[77264] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

block cipher modes and collisions

daemon@ATHENA.MIT.EDU (Travis H.)
Thu Jan 25 14:04:06 2007

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Wed, 24 Jan 2007 18:54:13 -0600
From: "Travis H." <travis+ml-cryptography@subspacefield.org>
To: Cryptography <cryptography@metzdowd.com>
Mail-Followup-To: Cryptography <cryptography@metzdowd.com>


--aM3YZ0Iwxop3KEKx
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

The wikipedia page on the IEEE SISWG debate about LRW says:

"[A] general security requirement for any block cipher, regardless of
mode of operation, is that no block cipher should be used to encrypt
any more data, without changing the key, when the probability of a
collision becomes not negligible (see also birthday paradox)."

They must mean output collisions, rather than multiple preimages,
but I think some modes will have collisions at a rate which depends
on the plaintext (LRW being the obvious example)... but I've never
heard of this security requirement before.  Excepting the Handbook
of Applied Cryptography, which I need to read, does anyone have
another reference for this requirement, or others like it?

I suppose that NIST might have published something like that
in the various publications about block cipher modes, but don't
know where to look exactly...
--=20
``Unthinking respect for authority is the greatest enemy of truth.''
-- Albert Einstein -><- <URL:http://www.subspacefield.org/~travis/>

--aM3YZ0Iwxop3KEKx
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.1 (OpenBSD)

iQIVAwUBRbf/tWQVZZEDJt9HAQKE7RAArH5QDDI58VyUPCdq2UN2lKMkj88JsNPm
C7+MyvTl2TOGagHtsvHIAWs7kwiLtzcsoXewUdPQEA8k5X/GSBJ/PGBqg+d56iGY
uKhdnOcNz5mgmOrV8VIaHoSE4vMT0q7OmKXMo4vfx+R10/Qqy+Bi2qdlW8S+eXAX
dLc4KnDSqmNEvo5DGhr8HL/+hqup5mSD39SSFD50hmvrJE0TXFjPQcAeBzQW+Net
vWBxE2dgNVD6DK7AIxRZ1oi5nOH8dGqdH0xu0YSMsZ28FUR4OaeL4AQFZAuePoHy
EGqfus+wZ9jWotYsmxFAgLdfn3pj/v18Wp0u9yi27NERWu7xMaVvwI38CtbdCTTf
p2haYeEiEveMQEYVo1BC46QUYRwthYrAF6jjDYPVQAmQzBMl0DTh4v6qkWKWhiMT
mYmFv8GKkDdkuAGFR8MAQZBlxxEo3g/hq/hVu8UFXlR2TQNJW5w1xE1B867Un+Qd
chBaSu931hHs1cSffqFxFMnxdnL9UJBeqajeKTw8X2Zh0Ee6233A7TxHRI+PHpau
nCwX08KBltdsP9taxXN4g+rFmGglPf29NRug0czdQFW/npY14m4GBky7xZTclCfG
wPLOJFIttYC8paVaF+E//ZdqzC4n1U7YYnVfiIPrd9oN959Q20Z5yvEjTsocs62g
GXMI22hmAR0=
=36iY
-----END PGP SIGNATURE-----

--aM3YZ0Iwxop3KEKx--

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post