Re: retro crypto
Ben Laurie <[email protected]> Sun, 12 Jan 2020 05:44:57 +0000
| Newsgroups | gmane.comp.encryption.general |
|---|---|
| Message-ID | <CAG5KPzzSBkCyWwVpgKmVb6=XnOYeS93xvS6wU_teEu-Ky9ykzA@mail.gmail.com> |
--===============7599423018301155857== Content-Type: multipart/alternative; boundary="00000000000092a700059beadc05" --00000000000092a700059beadc05 Content-Type: text/plain; charset="UTF-8" On Wed, 8 Jan 2020 at 21:59, John Denker via cryptography < [email protected]> wrote: > Using 1970s technology, you can build a cipher machine on > rotor-like principles. It has the virtue of "not running > any kind of malware because it can't". > > For example: Use LFSRs (linear feedback shift registers) > to drive the address lines on a bunch of EPROMs. XOR the > EEPROM outputs. > > Discussion: If you use a LFSR directly, as a stream cipher, > it is straightforward to ascertain the current state, whereupon > you can predict the future state for all time. But if you > muddy it up using an EPROM (as a form of S-box) then that's > not so easy. > Are you assuming the contents of the EPROM is secret? If so, why not use it as a OTP? If not, then surely this construction is trivially insecure? --00000000000092a700059beadc05 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">= <div dir=3D"ltr" class=3D"gmail_attr">On Wed, 8 Jan 2020 at 21:59, John Den= ker via cryptography <<a href=3D"mailto:[email protected]">crypt= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quo= te" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204= );padding-left:1ex">Using 1970s technology, you can build a cipher machine = on<br> rotor-like principles.=C2=A0 It has the virtue of "not running<br> any kind of malware because it can't".<br> <br> For example:=C2=A0 Use LFSRs (linear feedback shift registers)<br> to drive the address lines on a bunch of EPROMs.=C2=A0 XOR the<br> EEPROM outputs.<br> <br> Discussion:=C2=A0 If you use a LFSR directly, as a stream cipher,<br> it is straightforward to ascertain the current state, whereupon<br> you can predict the future state for all time.=C2=A0 But if you<br> muddy it up using an EPROM (as a form of S-box) then that's<br> not so easy.<br></blockquote><div><br></div><div>Are you assuming the conte= nts of the EPROM is secret? If so, why not use it as a OTP? If not, then su= rely this construction is trivially insecure?=C2=A0</div></div></div> --00000000000092a700059beadc05-- --===============7599423018301155857== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ The cryptography mailing list [email protected] https://www.metzdowd.com/mailman/listinfo/cryptography --===============7599423018301155857==--