Using SURF as a random data source

Bruce Guenter <[email protected]> Wed, 24 Mar 2004 14:10:44 -0600
Newsgroups gmane.org.djb.miscellaneous
Message-ID <[email protected]>
--6TrnltStXW4iwmi0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Greetings.

Is it reasonable to use surf as a cryptographically strong random data
source?

Obviously, if I use random secret data for both the seed and the input,
the result will also be secret.  The biggest question I have is how to
generate more than one output from the same secret in a robust manner.

If the math for SURF is sound (and I have no reason to doubt it is),
then simply treating the input as one long 384-bit counter will produce
a random number stream that is 2^(384*8) words long.  This seems to be
the simplest way of producing a random data source with a known period.
Will this work as described?

Thank you.
--=20
Bruce Guenter <[email protected]> http://em.ca/~bruceg/ http://untroubled.org/
OpenPGP key: 699980E8 / D0B7 C8DD 365D A395 29DA  2E2A E96F B2DC 6999 80E8

--6TrnltStXW4iwmi0
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAYetE6W+y3GmZgOgRAorlAJ9cXMnKbjRr2DKEE7W9f2eqTCe0vACeIiGU
oH9nD4C/5aHM/QFSlN8mqS4=
=fqFE
-----END PGP SIGNATURE-----

--6TrnltStXW4iwmi0--