[77035] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: analysis and implementation of LRW

daemon@ATHENA.MIT.EDU (David Wagner)
Tue Jan 23 09:35:36 2007

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: David Wagner <daw@cs.berkeley.edu>
To: cryptography@metzdowd.com
Date: Mon, 22 Jan 2007 16:22:32 -0800 (PST)

Jim Hughes writes:
>The IEEE P1619 standard group has dropped LRW mode. It has a  
>vulnerability that that are collisions that will divulge the mixing  
>key which will reduce the mode to ECB.

This is interesting.  Could you elaborate on this?  I suspect we could
all learn from the work the IEEE P1619 working group is doing.

I tried to trawl the P1619 mailing list archives to find some detailed
analysis on the topic of collisions, as you suggested, but I probably
wasn't looking in the right places.  The closest I found was this message:
  http://grouper.ieee.org/groups/1619/email/msg01322.html
which estimates that if one continuously accesses the disk for 4.6
years (roughly the average life time of a disk), the chances of seeing
a collision are about 1/2^29.  Is that the analysis that triggered the
concern over collisions?

Are there modes that beat the birthday bound on collisions while using
a 128-bit block cipher?  Are they proven secure beyond the birthday bound?
I'm a little behind on the latest developments in modes of operation.

It would be interesting to hear more about any interesting technical
developments from the P1619 group.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post