Re: AES 256 based key derivation function.
- From: Kristian Gjøsteen <kristiag+news@xxxxxxxxxxxx>
- Date: Fri, 24 Oct 2008 21:09:10 +0000 (UTC)
Fabrice <fabrice.gautier@xxxxxxxxx> wrote:
How does one define security of the Key Derivation Function in this
case ?
It should be hard to distinguish a small number of derived keys from
a collection of random keys.
Your second proposal, dk=tk || AES(rk,tk), can only yield 2^128
different dk (because tk is 128 bits), whereas the first one would
produce 2^256 keys.
As you correctly conclude, this doesn't matter if an attacker cannot
use this fact to his advantage.
--
Kristian Gjøsteen
.
- References:
- AES 256 based key derivation function.
- From: Fabrice
- Re: AES 256 based key derivation function.
- From: Kristian Gjøsteen
- Re: AES 256 based key derivation function.
- From: Fabrice
- AES 256 based key derivation function.
- Prev by Date: Re: AES 256 based key derivation function.
- Next by Date: Re: AES 256 based key derivation function.
- Previous by thread: Re: AES 256 based key derivation function.
- Next by thread: لأول مرّة.. صورة جثة سوزان تميم بعد قتلها مباشرة
- Index(es):
Relevant Pages
|