Re: SHA1 broken

From: Paul Rubin (//phr.cx_at_NOSPAM.invalid)
Date: 02/16/05


Date: 16 Feb 2005 09:00:02 -0800

daw@taverner.cs.berkeley.edu (David Wagner) writes:
> >Does that wide-trail stuff provide any results about distinguishing
> >attacks as opposed to actual message recovery?
>
> No. It only provides results about security against differential and
> linear cryptanalysis. Basically, it just involves counting the number
> of active S-boxes in any simple differential characteristic (for instance).

Well, clearly I didn't expect it to say anything about unknown
attacks, but when a wide-trail calculation says "6 rounds makes this
cipher secure against differential cryptanalysis", I'm wondering if
that means it takes more work than brute force to recover actual
plaintext by differential cryptanalysis, or whether it can mean it
takes more work than brute force to merely distinguish the permutation
from a random one.



Relevant Pages

  • Re: Good books?
    ... > knowing whether a given cryptosystem is patently ... it is known that certain very specific attacks don't work. ... which might not require cryptanalysis ... exploitations, and are guarded against by careful coding ...
    (sci.crypt)
  • Re: New cryptanalysis book coming out!
    ... But in the field of cryptanalysis, these are few and far between. ... Schneier who wrote a paper analyzing the attacks on unbalanced Feistel ... With that information I believe Applied Cryptography is in the same ... It may be that your criticisms are valid - but unless you've actually read ...
    (sci.crypt)
  • Re: simple math question
    ... I did not once state that linear cryptanalysis or differential cryptanalysis ... If you actually want to learn how to design ... from the basics by focusing on the attacks already published. ... An 8-bit cipher with an 8x8 bijective sbox S the cipher is simply ...
    (sci.crypt)
  • Re: New cryptanalysis book coming out!
    ... But in the field of cryptanalysis, these are few and far between. ... and the trade-offs and balances that such a design can achieve. ... a paper analyzing the attacks on unbalanced Feistel networks which covered ... With that information I believe Applied Cryptography is in the same ...
    (sci.crypt)
  • Re: Schneiers "Self-study course", Was: Re: Serious Responses Only Please...
    ... > section of his self study paper ... I think I found attacks on the RC5 variants and the ... S-Box-less DES; skipping the Skipjacks, I remember I then tried 4 & 6 ... Cryptanalysis" section are problems that took researchers a while to ...
    (sci.crypt)

Loading