[77080] in cryptography@c2.net mail archive
Re: analysis and implementation of LRW
daemon@ATHENA.MIT.EDU (Ben Laurie)
Tue Jan 23 16:32:23 2007
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Tue, 23 Jan 2007 18:03:04 +0000
From: Ben Laurie <ben@links.org>
To: cryptography@metzdowd.com
In-Reply-To: <200701230022.l0N0MWAk004808@taverner.cs.berkeley.edu>
David Wagner wrote:
> Jim Hughes writes:
>> The IEEE P1619 standard group has dropped LRW mode. It has a
>> vulnerability that that are collisions that will divulge the mixing
>> key which will reduce the mode to ECB.
>
> This is interesting. Could you elaborate on this? I suspect we could
> all learn from the work the IEEE P1619 working group is doing.
>
> I tried to trawl the P1619 mailing list archives to find some detailed
> analysis on the topic of collisions, as you suggested, but I probably
> wasn't looking in the right places. The closest I found was this message:
> http://grouper.ieee.org/groups/1619/email/msg01322.html
> which estimates that if one continuously accesses the disk for 4.6
> years (roughly the average life time of a disk), the chances of seeing
> a collision are about 1/2^29. Is that the analysis that triggered the
> concern over collisions?
Google is your friend:
http://grouper.ieee.org/groups/1619/email/msg00558.html
Cheers,
Ben.
--
http://www.apache-ssl.org/ben.html http://www.links.org/
"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com