<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kryptoblog &#187; estream</title>
	<atom:link href="http://www.strombergson.com/kryptoblog/tag/estream/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.strombergson.com/kryptoblog</link>
	<description>Kryptografi och IT-säkerhet på svenska</description>
	<lastBuildDate>Thu, 20 Jan 2011 21:25:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Uppdaterad eSTREAM-portfölj och nya attacker</title>
		<link>http://www.strombergson.com/kryptoblog/2008/11/17/uppdaterad-estream-portfolj-och-nya-attacker/</link>
		<comments>http://www.strombergson.com/kryptoblog/2008/11/17/uppdaterad-estream-portfolj-och-nya-attacker/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 21:05:27 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[ECRYPT eSTREAM]]></category>
		<category><![CDATA[Forskning]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[estream]]></category>

		<guid isPermaLink="false">http://strombergson.com/kryptoblog/?p=585</guid>
		<description><![CDATA[<p>eSTREAM-projektet <a href="http://strombergson.com/kryptoblog/2008/04/19/och-estream-vinnarna-ar/">presenterade sin portf&#246;lj med str&#246;mkrypton i april i &#229;r</a>. Portf&#246;ljen som d&#229; presenterades inkluderade fyra krypton i profil ett avsedda i f&#246;rsta hand f&#246;r SW-implementation och fyra krypton i profil tv&#229; avsedda f&#246;r inbyggda system och h&#229;rdvaruimplementationer.&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>eSTREAM-projektet <a href="http://strombergson.com/kryptoblog/2008/04/19/och-estream-vinnarna-ar/">presenterade sin portf&#246;lj med str&#246;mkrypton i april i &#229;r</a>. Portf&#246;ljen som d&#229; presenterades inkluderade fyra krypton i profil ett avsedda i f&#246;rsta hand f&#246;r SW-implementation och fyra krypton i profil tv&#229; avsedda f&#246;r inbyggda system och h&#229;rdvaruimplementationer. Dessa krypton var:</p>

	<p><strong>Profil ett:</strong><br />
<ul></p>
	<p><li>HC-128</li><br />
<li>Rabbit</li><br />
<li>Salsa 20/12</li><br />
<li>Sosemanuk</li><br />
</ul></p>

	<p><strong>Profil tv&#229;:</strong><br />
<ul></p>
	<p><li>F-FCSR-H v2</li><br />
<li>Grain v1</li><br />
<li>Mickey v2</li><br />
<li>Trivium</li><br />
</ul></p>

	<p>Sedan april har det h&#228;nt en del. Det mest direkta &#228;r att <a href="http://www.ecrypt.eu.org/stream/portfolio_revision1.pdf">eSTREAM-portf&#246;ljen har uppdaterats</a> med den stora f&#246;r&#228;ndringen att F-FCSR-H plockats bort fr&#229;n profil tv&#229;.</p>

	<p>Sk&#228;let till detta &#228;r att Hell och Johansson skrivit en artikel kallad <em>Breaking the F-FCSR-H stream cipher</em> som tydligen visar en praktiskt genomf&#246;rbar artikel mot F-FCSR-H. Artikeln <a href="http://www.ics.mq.edu.au/conferences/asiacrypt2008/program.html">skall presenteras p&#229; Asiacrypt i december</a>, men tydligen st&#228;mmer resultatet d&#229; eSTREAM valt att plocka bort F-FCSR-H.</p>

	<p>N&#229;gra andra eSTREAM-krypton som inte ser ut att m&#229; speciellt bra &#228;r Trivium och Salsa 20, speciellt Trivium ser ut att m&#229; d&#229;ligt.</p>

	<p>I h&#246;stas kom <a href="http://strombergson.com/kryptoblog/2008/09/15/kubattacker-mot-kryptografiska-funktioner/">Adi Shamirs kubattack</a> som i artikeln inneh&#229;ller en allvarlig attack mot Trivium. Under h&#246;sten har &#228;ven kommit ett par andra attacker mot Trivium.</p>

	<p>I oktober kom artikeln <em><a href="http://eprint.iacr.org/2008/443">Transforming chosen IV attack into a key differential attack: how to break <span class="caps">TRIVIUM</span> and similar designs</a></em> med en komplexitet p&#229; 2**68.</p>

	<p>En annan artikel, <em><a href="http://eprint.iacr.org/2008/405">Slid Pairs in Salsa20 and Trivium</a></em>, som attackerar b&#229;de Trivium och Salsa 20 kom i slutet av september. F&#246;rfattarna Deike Priemuth-Schmid och Alex Biryukov skriver:</p>

	<p><blockquote><br />
The stream ciphers Salsa20 and Trivium are two of the finalists of the eSTREAM project which are in the final portfolio of new promising stream ciphers. In this paper we show that initialization and key-stream generation of these ciphers is <em>slidable</em>, i.e. one can find distinct (Key, IV) pairs that produce identical (or closely related) key-streams.</p>

	<p>There are 2**256 and more then 2**39 such pairs in Salsa20 and Trivium respectively. We write out and solve the non-linear equations which describe such related (Key, IV) pairs. This allows us to sample the space of such related pairs efficiently as well as detect such pairs in large portions of key-stream very efficiently.</p>

	<p>We show that Salsa20 does not have 256-bit security if one considers general birthday and related key distinguishing and key-recovery attacks<br />
</blockquote></p>

	<p>Det ser allvarligt ut, men <a href="http://cr.yp.to/snuffle/reslid-20080925.pdf">l&#228;ser man Daniel J Bernsteins svar</a> verkar det inte vara en attack som &#228;r b&#228;ttre &#228;n brute force:</p>

	<p><blockquote><br />
These claims are entirely without merit. The &#8220;attacks&#8221; on Salsa20 are vastly more expensive than the standard brute-force attacks discussed in the original Salsa20 documentation.<br />
</blockquote></p>

	<p>Vad g&#228;ller Trivium, med tre olika attacker p&#229; kort tid, skulle jag inte bli f&#246;rv&#229;nad om den &#229;ker ut ur eSTREAM-portf&#246;ljen och jag skulle vara f&#246;rsiktg att anv&#228;nda den.</p>

	<p>Det som g&#246;r mig en aning bekymrad &#228;r att flera attacker allts&#229; dykt upp strax efter att eSTREAM-projektet avslutats och porf&#246;ljen presenterats &#8211; efter fyra &#229;r av utv&#228;rderingar.</p>

	<p>Om man vore lite konspiratoriskt lagd skulle man kunna f&#229; f&#246;r sig att det &#228;r mer prestige och publiceringsv&#228;rde i att attackera accepterade och utvalda algoritmer snarare &#228;n kandidater. Detta &#228;r naturligtvis rent trams, men om det skulle vara s&#229; vore det bekymmersamt f&#246;r forskningen och andra f&#246;rs&#246;k att ta fram bra algoritmer &#8211; exempelvis f&#246;r <span class="caps">NIS</span>Ts <span class="caps">SHA</span>-3-t&#228;vling.</p>

	<p>En sista sak om eSTREAM v&#228;rd att notera &#228;r att kryptot Rabbit, enligt <a href="http://www.ecrypt.eu.org/stream/phorum/read.php?1,1244">en postning av Erik Zenner p&#229; eSTREAM-forumet</a>, har f&#229;tt &#228;ndrad licens:</p>

	<p><blockquote><br />
On behalf of Cryptico A/S, the company who designed the Rabbit stream cipher, I&#8217;m happy to relay the following:</p>

	<p>&#8220;Rabbit has been released into the public domain and may be used freely for<br />
any purpose.&#8221;</p>

	<p>So in retrospect, I think that it was a good decision not to make patent issues a key criterion for the eStream portfolio: The patent status can change, the algorithmic properties can&#8217;t.<br />
</blockquote></p>

	<p>Tyv&#228;rr &#228;r inte detta det mest officiella av uttalanden, och dessutom saknar jag information om hur Cryptico avser att agera vad g&#228;ller sina patent relaterade till Rabbit. Jag har letat p&#229; <a href="http://www.cryptico.com/">Cryptico A/S</a> webbplats f&#246;r att hitta ett mer officiellt uttalande, men d&#228;r finns inte mycket nyheter.</p>

	<p>Jag har kontaktat Erik Zenner f&#246;r att se om det g&#229;r att f&#229; ett mer officiellt uttalande. H&#246;r jag n&#229;got publicerar jag det h&#228;r. <a href="http://www.ecrypt.eu.org/stream/phase3ip.html#rabbit">eSTREAM-projektets text om licensen f&#246;r Rabbit</a> har i alla fall inte uppdaterats:</p>

	<p><blockquote><br />
Cryptico A/S currently has patents pending on Rabbit. The algorithm is provided royalty-free for non-commectical use. Licenses for commercial use may be obtained from Cryptico A/S.<br />
</blockquote></p>

	<p>Om jag sj&#228;lv skall v&#228;lja krypton fr&#229;n eSTREAM skulle jag i f&#246;rsta hand g&#229; p&#229; HC-128 och <strong>kanske</strong> Salsa 20. I profil tv&#229; skulle jag v&#228;lja Grain och Mickey, men d&#229; anv&#228;nda versionerna med 128 bit nycklar som inte kostar mer i implementation (bortsett fr&#229;n sex Bytes l&#228;ngre nyckel). Inbyggda system f&#246;rtj&#228;nar lika bra skydd som <em>PC-system</em>.</p>
 <div class="shr-publisher-585"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2008/11/17/uppdaterad-estream-portfolj-och-nya-attacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kubattacker mot kryptografiska funktioner</title>
		<link>http://www.strombergson.com/kryptoblog/2008/09/15/kubattacker-mot-kryptografiska-funktioner/</link>
		<comments>http://www.strombergson.com/kryptoblog/2008/09/15/kubattacker-mot-kryptografiska-funktioner/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 20:27:00 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[ECRYPT eSTREAM]]></category>
		<category><![CDATA[Forskning]]></category>
		<category><![CDATA[Krypto]]></category>
		<category><![CDATA[estream]]></category>

		<guid isPermaLink="false">http://strombergson.com/kryptoblog/?p=561</guid>
		<description><![CDATA[<p>En av de mest uppm&#228;rksammade h&#228;ndelserna p&#229; den f&#246;r ungef&#228;r en m&#229;nad sedan avslutade Crypto-konferensen var en presentation av <a href="http://en.wikipedia.org/wiki/Adi_Shamir">Adi Shamir</a> om en ny typ av attackmetod mot kryptografiska metoder kallad <em>kubattack</em>.</p>

	<p><img src="http://blogs.zdnet.com/images/shamir.jpg" alt="Adi Shamir" /><br />
<em>Adi Shamir</em></p>

	<p>N&#228;r metoden presenterades&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p>En av de mest uppm&#228;rksammade h&#228;ndelserna p&#229; den f&#246;r ungef&#228;r en m&#229;nad sedan avslutade Crypto-konferensen var en presentation av <a href="http://en.wikipedia.org/wiki/Adi_Shamir">Adi Shamir</a> om en ny typ av attackmetod mot kryptografiska metoder kallad <em>kubattack</em>.</p>

	<p><img src="http://blogs.zdnet.com/images/shamir.jpg" alt="Adi Shamir" /><br />
<em>Adi Shamir</em></p>

	<p>N&#228;r metoden presenterades fanns inget om den nya metoden publicerat. Detta ledde till en hel del diskussioner och spekulationer p&#229; maillistor. Exempelvis diskuterades det mycket om <a href="http://www.schneier.com/blog/archives/2008/08/adi_shamirs_cub.html">krypton som <span class="caps">AES</span>, Twofish &#228;r s&#229;rbara</a>.</p>

	<p>David Wagner skrev ett par l&#228;ngre inl&#228;gg p&#229; Cryptography-listan (<a href="http://www.mail-archive.com/cryptography@metzdowd.com/msg09686.html">inl&#228;gg ett</a>, <a href="http://www.mail-archive.com/cryptography@metzdowd.com/msg09685.html">inl&#228;gg tv&#229;</a>). David skrev bland annat:</p>

	<p><blockquote><br />
Basically the method focuses on terms of the polynomial in which only one secret bit of the key appears, and many of the non-secret bits. Using chosen (or lucky) plaintexts, vary all but one of the non-secret bits, and sum the output bits (mod 2, that is, <span class="caps">XOR</span>).</p>

	<p>Fix the other non-secret bit to 1. Now all the terms that involve less than the full complement of non-secret bits will appear an even number of times in the sum, and because it is mod 2, they will all cancel out! The only terms that will be left are the ones with one secret bit, and all ones for the non-secret bits&#8230; but that is linear in the secret bit! So what you are left with is a simple, linear, polynomial relating unknown (key) bits.<br />
</blockquote></p>

	<p>Nu har artikeln <em><a href="http://eprint.iacr.org/2008/385.pdf">Cube Attacks on Tweakable Black Box Polynomials</a></em> av Itai Dinur and Adi Shamir publicerats p&#229; <span class="caps">IACR</span>. F&#246;rfattarna skriver i artikelns (l&#229;nga) sammanfattning:</p>

	<p><blockquote><br />
Almost any cryptographic scheme can be described by tweakable polynomials over <span class="caps">GF </span>(2), which contain both secret variables (e.g., key bits) and public variables (e.g., plaintext bits or IV bits). The cryptanalyst is allowed to tweak the polynomials by choosing arbitrary values for the public variables, and his goal is to solve the resultant system of polynomial equations in terms of their common secret variables.</p>

	<p>In this paper we develop a new technique (called a cube attack) for solving such tweakable polynomials, which is a major improvement over several previously published attacks of the same type.</p>

	<p>For example, on the stream cipher Trivium with a reduced number of initialization rounds, the best previous attack (due to Fischer, Khazaei, and Meier) requires a barely practical complexity of 2**55 to attack 672 initialization rounds, whereas a cube attack can ﬁnd the complete key of the same variant in 2**19 bit operations (which take less than a second on a single PC). Trivium with 735 initialization rounds (which could not be attacked by any previous technique) can now be broken with 2**30 bit operations, and by extrapolating our experimentally veriﬁed complexities for various sizes, we have reasons to believe that cube attacks will remain faster than exhaustive search even for 1024 initialization rounds.</p>

	<p>Whereas previous attacks were heuristic, had to be adapted to each cryptosystem, had no general complexity bounds, and were not expected to succeed on random looking polynomials, cube attacks are provably successful when applied to random polynomials of degree d over n secret variables whenever the number m of public variables exceeds d + logd n. Their complexity is 2d&#8722;1 n + n2 bit operations,<br />
which is polynomial in n and amazingly low when d is small.</p>

	<p>Cube attacks can be applied to any block cipher, stream cipher, or <span class="caps">MAC</span> which is provided as a black box (even when nothing is known about its internal structure) as long as at least one output bit can be represented by (an unknown) polynomial of relatively low degree in the secret and public variables. In particular, they can be easily and automatically combined with any type of side channel attack that leaks some partial information about the early stages of the encryption process (which can typically be<br />
represented by a very low degree polynomial), such as the Hamming weight of a byte written into a register.<br />
</blockquote></p>

	<p>Publiceringen av artikeln har skapat nya diskussioner, exempelvis <a href="http://www.schneier.com/blog/archives/2008/09/adi_shamirs_cub_1.html#comments">p&#229; Bruce Schneiers blog</a>.</p>

	<p>Min uppfattning om Adi Shamir &#228;r att han &#228;r en av v&#228;rldens absolut b&#228;sta kryptologer, risken att han skulle missat fullst&#228;ndigt och metoden inte alls fungerar tror jag &#228;r liten.  Men jag kan villigt erk&#228;nna att jag kan f&#246;r lite krypanalys f&#246;r att g&#246;ra en vettig bed&#246;mning av den nya metoden.</p>

	<p>Om det Itai Dinur och Adi Shamir skriver st&#228;mmer borde detta vara ett stort steg fram&#229;t f&#246;r kryptanalysen. Och lackmustestet kommer antagligen att vara om det dyker upp en ny v&#229;g av attacker mot olika specifika funktioner s&#229; fungerar kubattacken.</p>

	<p>Att <a href="http://www.ecrypt.eu.org/stream/triviumpf.html">Trivium</a>, en av de nyligen utsedda algoritmerna i eSTREAM-portf&#246;ljen (och lite av en personlig favorit) skulle f&#229; problem s&#229; h&#228;r n&#228;ra efter avslutningen av eSTREAM visar hur en ny metod pl&#246;tsligt kan kullkasta flera &#229;r av analysarbete.</p>

	<p>Vi kommer med stor sannolikhet att f&#229; &#229;terkomma till den h&#228;r nya attackmetoden. Inte minst under <span class="caps">AHS</span>-t&#228;vlingen kommer kubattacken antagligen att uppm&#228;rksammas.</p>



 <div class="shr-publisher-561"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2008/09/15/kubattacker-mot-kryptografiska-funktioner/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

