bytes
+from a cryptographically safe source:
+<tt>s[0]</tt>, <tt>s[1]</tt>, ..., <tt>s[31]</tt>.
+Then do
+<pre>
+ s[0] &= 248;
+ s[31] &= 127;
+ s[31] |= 64;
+</pre>
+to create a 32-byte Curve25519 secret key
+<tt>s[0]</tt>, <tt>s[1]</tt>, ..., <tt>s[31]</tt>.
+<p>
+To generate the corresponding 32-byte Curve25519 public key
+<tt>P[0]</tt>, <tt>P[1]</tt>, ..., <tt>P[31]</tt>,
+call
+<pre>
+ curve25519(P,s,basepoint);
+</pre>
+where the constant <tt>basepoint</tt> is 9 followed by all zeros:
+<pre>
+ const unsigned char basepoint[32] = {9};
+</pre>
+<p>
+Given someone else's Curve25519 public key
+<tt>Q[0]</tt>, <tt>Q[1]</tt>, ..., <tt>Q[31]</tt>,
+call
+<pre>
+ curve25519(u,s,Q);
+</pre>
+to generate a 32-byte secret
+<tt>u[0]</tt>, <tt>u[1]</tt>, ..., <tt>u[31]</tt>.
+The other user can compute the same secret
+by applying his secret key to your public key.
+Both of you can then hash this shared secret
+and use the result as a key for, e.g.,
+<a href="mac.html">Poly1305-AES</a>.
+<p>
+Please make sure to set up a Googleable web page
+identifying your program and saying that it is ``powered by Curve25519.''
<h2>Technical details: the Curve25519 function</h2>
-Define p as the prime 2^255 - 19.
+Define p as the prime 2^{255} - 19.
Define A = 486662.
Define E as the elliptic curve y^2 = x^3 + Ax^2 + x over the field F_p.
-For each integer n,
-define Curve25519(n) in {0,1,...,p-1,infinity}
-as the x-coordinate of the nth multiple of the point
-(9,14781619447589544791020593568409986887264606134616475288964881837755586237401)
-on E.
-<p>
-More generally, for each integer n
-and each K in {0,1,...,p-1,infinity},
-define Curve25519(n,K) in {0,1,...,p-1,infinity}
-as the x-coordinate of the nth multiple of the point (K,...)
-on E over F_(p^2).
-There are usually two points (K,...),
+The Curve25519 function has two inputs:
+<ol>
+<li>a 32-byte string representing, in little-endian form,
+an integer n in 2^{254}+8{0,1,2,3,...,2^{251}-1};
+and
+<li>a 32-byte string representing, in little-endian form,
+an integer K in {0,1,2,3,...,2^{256}-1}.
+</ol>
+The output of Curve25519 is the 32-byte string
+representing, in little-endian form, an integer in {0,1,2,3,...,p-1}:
+namely,
+the x-coordinate of the nth multiples of the points (K,+-sqrt{K^3+AK^2+K})
+on E over F_{p^2},
+or 0 if nth multiples are the point at infinity.
+There are usually two different points (K,+-sqrt{K^3+AK^2+K}),
but their nth multiples always have the same x-coordinates.
<p>
Security notes:
@@ -50,15 +135,5 @@
0,
-1,
and infinity.
-<h2>Technical details: Diffie-Hellman</h2>
-A user's secret key is a uniform random element
-U of {2^254,2^254+8,2^254+16,2^254+24,...,2^255-8}.
-The user's public key is Curve25519(U).
-<p>
-Given another user's public key Curve25519(V),
-this user can compute Curve25519(U,Curve25519(V)) = Curve25519(UV),
-a secret shared by the two users.
-This secret is then hashed and used as a key
-for, e.g., <a href="mac.html">Poly1305-AES</a>.
</body>
</html>
diff -ru .old-crypto/hardware/assembly.html cr.yp.to/hardware/assembly.html
--- .old-crypto/hardware/assembly.html 2005-08-24 04:49:00.000000000 -0400
+++ cr.yp.to/hardware/assembly.html 2005-09-17 02:09:19.000000000 -0400
@@ -6,6 +6,7 @@
<h1>Assembling a computer from components</h1>
<h2>Assembling the 2005.05.14 standard workstation</h2>
The instructions below are for the 2004.10.10 standard workstation.
+<p>
The 2005.05.14 standard workstation has the following changes:
<ul>
<li>The UATA hard drive (and cable) have been replaced by a SATA hard drive
@@ -22,8 +23,31 @@
Effects on assembly:
none, but slightly different pictures.
</ul>
-The 2005.08.23 standard workstation has more changes,
-not reflected here yet.
+<p>
+The 2005.08.23 standard workstation has more changes.
+There turns out to be a serious bug
+in the motherboard BIOS in the 2005.08.23 workstation,
+and fixing that bug requires the following extra steps
+once the computer has beeped:
+<ul>
+<li>On a working computer, download the file <tt>A8V-ASUS-0213.ROM</tt>
+from the Asus A8V download page.
+This file has MD5 checksum 9c44e207cb3e37a6dc797aa6e1b99f5e.
+<li>On a working computer, rename the file as <tt>A8VB.ROM</tt>
+and burn that file to a CD.
+<li>On the standard workstation,
+as soon as the initial boot screen appears,
+press Alt-F2 to enter the BIOS EZ Flash utility,
+and then insert the CD.
+The EZ Flash utility will read <tt>A8VB.ROM</tt> from CD,
+erase the system's BIOS,
+and copy <tt>A8VB.ROM</tt> to the system's BIOS;
+don't turn the computer off while this is happening!
+<li>After reboot, don't worry about the bad-checksum message;
+simply press F2 to continue.
+</ul>
+Other changes in the 2005.08.23 standard workstation
+are not reflected here yet.
<h2>Assembling the 2004.10.10 standard workstation</h2>
The 2004.10.10 standard workstation
is a very nice x86 (Intel-compatible) computer:
@@ -237,7 +261,7 @@
Watch the CPU fan, and press the front power button on the case.
If the CPU fan doesn't start spinning, turn power off immediately;
you have a problem.
-If the computer doesn't beep within ten seconds, turn power off;
+If the computer doesn't beep within thirty seconds, turn power off;
you have a problem.
If the CPU fan starts spinning and the computer beeps, turn power off;
you have a working computer.
diff -ru .old-crypto/streamciphers.html cr.yp.to/streamciphers.html
--- .old-crypto/streamciphers.html 2005-09-13 01:48:18.000000000 -0400
+++ cr.yp.to/streamciphers.html 2005-09-13 15:57:58.000000000 -0400
@@ -274,7 +274,8 @@
``If a key is used with about 2^61 random IVs,
and 20,000 keystream bytes are generated from each IV,
then the key could be recovered easily.''
-<b>No response yet from the author.</b>
+Author's response is that this does not have
+better price-performance ratio than brute force.
<h2>Notes on YAMB</h2>
Key as large as 32 bytes.
Nonce as large as 16 bytes.