<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kryptoblog &#187; Internet</title>
	<atom:link href="http://www.strombergson.com/kryptoblog/category/internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.strombergson.com/kryptoblog</link>
	<description>Kryptografi och IT-säkerhet på svenska</description>
	<lastBuildDate>Thu, 20 Jan 2011 21:25:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Två observationer om AES</title>
		<link>http://www.strombergson.com/kryptoblog/2010/11/23/tva-observationer-om-aes/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/11/23/tva-observationer-om-aes/#comments</comments>
		<pubDate>Tue, 23 Nov 2010 21:24:39 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Forskning]]></category>
		<category><![CDATA[Inbyggda system]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AES]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1412</guid>
		<description><![CDATA[<p>Det har dykt upp tv&#229; olika observationer av egenskaper hos <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard">blockkryptot <span class="caps">AES</span></a>.</p>

	<p>Den f&#246;rsta observationen &#228;r <a href="http://arxiv.org/">publicerad p&#229; det &#246;ppna artikelarkivet Arxiv</a>. Artikeln handlar om huruvida <span class="caps">AES</span> kan ses som en slumpm&#228;ssig transform av indatat,&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>Det har dykt upp tv&#229; olika observationer av egenskaper hos <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard">blockkryptot <span class="caps">AES</span></a>.</p>

	<p>Den f&#246;rsta observationen &#228;r <a href="http://arxiv.org/">publicerad p&#229; det &#246;ppna artikelarkivet Arxiv</a>. Artikeln handlar om huruvida <span class="caps">AES</span> kan ses som en slumpm&#228;ssig transform av indatat, eller om det finns ett detekterbart m&#246;nster &#8211; ett m&#246;nster som g&#229;r att gissa. En ideal kryptoalgoritm skall m&#246;ta den s&#229; kallade Random Oracle-modellen d&#228;r det inte skall g&#229; att p&#229; f&#246;rhand gissa vilken sekvens som skapas. En avvikelse fr&#229;n denna slumpm&#228;ssighet inneb&#228;r en svaghet hos algoritmen.</p>

	<p>F&#246;rfattarna tAnna Rimoldi, Massimiliano Sala och Enrico Bertolazzi skriver i sin artikel <em><a href="http://arxiv.org/abs/1011.2644">Do <span class="caps">AES</span> encryptions act randomly?</a></em> f&#246;ljande:</p>

	<p><blockquote><br />
With our attack we give some statistical evidence that the set of <span class="caps">AES</span>-$128 encryptions acts on the message space in a way significantly different than that of the set of random permutations acting on the same space.</p>

	<p>While we feel that more computational experiments by independent third parties are needed in order to validate our statistical results, we show that the non-random behaviour is the same as we would predict using the property of our embedding.</p>

	<p>Indeed, the embedding lowers the nonlinearity of the <span class="caps">AES</span> rounds and therefore the <span class="caps">AES</span> encryptions tend, on average, to keep low the rank of low-rank matrices constructed in the large space. Our attack needs 2**23 plaintext-ciphertext pairs and costs the equivalent of 2**48 encryptions.</p>

	<p>We expect our attack to work also for <span class="caps">AES</span>-192 and <span class="caps">AES</span>-$56, as confirmed by preliminary experiments.<br />
</blockquote></p>

	<p>Om jag fattat det r&#228;tt kan f&#246;rfattarna allts&#229; s&#228;rskilja/identifiera att en viss m&#228;ngd data &#228;r krypterat med <span class="caps">AES</span>, eller om det &#228;r en rent slumpm&#228;ssig sekvens. Dom kan allts&#229; inte extrahera nyckeln. Och notera att dom beh&#246;ver par med okrypterat och motsvarande krypterat material. Detta &#228;r mao inte en attack som g&#246;r <span class="caps">AES</span> v&#228;rdel&#246;s, utan &#228;r snarare en observation.</p>

	<p>Den andra artikeln, <em><a href="http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.118.4090&#38;rep=rep1&#38;type=pdf">On Deviations of the <span class="caps">AES S</span>-box when Represented as Vector Valued Boolean Function</a></em>, tittar mer specifikt p&#229; den substitutionstabell (S-box) som finns i <span class="caps">AES</span>.</p>

	<p>S-boxen, &#228;ven kallad SubBytes-steget i <span class="caps">AES </span>&#228;r en enkel tabell som byter ut en byte mot en annan. Tabellen ser ut s&#229; h&#228;r:</p>

	<p><img src="http://aes.andreasaw.com/images/sbox.gif" alt="AES Sbox" /></p>

	<p>S-boxen bidrar till kryptots olinj&#228;ra egenskaper, men f&#246;r att g&#246;ra det skall det inte finnas n&#229;got enkelt m&#246;nster bakom S-boxen, utan b&#246;r vara en slumpm&#228;ssig h&#246;g med tal. Samtidigt vill man v&#228;ldigt g&#228;rna veta varifr&#229;n dessa konstanter kommer ifr&#229;n &#8211; hur dom genererats.</p>

	<p>S&#228;kerhetsexperten Bruce Schneier brukar prata om <em><a href="http://en.wikipedia.org/wiki/Nothing_up_my_sleeve_number">Nothing up my sleeve numbers</a></em> som en viktig egenskap hos en s&#228;kerhetsfunktion. Vad han avser med denna egenskap &#228;r att det inte skall finnas hemliga antaganden eller delar av funktionen, delar vilkas s&#228;kerhetsm&#228;ssiga betydelse inte g&#229;r att avg&#246;ra. Bra specifikationer talar d&#228;rf&#246;r om varifr&#229;n konstanter kommer ifr&#229;n.</p>

	<p>I fallet med <span class="caps">AES S</span>-box &#228;r det i standarden &#228;r det tydligt specificerat att den genereras p&#229; ett specifikt s&#228;tt. <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard#The_SubBytes_step">Wikipedia ger en bra beskrivning av SubBytes</a>:</p>

	<p><blockquote><br />
In the SubBytes step, each byte in the array is updated using an 8-bit substitution box, the Rijndael S-box. This operation provides the non-linearity in the cipher. The S-box used is derived from the multiplicative inverse over GF(28), known to have good non-linearity properties. To avoid attacks based on simple algebraic properties, the S-box is constructed by combining the inverse function with an invertible affine transformation. The S-box is also chosen to avoid any fixed points (and so is a derangement), and also any opposite fixed points.<br />
</blockquote></p>

	<p>Att man k&#228;nner till hur S-boxen &#228;r genererad utnyttjas &#228;ven i vissa <span class="caps">AES</span>-implementationer som ist&#228;llet f&#246;r att ha en fast tabell p&#229; 256 Bytes r&#228;knar ut S-boxen under det att transformen genomf&#246;rs. Detta tar tid, men sparar minnesutrymme.</p>

	<p>N&#229;, tillbaka till artikeln. Vad f&#246;rfattarna Danilo Gligoroski och Marie Elisabeth Gaup Moe visar &#228;r att, till skillnad p&#229; vad Wikipedia s&#228;ger visar sig S-boxen inte vara riktigt s&#229; slumpm&#228;ssig och vara s&#229; icke-linj&#228;r som man skulle kunna hoppas utifr&#229;n ett idealperspektiv, och vad man tidigare antagit. F&#246;rfattarna skriver:</p>

	<p><blockquote><br />
In this paper we give an explicit representation of the <span class="caps">AES S</span>-box as a vector valued Boolean function in GF(2)8 and show several significant deviations in the number of terms that follows from that representation when it is compared with the algebraic representation of randomly generated permutations of 256 elements. We see this as a potential research direction in cryptanalysis of <span class="caps">AES</span>.<br />
</blockquote></p>

	<p>Inte heller denna artikel visar p&#229; en direkt, praktisk attack &#8211; utan &#228;r en observation. En av f&#246;rfattarna, Danilo Gligoroski har &#228;ven sagt p&#229; en maillista att han inte ser speciellt stora m&#246;jligheter att utnyttja deras observation i en seri&#246;s attack.</p>

	<p>Vad &#228;r d&#229; slutsatsen efter denna l&#229;nga postning? Ungef&#228;r det h&#228;r: <span class="caps">AES</span> har inte fallit, l&#229;ngt ifr&#229;n det. Men tillsammans med <a href="http://www.strombergson.com/kryptoblog/2010/06/12/tva-nya-attacker-pa-aes/">tidigare publicerade attacker</a> de senaste &#229;ren visar de h&#228;r artiklarna p&#229; att det sker framsteg inom kryptanalysen.</p>

	<p>Detta visar &#228;ven hur viktigt det &#228;r att l&#229;ta utv&#228;rdering av algoritmer ta tid och att vid systemdesign inte binda sig stenh&#229;rt f&#246;r en enda algoritm vid systemdesign. Det kan h&#228;nda att den algoritm s&#229; s&#229;g bra och s&#228;ker ut vid design, n&#229;gra &#229;r senare visar sig vara svag. Om systemet och det systemet hanterar har l&#228;ngre livsl&#228;ngd &#228;n s&#229; beh&#246;ver man kunna byta ut algoritmerna, att vara flexibel.</p>
 <div class="shr-publisher-1412"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/11/23/tva-observationer-om-aes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XKCD om återanvändning av lösenord</title>
		<link>http://www.strombergson.com/kryptoblog/2010/09/13/xkcd-om-ateranvandning-av-losenord/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/09/13/xkcd-om-ateranvandning-av-losenord/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 19:02:46 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Dumheter]]></category>
		<category><![CDATA[IT och integritet]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Läsvärt]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[lösenord]]></category>
		<category><![CDATA[XKCD]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1404</guid>
		<description><![CDATA[<p><em>(Tack JakobE f&#246;r tipset!)</em><br />
Alltid lika pricks&#228;kra n&#228;tserien <a href="http://xkcd.com/"><span class="caps">XKCD</span></a> har en ny serie som tar upp problematiken runt &#229;teranv&#228;ndning av l&#246;senord:<br />
<img src="http://xkcd.com/792/" alt="XKCD om &#229;teranv&#228;ndning av l&#246;senord." /></p>

	<p>Jag tyckeer ofta jag h&#246;r personer som resonerar&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p><em>(Tack JakobE f&#246;r tipset!)</em><br />
Alltid lika pricks&#228;kra n&#228;tserien <a href="http://xkcd.com/"><span class="caps">XKCD</span></a> har en ny serie som tar upp problematiken runt &#229;teranv&#228;ndning av l&#246;senord:<br />
<img src="http://xkcd.com/792/" alt="XKCD om &#229;teranv&#228;ndning av l&#246;senord." /></p>

	<p>Jag tyckeer ofta jag h&#246;r personer som resonerar att d&#229; n&#228;ttj&#228;nster som Facebook inte &#228;r viktiga/k&#228;nsliga beh&#246;ver man inte bry sig om att skydda sitt konto, exempelvis med att anv&#228;nda olika och bra l&#246;senord f&#246;r varje tj&#228;nst. Dels har dom fel i sak, Facebook inneh&#229;ller f&#246;r m&#229;nga massor med personlig information.</p>

	<p>Men sedan &#228;r det risken med att komma &#229;t andra konton och samla ihop mer information p&#229; ett enkelt s&#228;tt som gravt underskattas. Slutligen &#228;r det ren <em>s&#228;kerhetshygien</em> att inte &#229;teranv&#228;nda l&#246;senord hur som helst. Ungef&#228;r som att alltid anv&#228;nda blinkers n&#228;r man skall sv&#228;nga&#8230;</p>
 <div class="shr-publisher-1404"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/09/13/xkcd-om-ateranvandning-av-losenord/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lite mer om strömkryptot ZUC</title>
		<link>http://www.strombergson.com/kryptoblog/2010/09/06/lite-mer-om-stromkryptot-zuc/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/09/06/lite-mer-om-stromkryptot-zuc/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 18:32:50 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Forskning]]></category>
		<category><![CDATA[Inbyggda system]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[Om Kryptoblog]]></category>
		<category><![CDATA[LTE]]></category>
		<category><![CDATA[LTE Advanced]]></category>
		<category><![CDATA[SAGE]]></category>
		<category><![CDATA[ZUC]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1391</guid>
		<description><![CDATA[<p><a href="http://www.strombergson.com/kryptoblog/2010/09/05/en-titt-pa-nya-lte-kryptot-zuc/">Ig&#229;r bloggade jag om det nya str&#246;mkryptot <span class="caps">ZUC</span> avsett f&#246;r <span class="caps">LTE</span> och <span class="caps">LTE </span>Advanced</a>.  Jag har plockat ut <a href="http://gsmworld.com/documents/EEA3_EIA3_ZUC_v1_4.pdf">referenskoden f&#246;r <span class="caps">ZUC</span> som finns i specifikationen</a> och testat att k&#246;ra str&#246;mkryptot.</p>

	<p>Referenskoden &#228;r inte kanonsnygg&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.strombergson.com/kryptoblog/2010/09/05/en-titt-pa-nya-lte-kryptot-zuc/">Ig&#229;r bloggade jag om det nya str&#246;mkryptot <span class="caps">ZUC</span> avsett f&#246;r <span class="caps">LTE</span> och <span class="caps">LTE </span>Advanced</a>.  Jag har plockat ut <a href="http://gsmworld.com/documents/EEA3_EIA3_ZUC_v1_4.pdf">referenskoden f&#246;r <span class="caps">ZUC</span> som finns i specifikationen</a> och testat att k&#246;ra str&#246;mkryptot.</p>

	<p>Referenskoden &#228;r inte kanonsnygg och r&#228;tt d&#229;ligt dokumenterad. Bland annat st&#228;mmer inte namn med specifikationen, man g&#246;r egen definition av typer d&#228;r man rimligen borde anv&#228;nd stdint.h och det finns inget k&#246;rbart exempel. (I &#228;rlighetens namn &#228;r det dock inte den s&#228;msta referenskoden jag sett f&#246;r ett krypto &#8211; kryptologer verkar i gemen vara r&#228;tt d&#229;ligt insatta i hur man skriver kod.)</p>

	<p>Det var dock inga st&#246;rre problem att f&#229; snurr p&#229; <span class="caps">ZUC</span> och generera lite nyckelstr&#246;mmar. P&#229; min laptop och med referenskoden f&#229;r jag ca 250 Mbit/s n&#228;r jag genererar block om 100 miljoner ord. Inte kanonh&#246;g prestanda, faktiskt n&#229;got f&#246;rv&#229;nande om man j&#228;mf&#246;r med Snow.</p>

	<p>Vad g&#228;ller algoritmen i sig och de naiva analyser jag kan g&#246;ra ser jag egentligen inga nya saker. Jag hittar ingen bias mot n&#229;gra v&#228;rden i Sboxarna, utan dom &#228;r rektangelf&#246;rdelade. Initiering och klockning av interntillst&#229;ndet ser v&#228;ldigt mycket ut som i Snow. D&#228;remot &#228;r det fortfarande oklart varf&#246;r man valt de magiska konstanter och just de Sboxar man gjort. Vidare &#228;r det fr&#229;gan hur mycket det p&#229;verkar att bara ha tv&#229; Sboxar ist&#228;llet f&#246;r fyra som i Snow.</p>

	<p>En h&#229;rdvaruimplementation av <span class="caps">ZUC</span> ser ut att vara ungef&#228;r lika sv&#229;r att g&#246;ra som en implementation av Snow, dvs inte alls speciellt sv&#229;rt och ge en kompakt implementation. Och d&#229; uppdatering av <span class="caps">LFSR</span>-kedjan samt uppslagning av Sboxar g&#229;r att parallellisera borde det g&#229; att f&#229; en rej&#228;l prestanda&#246;kning j&#228;mf&#246;rt med en SW-implementation.</p>

	<p>Slutsatsen jag kan dra &#228;r att specifikationen verkar st&#228;mma med referenskoden och att det g&#229;r att generera nyckelstr&#246;mmar som st&#228;mmer med testvektorerna. Kan man lita p&#229; s&#228;kerheten hos <span class="caps">ZUC</span> ser det ut att vara ett helt ok str&#246;mkrypto. Det finns inga stora m&#228;rkligheter men heller inget speciellt attraktivt och speciellt. Det &#228;r d&#228;rf&#246;r knappast av tekniska sk&#228;l som <span class="caps">ETSI</span>/SAGE, 3GPP och <span class="caps">GSMA</span> standardiserar <span class="caps">ZUC</span>. Speciellt d&#229; man precis standardiserat Snow 3G ger <span class="caps">ZUC</span> knappast n&#229;gon algoritmisk diversitet, d&#229; borde man ist&#228;llet valt <a href="http://www.ecrypt.eu.org/stream/triviumpf.html">Trivium</a>, <a href="http://www.ecrypt.eu.org/stream/grainpf.html">Grain</a> eller <a href="http://www.ecrypt.eu.org/stream/rabbitpf.html">Rabbit</a>, alla tre str&#246;mkrypton fr&#229;n <a href="http://www.ecrypt.eu.org/stream/index.html">eSTREAM-sviten</a> med stora skillnader i struktur och uppbyggnad i j&#228;mf&#246;relse med <span class="caps">ZUC</span> och Snow..</p>

	<p>Nej valet av <span class="caps">ZUC</span> handlar nog enbart om att m&#246;ta kraven f&#246;r access till en marknad och m&#246;jligheten att tj&#228;na stora pengar. F&#246;rhoppningsvis blir vi som konsumenter inte lidande.</p>

 <div class="shr-publisher-1391"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/09/06/lite-mer-om-stromkryptot-zuc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bra blogpost om Strict Transport Security</title>
		<link>http://www.strombergson.com/kryptoblog/2010/08/22/bra-blogpost-om-strict-transport-security/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/08/22/bra-blogpost-om-strict-transport-security/#comments</comments>
		<pubDate>Sun, 22 Aug 2010 19:54:26 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[SSL/TLS]]></category>
		<category><![CDATA[STS]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1355</guid>
		<description><![CDATA[<p><a href="http://www.blogger.com/profile/12586406716617551079">John Wilander</a> p&#229; <a href="http://owaspsweden.blogspot.com/"><span class="caps">OWASP </span>Sweden Blog</a> har skrivet <a href="http://owaspsweden.blogspot.com/2010/08/sakrare-ssl-med-strict-transport.html">en mycket bra postning</a> om <a href="http://tools.ietf.org/html/draft-hodges-strict-transport-sec-02"><span class="caps">HTTP </span>Strict Transport Security</a>, en teknik (just nu en <span class="caps">IETF </span>Internet Draft) f&#246;r att eliminera <em><a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man i mitten-attacker</a></em> i <span class="caps">SSL</span>/TLS. Se&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.blogger.com/profile/12586406716617551079">John Wilander</a> p&#229; <a href="http://owaspsweden.blogspot.com/"><span class="caps">OWASP </span>Sweden Blog</a> har skrivet <a href="http://owaspsweden.blogspot.com/2010/08/sakrare-ssl-med-strict-transport.html">en mycket bra postning</a> om <a href="http://tools.ietf.org/html/draft-hodges-strict-transport-sec-02"><span class="caps">HTTP </span>Strict Transport Security</a>, en teknik (just nu en <span class="caps">IETF </span>Internet Draft) f&#246;r att eliminera <em><a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man i mitten-attacker</a></em> i <span class="caps">SSL</span>/TLS. Se &#228;ven till att l&#228;sa diskussionerna i kommentarerna.</p>
 <div class="shr-publisher-1355"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/08/22/bra-blogpost-om-strict-transport-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SEC-T 2010</title>
		<link>http://www.strombergson.com/kryptoblog/2010/08/12/sec-t-2010/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/08/12/sec-t-2010/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 20:12:25 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Hårdvara]]></category>
		<category><![CDATA[Inbyggda system]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[Tillställningar]]></category>
		<category><![CDATA[konferens]]></category>
		<category><![CDATA[SEC-T]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1353</guid>
		<description><![CDATA[<p><a href="http://www.sec-t.org/">S&#228;kerhetskonferensen <span class="caps">SEC</span>-T</a> anordnas i &#229;r f&#246;r tredje g&#229;ngen och g&#229;r i &#229;r den 9 och 10 September.</p>

	<p><img src="http://www.sec-t.org/assets/templates/2010/images/sec-t_top.png" alt="SEC-T logga" /></p>

	<p>Arrang&#246;rerna har postat agendan f&#246;r konferensen. Tittar jag p&#229; agendan finns det ett par klart sp&#228;nnande presentationer, bland annat <a&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.sec-t.org/">S&#228;kerhetskonferensen <span class="caps">SEC</span>-T</a> anordnas i &#229;r f&#246;r tredje g&#229;ngen och g&#229;r i &#229;r den 9 och 10 September.</p>

	<p><img src="http://www.sec-t.org/assets/templates/2010/images/sec-t_top.png" alt="SEC-T logga" /></p>

	<p>Arrang&#246;rerna har postat agendan f&#246;r konferensen. Tittar jag p&#229; agendan finns det ett par klart sp&#228;nnande presentationer, bland annat <a href="http://www.sec-t.org/2010/Speakers.html#mub">en presentation om svagheter i diskkrypteringsprodukter</a> och <a href="http://www.sec-t.org/2010/Speakers.html#andrei">en presentation om (o)s&#228;kerheten hos skrivare</a>.</p>

	<p>F&#246;r den som vill g&#229; p&#229; &#229;rets <span class="caps">SEC</span>-T <a href="http://www.sec-t.org/2010/Registration.html">&#228;r det h&#246;g tid att anm&#228;la sig</a>.</p>


 <div class="shr-publisher-1353"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/08/12/sec-t-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intressant analys av Wikileaks-data</title>
		<link>http://www.strombergson.com/kryptoblog/2010/08/11/intressant-analys-av-wikileaks-data/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/08/11/intressant-analys-av-wikileaks-data/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 20:25:38 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[övrigt]]></category>
		<category><![CDATA[afghanistan]]></category>
		<category><![CDATA[wikileaks]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1349</guid>
		<description><![CDATA[<p>P&#229; BoingBoing d&#246;k det upp en nyhet om <a href="http://www.boingboing.net/2010/08/09/wikileaks-afghan-war.html">en analys av det data fr&#229;n Afghanistan-kriget Wikileaks publicerat</a>. Genom att plocka ut information om var och n&#228;r strider har skett enligt datat har <a href="http://www.drewconway.com/zia/">Drew Conway</a> skapat en sekvens&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>P&#229; BoingBoing d&#246;k det upp en nyhet om <a href="http://www.boingboing.net/2010/08/09/wikileaks-afghan-war.html">en analys av det data fr&#229;n Afghanistan-kriget Wikileaks publicerat</a>. Genom att plocka ut information om var och n&#228;r strider har skett enligt datat har <a href="http://www.drewconway.com/zia/">Drew Conway</a> skapat en sekvens bilder:</p>

	<p><img src="http://boingboing.net/images/xeni/events_by_label_map-660x476_a808.jpg" alt="Bildsekvens &#246;ver kriget i Afghanistan." /></p>

	<p>R&#228;tt skr&#228;mmande bildsekvens. Jag kan inte tolka det som att kriget &#228;r p&#229; v&#228;g att avslutas. Bilderna har &#228;ven l&#228;tt till <a href="http://www.reddit.com/r/worldnews/comments/cyj26/wikileaks_attack_data_by_year_and_type_projected/">en analys och diskussion av krigets utveckling, ex att Talibanerna ser ut att ha b&#246;rjat f&#246;rs&#246;ka st&#246;ra den ringv&#228;g som tydligen finns i Afghanistan</a>.</p>

	<p>Vad g&#228;ller <a href="http://wikileaks.org/">Wikileaks</a> har tydligen <a href="http://www.thedailybeast.com/blogs-and-stories/2010-08-10/a-western-crackdown-on-wikileaks/">president Obama bett England, Tydlland, Australien m.fl. l&#228;nder att &#229;tala Wikileaks Julian Assange f&#246;r spionage</a> p&#229; grund av publiceringen av Afghanistan-informationen.</p>

	<p>Wikileaks har svarat med att publicera en stor fil kallad Insurance (<a href="http://wikileaks.org/wiki/Afghan_War_Diary,_2004-2010">finns l&#228;ngst ner p&#229; sidan om Afghanistan-kriget</a>). <a href="http://www.schneier.com/blog/archives/2010/08/wikileaks_insur.html">P&#229; Bruce Schneiers blog</a> g&#229;r diskussionerna h&#246;ga om filen verkligen inneh&#229;ller vad den misst&#228;nks inneh&#229;lla, om Wikileaks anv&#228;nder r&#228;tt strategi etc. Klart intressant l&#228;sning iaf.</p>
 <div class="shr-publisher-1349"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/08/11/intressant-analys-av-wikileaks-data/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ny TCP-sekvensgenerator för uIP</title>
		<link>http://www.strombergson.com/kryptoblog/2010/07/17/ny-tcp-sekvensgenerator-for-uip/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/07/17/ny-tcp-sekvensgenerator-for-uip/#comments</comments>
		<pubDate>Sat, 17 Jul 2010 14:35:36 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Forskning]]></category>
		<category><![CDATA[Inbyggda system]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Verktyg]]></category>
		<category><![CDATA[prng]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[uIP]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1339</guid>
		<description><![CDATA[<p>Tillsammans med <a href="http://www.sics.se/~adam/">Adam Dunkels</a> har jag b&#246;rjat titta lite f&#246;rsiktigt p&#229; att hitta en b&#228;ttre generator f&#246;r <span class="caps">TCP</span>-sekvensnummer till den miniskula <a href="http://www.sics.se/~adam/uip/index.php/Main_Page"><span class="caps">TCP</span>/IP-stacken uIP</a>.</p>

	<p><img src="http://www.sics.se/~adam/img/adam13.jpg" alt="Adam Dunkels" /><br />
<em>Adam Dunkels &#8211; pappa till uIP, bland annat.</em></p>

	<p>Den nuvarande generatorn ger&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>Tillsammans med <a href="http://www.sics.se/~adam/">Adam Dunkels</a> har jag b&#246;rjat titta lite f&#246;rsiktigt p&#229; att hitta en b&#228;ttre generator f&#246;r <span class="caps">TCP</span>-sekvensnummer till den miniskula <a href="http://www.sics.se/~adam/uip/index.php/Main_Page"><span class="caps">TCP</span>/IP-stacken uIP</a>.</p>

	<p><img src="http://www.sics.se/~adam/img/adam13.jpg" alt="Adam Dunkels" /><br />
<em>Adam Dunkels &#8211; pappa till uIP, bland annat.</em></p>

	<p>Den nuvarande generatorn ger en monotont &#246;kande sekvens som &#228;r l&#228;tt att prediktera. En ny generator skall ge en bra slumpm&#228;ssig som inte &#228;r l&#228;tt (inte g&#229;r) att prediktera. MEn samtidigt f&#229;r storleken p&#229; stacken inte v&#228;xa speciellt mycket och skall g&#229; att implementera p&#229; en 8-bitars processor. Vidare f&#229;r vi inte inf&#246;r en massa nya krav p&#229; m&#229;lsystemet, exempelvis tillg&#229;ng till bra fysisk entropi. En icke-trivial kombination av krav.</p>

	<p>Jag har t&#228;nkt, kladdat och sedan postat p&#229; Cryptography-listan och f&#229;tt en del tips. Men jag (vi) tar med stor gl&#228;dje emot mer klokskap. H&#228;r kommer d&#228;rf&#246;r min postning till listan. L&#228;s, kommentera. <strong>Tack!</strong> <blockquote><br />
uIP [1] is a very compact <span class="caps">TCP</span>/IP stack for small, networked connected, embedded devices. (The code size for uIP including <span class="caps">TCP</span> and <span class="caps">ICMP</span> on the <span class="caps">AVR</span> processor is about 5 kBytes.)<br />
<br />
</p>

	<p>Unfortunately, the <span class="caps">TCP</span> sequence number generator in uIP is a bit simplistic &#8211; basically a monotonically increasing number. In order to reduce the opportunities for <span class="caps">TCP </span>Spoofing (like this nice one [2]) we are trying to implement a new <span class="caps">TCP</span> sequence number generator.<br />
<br />
</p>

	<p>What we want to find is an algorithm that generates a good (secure) <span class="caps">TCP</span> seq numbers, but use very little resources (on 8-bit computing devices).<br />
<br />
</p>

	<p>We have done some preliminary investigations, have some rough ideas and would really appreciate comments and suggestions from the enlightened minds on this list.<br />
<br />
</p>

	<p>As we see it, the two main problems to solve are:<br />
(1) Find a secure <span class="caps">PRNG</span> algorithm that have as low implementation complexity as possible.<br />
<br />
</p>

	<p>(2) Add as little system/application requirements on entropy source and persistent storage as possible.<br />
<br />
</p>

	<p>Looking at TinyRNG [3] for example, it seems that a block cipher in <span class="caps">CTR</span> mode (or <span class="caps">OFB</span> mode) should be sufficient. The question then is what block cipher to use? The <span class="caps">XTEA</span> block cipher [4] is very compact, but would it be a wise choice from a security perspective?<br />
<br />
</p>

	<p>But what to feed the <span class="caps">PRNG</span> with? Looking again at TinyRNG, it uses a simplistic version of the entropy accumulator from the Fortuna <span class="caps">PRNG </span>[5], but with fewer and smaller pools. The pools are processed using a <span class="caps">CBC</span>-MAC built around the same block cipher as used in the <span class="caps">PRNG</span>.<br />
<br />
</p>

	<p>The combined storage for the pools as well as <span class="caps">CBC</span>-MAC state would probably be acceptable for uIP. The question is if the pool feeding operation as such adds operational requirements on uIP that makes it harder to integrate?<br />
<br />
</p>

	<p>A simpler scheme could be to feed the <span class="caps">PRNG </span>(CTR-mode) with entropy used as part of Key and IV, that is not use a pool mechanism at all and leave it to user application to provide entropy words when performing a reseed. The Key (and IV?) would also consists of a counter that is monotonically increased.<br />
<br />
</p>

	<p>The problem with this (we guess) is that in order to ensure that <span class="caps">KEY</span>+IV is never reused is to keep at least part of <span class="caps">KEY</span> or IV as a counter that is stored in persistent memory and increased once (and stored) every time reseed (or boot) is performed. (How bad from a security perspective would this be? Compared to other <span class="caps">TCP</span> sequence generators?)<br />
<br />
</p>

	<p>The current version of uIP places few (basically no) demands on the system/application regarding physical resources (besides mem for code and data) and does not use any persistent storage besides code memory. It seems that any good sequence generator that are driven by physical entropy and tries to avoid sequence repetition need to place additional demands on the system. No?<br />
<br />
</p>

	<p>This is basically as far as we have taken this. More or less a bit of Googling, reading and attempts at thinking. The ambition is not to invent something new and unproven but to adapt existing tech and ideas that seem to work. But get it to work with the size, performance and <span class="caps">API</span> constraints of uIP.<br />
<br />
</p>

	<p>Any thoughts, comments, suggestions and pointers would be very greatly appreciated.<br />
<br />
</p>

	<p>Thank you!<br />
Joachim Str&#246;mbergson<br />
<br />
</p>


	<p>References<br />
&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<br />
[1] A. Dunkels. uIP <span class="caps">TCP</span>/IP stack.<br />
</p>
 http://www.sics.se/~adam/uip/index.php/Main_Page<br />
<br />


	<p>[1] R. Lawshae. Picking Electronic Locks Using <span class="caps">TCP </span>Sequence Prediction<br />
http://www.defcon.org/images/defcon-17/dc-17-presentation/Ricky_Lawshae/defcon-17-ricky_lawshae-picking_electronic_locks-wp.pdf<br />
<br />
</p>

	<p>[3] A. Francillon, C. Castelluccia. TinyRNG: A Cryptographic Random<br />
</p>
    Number Generator for Wireless Sensors Network Nodes<br />
<br />
http://planete.inrialpes.fr/~ccastel/PAPERS/TinyRNG.pdf<br />
<br />


	<p>[4] R. M. Needham, D. J. Wheeler. Tea extensions.<br />
</p>
    http://www.cix.co.uk/~klockstone/xtea.pdf<br />
<br />


	<p>[5] Wikipedia. Fortuna <span class="caps">PRNG</span>.<br />
</p>
    http://en.wikipedia.org/wiki/Fortuna_%28PRNG%29<br />
</blockquote>
 <div class="shr-publisher-1339"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/07/17/ny-tcp-sekvensgenerator-for-uip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ny version av Internet Draft för RC4</title>
		<link>http://www.strombergson.com/kryptoblog/2010/06/29/ny-version-av-internet-draft-for-rc4/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/06/29/ny-version-av-internet-draft-for-rc4/#comments</comments>
		<pubDate>Tue, 29 Jun 2010 14:59:07 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[Om Kryptoblog]]></category>
		<category><![CDATA[RC4]]></category>
		<category><![CDATA[RC4 Internet Draft]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1335</guid>
		<description><![CDATA[<p>Vi (Jag och Simon Josefsson) har precis sl&#228;ppt <a href="https://datatracker.ietf.org/doc/draft-josefsson-rc4-test-vectors/">version 01</a> av <a href="http://www.strombergson.com/kryptoblog/2010/05/04/ny-internet-draft-test-vectors-for-the-stream-cipher-rc4/">v&#229;r Internet Draft med testvektorer f&#246;r str&#246;mkryptot <span class="caps">RC4</span></a>.</p>

	<p>Den st&#246;rsta f&#246;r&#228;ndringen i draften &#228;r att vi &#228;ndrat en av kryptonycklarna och d&#228;rmed genererat nya vektorer.&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>Vi (Jag och Simon Josefsson) har precis sl&#228;ppt <a href="https://datatracker.ietf.org/doc/draft-josefsson-rc4-test-vectors/">version 01</a> av <a href="http://www.strombergson.com/kryptoblog/2010/05/04/ny-internet-draft-test-vectors-for-the-stream-cipher-rc4/">v&#229;r Internet Draft med testvektorer f&#246;r str&#246;mkryptot <span class="caps">RC4</span></a>.</p>

	<p>Den st&#246;rsta f&#246;r&#228;ndringen i draften &#228;r att vi &#228;ndrat en av kryptonycklarna och d&#228;rmed genererat nya vektorer. Draften inneh&#229;ller tv&#229; olika slags nycklar med tillh&#246;rande testvektorer f&#246;r olika nyckell&#228;ngder. En av dessa nycklar &#228;r genererad genom att k&#246;ra str&#228;ngen Internet Engineering Task Force genom <a href="http://en.wikipedia.org/wiki/SHA-2">hashfunktionen <span class="caps">SHA</span>-256</a>. Tyv&#228;rr inkluderade den gamla str&#228;ngen radbrytning vilket inte syns i str&#228;ngen. Detta &#228;r nu &#228;ndrat.</p>

	<p>Andra &#228;ndringar &#228;r att vi nu &#228;ven har med testvektorer runt nyckelstr&#246;mspunkten 4096 Bytes. Vidare har vi f&#246;rtydligat en del referenser och s&#228;kerhetsrekommendationer f&#246;r <span class="caps">RC4</span>. Rent krasst skriver vi att: <blockquote>The <span class="caps">RC4</span> algorithm does not meet the basic criteria required for an encryption algorithm, as its output is distinguishable from random. The use of <span class="caps">RC4</span> continue to be recommended against; in particular, its use in new specifications is discouraged.  This note is intended only to aid the interoperability of existing specifications that make use of <span class="caps">RC4</span>.<br />
</blockquote></p>

	<p>Vi tar g&#228;rna emot kommentarer och synpunkter p&#229; draften.</p>
 <div class="shr-publisher-1335"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/06/29/ny-version-av-internet-draft-for-rc4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hälsoläget för AES</title>
		<link>http://www.strombergson.com/kryptoblog/2010/06/01/halsolaget-for-aes/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/06/01/halsolaget-for-aes/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 19:46:43 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Forskning]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[AES]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1230</guid>
		<description><![CDATA[<p>P&#229; <a href="http://crypto.rd.francetelecom.com/events/eurocrypt2010/">Eurocrypt 2010</a> idag tisdag 2010-06-01 presenterade Ali Biham, Orr Dunkelman m.fl. en uppdaterade attack av sin attack p&#229; <span class="caps">AES</span>: <em><a href="http://eprint.iacr.org/2009/374">Key Recovery Attacks of Practical Complexity on <span class="caps">AES</span>-256 Variants with up to 10 Rounds</a></em>.</p>

	<p><a href="http://crypto.rd.francetelecom.com/events/eurocrypt2010/"><img src="http://crypto.rd.francetelecom.com/events/eurocrypt2010/img/banner-4.png" alt="Eurocrypt 2010" /></a></p>

	<p>Detta&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>P&#229; <a href="http://crypto.rd.francetelecom.com/events/eurocrypt2010/">Eurocrypt 2010</a> idag tisdag 2010-06-01 presenterade Ali Biham, Orr Dunkelman m.fl. en uppdaterade attack av sin attack p&#229; <span class="caps">AES</span>: <em><a href="http://eprint.iacr.org/2009/374">Key Recovery Attacks of Practical Complexity on <span class="caps">AES</span>-256 Variants with up to 10 Rounds</a></em>.</p>

	<p><a href="http://crypto.rd.francetelecom.com/events/eurocrypt2010/"><img src="http://crypto.rd.francetelecom.com/events/eurocrypt2010/img/banner-4.png" alt="Eurocrypt 2010" /></a></p>

	<p>Detta &#228;r den f&#246;rsta stora attacken (som dock snarare &#228;r en uppdatering p&#229; en attack fr&#229;n f&#246;rra &#229;ret) i &#229;r. Men sett &#246;ver de senaste dryga &#229;ret har vi sett fem, sex st&#246;rre attacker p&#229; <span class="caps">AES</span> som algoritm, samt ett antal mindre attacker d&#228;r olika delar av algoritmen analyseras. Och sedan, naturligtvis ett antal attacker p&#229; implementationer, inte minst attacker basererade p&#229; felinjektering och sidoattacker. <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard">Wikipedias sida om <span class="caps">AES</span></a> listar n&#229;gra av dessa attacker, men l&#229;ngt ifr&#229;n alla. Bruce Schneier bloggade om dessa attacker ett par g&#229;nger i mitten p&#229; f&#246;rra &#229;ret (<a href="http://www.schneier.com/blog/archives/2009/07/new_attack_on_a.html">ett</a>, <a href="http://www.schneier.com/blog/archives/2009/07/another_new_aes.html">tv&#229;</a>). En av de fr&#228;msta p&#229; att attacker <span class="caps">AES </span>&#228;r <a href="http://www.wisdom.weizmann.ac.il/~orrd/">Orr Dunkelmans</a>.</p>

	<p><img src="http://www.wisdom.weizmann.ac.il/~orrd/pictures/face.jpg" alt="Orr Dunkelman" /><br />
<em>Orr Dunkelman</em></p>

	<p>Kolla man p&#229; <a href="http://www.wisdom.weizmann.ac.il/~orrd/crypt/">Orr Dunkelmans forskningssida</a> hittar man ett flertal artiklar med olika analyser av <span class="caps">AES</span> och attacker. Den h&#228;r om vad som h&#228;nder om <a href="http://eprint.iacr.org/2010/041.pdf">MixColumns-operationen i <span class="caps">AES</span> inte fungerar i den sista iterationen</a> &#228;r ett typiskt exempel p&#229; den typ av analys jag tycker att man ser ofta just nu (en trend inom kryptanalys).</p>

	<p>Vad jag f&#246;rs&#246;ker s&#228;ga &#228;r att jag upplever det som att <span class="caps">AES</span>, efter snart tio &#229;r sedan (AES publicerades i november 2001 s&#229; det snarare &#229;tta &#229;r, men&#8230;) utan st&#246;rre s&#228;kerhetsproblem med algoritmen nu pl&#246;tsligt b&#246;rjar se lite skadeskjuten ut &#8211; att den kanske inte &#228;r s&#229; s&#228;ker l&#228;ngre. Det &#228;r inte dags f&#246;r panik, men l&#229;ngsiktigt och f&#246;r nya applikationer b&#246;r man nog t&#228;nka p&#229; att inte l&#229;sa fast sig i <span class="caps">AES</span>, utan g&#246;ra det m&#246;jligt att byta algoritm.</p>

	<p>Till saken h&#246;r att <span class="caps">AES</span> har varit en formidabel succ&#233; och har designats in i alltifr&#229;n kommunikation f&#246;r sm&#229; sensorsystem (IEEE 802.15.4 &#8211; ZigBee) till 10G Ethernet och en oherrans massa saker d&#228;romkring. Skulle <span class="caps">AES</span> falla och m&#229;ste bytas ut kommer det inte att bli enkelt.</p>

	<p>Det skall bli sp&#228;nnande att se hur det g&#229;r.</p>
 <div class="shr-publisher-1230"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/06/01/halsolaget-for-aes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>En liten titt på Evernote</title>
		<link>http://www.strombergson.com/kryptoblog/2010/06/01/en-liten-titt-pa-evernote/</link>
		<comments>http://www.strombergson.com/kryptoblog/2010/06/01/en-liten-titt-pa-evernote/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 19:12:50 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[IT och integritet]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Verktyg]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[molnet]]></category>

		<guid isPermaLink="false">http://www.strombergson.com/kryptoblog/?p=1298</guid>
		<description><![CDATA[<p><a href="http://www.evernote.com/">Evernote</a> &#228;r en v&#228;ldigt nifty och snygg molntj&#228;nst f&#246;r att hantera anteckningar.</p>

	<p><a href="http://www.evernote.com/"><img src="http://www.evernote.com/about/media/img/logo.png" alt="Evernote logo" /></a></p>

	<p>Med inbyggt st&#246;d f&#246;r att identifiera text i bilder, snygga till figurer, kopplingar till andra tj&#228;nster &#228;r det mycket jag gillar med Evernote. Och att d&#246;ma&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.evernote.com/">Evernote</a> &#228;r en v&#228;ldigt nifty och snygg molntj&#228;nst f&#246;r att hantera anteckningar.</p>

	<p><a href="http://www.evernote.com/"><img src="http://www.evernote.com/about/media/img/logo.png" alt="Evernote logo" /></a></p>

	<p>Med inbyggt st&#246;d f&#246;r att identifiera text i bilder, snygga till figurer, kopplingar till andra tj&#228;nster &#228;r det mycket jag gillar med Evernote. Och att d&#246;ma av kommentarer fr&#229;n de som anv&#228;nder Evernote verkar jag inte vara den enda och att tj&#228;nsten faktiskt fungerar. Eftersom det &#228;r en molntj&#228;nst g&#229;r det dessutom att komma &#229;t alla sin insamlade information via klienter p&#229; mobil, dator, webbl&#228;sare etc.</p>

	<p><img src="http://reallynattu.com/blog/wp-content/uploads/2009/08/evernote_iphone.png" alt="Evernote p&#229; iPhone." /></p>

	<p>Tyv&#228;rr m&#229;ste jag dock, f&#246;r att citera <a href="http://www.tonyirving.se/">Tony Irving</a> s&#228;ga: <strong>Men&#8230;.</strong>Kolla in anv&#228;ndarvillkoren (<a href="http://www.evernote.com/about/tos/">Terms of Service</a>) f&#246;r Evernote:<br />
<blockquote><br />
by using the Service and posting Content, you grant Evernote a license to display, perform and distribute your Content, and to modify and reproduce such Content to enable Evernote to operate and promote the Service. (You also agree that Evernote has the right to elect not to accept, post, store, display, publish or transmit any Content in our sole discretion.)<br />
<br />
</p>

	<p>You agree that these rights and licenses are royalty free, irrevocable and worldwide, and include a right for Evernote to make such Content available to, and pass these rights along to, others with whom Evernote has contractual relationships related to the provision of the Evernote Service, solely for the purpose of providing such services, and to otherwise permit access to your Content to third parties if Evernote determines such access is necessary to comply with its legal obligations.<br />
</blockquote></p>

	<p>J&#246;sses, man blir lite tveksam till att anv&#228;nda Evernote &#8211; &#228;ven om det som sagt &#228;r en v&#228;ldigt nifty tj&#228;nst.</p>
 <div class="shr-publisher-1298"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2010/06/01/en-liten-titt-pa-evernote/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

