Re: retro crypto

Ben Laurie <[email protected]> Sun, 12 Jan 2020 05:44:57 +0000
Newsgroups gmane.comp.encryption.general
Message-ID <CAG5KPzzSBkCyWwVpgKmVb6=XnOYeS93xvS6wU_teEu-Ky9ykzA@mail.gmail.com>
--===============7599423018301155857==
Content-Type: multipart/alternative; boundary="00000000000092a700059beadc05"

--00000000000092a700059beadc05
Content-Type: text/plain; charset="UTF-8"

On Wed, 8 Jan 2020 at 21:59, John Denker via cryptography <
[email protected]> wrote:

> Using 1970s technology, you can build a cipher machine on
> rotor-like principles.  It has the virtue of "not running
> any kind of malware because it can't".
>
> For example:  Use LFSRs (linear feedback shift registers)
> to drive the address lines on a bunch of EPROMs.  XOR the
> EEPROM outputs.
>
> Discussion:  If you use a LFSR directly, as a stream cipher,
> it is straightforward to ascertain the current state, whereupon
> you can predict the future state for all time.  But if you
> muddy it up using an EPROM (as a form of S-box) then that's
> not so easy.
>

Are you assuming the contents of the EPROM is secret? If so, why not use it
as a OTP? If not, then surely this construction is trivially insecure?

--00000000000092a700059beadc05
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">=
<div dir=3D"ltr" class=3D"gmail_attr">On Wed, 8 Jan 2020 at 21:59, John Den=
ker via cryptography &lt;<a href=3D"mailto:[email protected]">crypt=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quo=
te" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204=
);padding-left:1ex">Using 1970s technology, you can build a cipher machine =
on<br>
rotor-like principles.=C2=A0 It has the virtue of &quot;not running<br>
any kind of malware because it can&#39;t&quot;.<br>
<br>
For example:=C2=A0 Use LFSRs (linear feedback shift registers)<br>
to drive the address lines on a bunch of EPROMs.=C2=A0 XOR the<br>
EEPROM outputs.<br>
<br>
Discussion:=C2=A0 If you use a LFSR directly, as a stream cipher,<br>
it is straightforward to ascertain the current state, whereupon<br>
you can predict the future state for all time.=C2=A0 But if you<br>
muddy it up using an EPROM (as a form of S-box) then that&#39;s<br>
not so easy.<br></blockquote><div><br></div><div>Are you assuming the conte=
nts of the EPROM is secret? If so, why not use it as a OTP? If not, then su=
rely this construction is trivially insecure?=C2=A0</div></div></div>

--00000000000092a700059beadc05--

--===============7599423018301155857==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
The cryptography mailing list
[email protected]
https://www.metzdowd.com/mailman/listinfo/cryptography

--===============7599423018301155857==--