Re: Speck Cipher Integration with OpenSSL

Daniel Kahn Gillmor <[email protected]> Wed, 10 Jan 2018 02:30:59 -0500
Newsgroups gmane.comp.encryption.openssl.devel
Message-ID <[email protected]>
--===============8057592281881474736==
Content-Type: multipart/signed; boundary="=-=-=";
	micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Tue 2018-01-09 18:41:25 -0800, William Bathurst wrote:
> [ dkg wrote: ]
>> My understanding is that the algorithm designers and primary advocates
>> have not been particularly forthcoming with their design goals, and
>> their reputation is mixed, at best.
>
> Simon and Speck has been in the public domain for a number of years and=20
> there are quite a few white papers and articles on the Ciphers. Allowing=
=20
> public scrutiny and crypto-analysis is one way to put a cipher through=20
> the grinder to make sure there are no back doors or weaknesses.

It sounds like we agree that adversarial cryptanalysis is a necessary
component of evaluating cryptographic algorithms today. :)

And yes, Simon and Speck have indeed been published for a while now.  My
understanding is that there has been a steady stream of cryptanalysis
against them, which has made some non-negligible progress in whittling
down their initially-claimed security levels.

Meanwhile (as i said above), the designers have not been particularly
forthcoming with producing their design goals and their own
cryptanalysis, despite requests for those documents.  Shouldn't the
designers of algorithms intended to be used by the public also be
transparent about their design goals and their own understanding of the
strengths and weaknesses of the algorithms they're proposing?  This
seems particularly relevant when the designers have been plausibly
accused of trying to pass off sub-standard cryptographic algorithms as
acceptable for public consumption (e.g. "we got punked" as one NIST
representative described the Dual EC DRBG fiasco).

I'd personally like to see documentation of the internal design goals
and cryptanalysis from the authors of Simon and Speck before considering
it for wider adoption, especially given that reasonably efficient strong
ciphers are already available.  Or do you think that knowing the
designers' goals and internal analysis should not a relevant criterion
for consideration?

Regards,

           --dkg

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEzicvlOwymaWlnoHjyu+ogyFnUzMFAlpVwTMACgkQyu+ogyFn
UzOWYhAAxdLSu1c4VrSoZ2MuIAWNWnJFuAHlqsQeVDFBZGCQ++Xnur773Saec6yt
bptLwgIqRLRWqgJx8PmW/3DDTrcx6NFCdwivRrLE1wnN0fkjFyucLbfQBzQ9M65+
Ov1TPa0fcZBOzQwVlW4HsexzX0pD6nrh8BsRFlLcuuynkk6wki6JNsf1W6+070bC
0+v/vmAvgLvGejKZgDlTygmGLpnIpTTzbcuSM+S+i+BmA8pJyJCbdjX+UIKI47Nm
OzpQHTFr8I6FfvGS4T9SBX5Nqdtc7I5FedI8pa9PKFNqS5j1CkzrxtjK0xcpSF9K
ovvSFJgPzqsxl0sjQGspFev/YBAYgLmrStae/Mhk/BecX1X0uATWyxI6FHiZ2MEj
WutFiQPnh9rE3VDM/1sfL4wLhyoGjZCaImHZVXVbUfIHLMw8eYh99Z/UlVVJ2d1U
isN3fZdvBEptmr0rADWix0rRC+1MJYx1ofXjBcvq2XNspUVzfL7/Oj/EByFRQCzB
gc7KwzXQivvgLJoOmmUlYxYPIDY6txIw0s33bny1onrljejJazS7V11sdDmz9jpC
c0Bj/Gq6PQHjtwEVrRWonqxSOT/w0M1U1aapwnMCLNvPJit1NpzqGgmJFCq1Oswj
zf3z3d9gCI5s5W04Vo3mTN4sk7QX97HSST3OuQsAArX/vC2ZmBg=
=5Axk
-----END PGP SIGNATURE-----
--=-=-=--

--===============8057592281881474736==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

--===============8057592281881474736==--