<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kryptoblog &#187; NIST</title>
	<atom:link href="http://www.strombergson.com/kryptoblog/tag/nist/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.strombergson.com/kryptoblog</link>
	<description>Kryptografi och IT-säkerhet på svenska</description>
	<lastBuildDate>Thu, 20 Jan 2011 21:25:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Intressanta kommentarer på NISTs AES-XTS</title>
		<link>http://www.strombergson.com/kryptoblog/2008/09/13/intressanta-kommentarer-pa-nists-aes-xts/</link>
		<comments>http://www.strombergson.com/kryptoblog/2008/09/13/intressanta-kommentarer-pa-nists-aes-xts/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 11:44:57 +0000</pubDate>
		<dc:creator>Joachim Strömbergson</dc:creator>
				<category><![CDATA[Krypto]]></category>
		<category><![CDATA[NIST AHS]]></category>
		<category><![CDATA[NIST]]></category>

		<guid isPermaLink="false">http://strombergson.com/kryptoblog/?p=560</guid>
		<description><![CDATA[<p><a href="http://www.nist.gov/"><span class="caps">NIST</span></a> har <a href="http://csrc.nist.gov/groups/ST/toolkit/BCM/comments.html">publicerat de kommentarer som inkommit p&#229; f&#246;rslaget att standardisera kryptomoden <span class="caps">XTS</span> f&#246;r <span class="caps">AES</span></a>.</p>

	<p><span class="caps">XTS </span>&#228;r en variant av <a href="http://en.wikipedia.org/wiki/Disk_encryption_theory#XEX">kryptomoden <span class="caps">XEX</span></a> skapad av Phillip Rogaway. <span class="caps">XTS</span> har tidigare standardiserats av <span class="caps">IEEE</span>&#8230;</p>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.nist.gov/"><span class="caps">NIST</span></a> har <a href="http://csrc.nist.gov/groups/ST/toolkit/BCM/comments.html">publicerat de kommentarer som inkommit p&#229; f&#246;rslaget att standardisera kryptomoden <span class="caps">XTS</span> f&#246;r <span class="caps">AES</span></a>.</p>

	<p><span class="caps">XTS </span>&#228;r en variant av <a href="http://en.wikipedia.org/wiki/Disk_encryption_theory#XEX">kryptomoden <span class="caps">XEX</span></a> skapad av Phillip Rogaway. <span class="caps">XTS</span> har tidigare standardiserats av <span class="caps">IEEE</span> i <span class="caps">P1619</span> f&#246;r att skydda i blockorienterad lagringsmedia (exempelvis h&#229;rddiskar och <span class="caps">FLASH</span>-minnnen).</p>

	<p>Matthew Ball, som &#228;r ordf&#246;rande i <span class="caps">IEE</span>Es Storage Working Group &#228;r <a href="http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/comments/XTS/XTS_comments-Ball.pdf">i sin kommentar</a>, inte helt &#246;verraskande, positiv till <span class="caps">NIS</span>Ts <span class="caps">XTS</span>-f&#246;rslag. Matthew p&#229;pekar att <span class="caps">XTS</span>, till skillnad fr&#229;n exempelvis <span class="caps">CBC </span>&#228;r en algoritm som g&#229;r att parallellisera och d&#228;rmed skalar bra prestandam&#228;ssigt.</p>

	<p>Mer intressant &#228;r att <a href="http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/comments/XTS/XTS_comments-Seagate.pdf">kommentarerna fr&#229;n h&#229;rddisk-tillverkaren Seagate</a> &#228;r s&#229; negativa. Seagate ser inga f&#246;rdelar med <span class="caps">XTS</span>, och tycker att den implementationsm&#228;ssigt &#228;r f&#246;r kostsam. Seagate skriver bland annat:</p>

	<p><blockquote><br />
The <span class="caps">XTS</span> encryption mode is not a good choice for storage encryption. There have been simpler, faster or more secure modes in use.</p>

	<p>Is <span class="caps">XTS</span> a good tradeoff between security and complexity (costs)? NO: There are asymmetric large block encryption modes (e.g. BitLocker of Windows Vista) with similar complexity but better security for storage systems. There are faster, simpler encryption modes used together with access control (e.g. <span class="caps">CBC</span>)<br />
</blockquote></p>

	<p><em>Notera att Seagate inte ser ett problem med <span class="caps">CBC</span> vad g&#228;ller prestanda.</em></p>

	<p><a href="http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/comments/XTS/collected_XTS_comments.pdf">&#196;ven &#246;vriga kommentarer</a> &#228;r p&#229; olika s&#228;tt negativa till <span class="caps">XTS</span>. Inte minst &#228;r det intressant att notera att Phillip Rogaway inte ser att <span class="caps">XTS</span> s&#228;kerhetsmekanismer inte tillf&#246;r n&#229;gon egentlig s&#228;kerhet.</p>

	<p>Ett annat problem, som alla utom Matthew Ball fr&#229;n <span class="caps">IEEE</span> p&#229;pekar, &#228;r att <span class="caps">IEEE </span>&#228;ger standarden och att den som vill l&#228;sa standarden d&#228;rf&#246;r m&#229;ste k&#246;pa standarden fr&#229;n <span class="caps">IEEE</span>. Som Niels Ferguson och Vijay Bharadwaj fr&#229;n Microsoft skriver i sin kommentar:</p>

	<p><blockquote><br />
The proposal for the approved specification to be available only by purchase from <span class="caps">IEEE </span>. We believe that it is highly undesirable to standardize an algorithm whose specification, unlike those of other <span class="caps">FIPS</span> approved algorithms, is not freely available.<br />
</blockquote></p>

	<p>Ytterligare ett potentiellt problem med <span class="caps">XTS </span>&#228;r att det finns IP-r&#228;ttigheter kopplade till standarden. Niels Ferguson och Vijay Bharadwaj &#229;terigen:</p>

	<p><blockquote><br />
As stated in the call for comments, the current situation of IP rights with respect to <span class="caps">XTS</span>-AES is unclear. We believe that standardizing an algorithm which is so encumbered is undesirable, and that IP issues could inhibit adoption of such a standard.<br />
</blockquote></p>

	<p>Det &#228;r lite illavarslande att flera duktiga krytopexperter inte ser att <span class="caps">XTS</span> mekanismer, med bland annat tv&#229; olika kryptonycklar tillf&#246;r n&#229;gon egentlig s&#228;kerhet och att det &#228;r oklart vad <span class="caps">XTS</span> egentligen &#228;r t&#228;nkt att l&#246;sa f&#246;r ett s&#228;kerhetsproblem.</p>

	<p>Men det som g&#246;r mig &#228;n mer orolig f&#246;r framtiden &#228;r fr&#229;gan om standardens &#246;ppenhet samt IP-problematiken, inte minst i ljuset av den p&#229;g&#229;ende <span class="caps">AHS</span>-t&#228;vlingen. Finns det en risk att framtidens <span class="caps">SHA</span>-algoritm inte kommer att vara &#246;ppen, och att implementationer kommer att begr&#228;nsas av IP-r&#228;ttigheter? Det skulle inte vara bra f&#246;r s&#228;kerheten.</p>

 <div class="shr-publisher-560"></div>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.strombergson.com/kryptoblog/2008/09/13/intressanta-kommentarer-pa-nists-aes-xts/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

