[77178] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: analysis and implementation of LRW

daemon@ATHENA.MIT.EDU (Peter Gutmann)
Wed Jan 24 16:36:26 2007

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cryptography@metzdowd.com, daw@cs.berkeley.edu
In-Reply-To: <200701231843.l0NIh4uu017715@taverner.cs.berkeley.edu>
Date: Wed, 24 Jan 2007 14:51:54 +1300

David Wagner <daw@cs.berkeley.edu> writes:

>That is indeed an interesting requirement, and one that seems to legitimately
>rule out a number of existing modes of operation for IEEE P1619.

>From reading through the followup discussions, I think there's a strong desire
to not standardise something that's very brittle (think RC4).  For example in
a later followup the same person who pointed out the LRW issues thought that
one widely-deployed implementation, TrueCrypt, might have fallen into this
trap.  Luckily it didn't, but it was a sign that LRW may be just a bit too
brittle to safely deploy, particularly when the intended audience is embedded
systems and ASIC engineers and not cryptographers.  So the current
recommendation is to go to XTS (sometimes, confusingly, referred to as XEX),
which can be implemented using existing IP blocks developed for AES-GCM.
There are already several vendors shipping IP for AES-XTS.

Peter.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post