3 ms·
Most of the eSTREAM finalists (http://www.ecrypt.eu.org/stream/index.html http://www.ecrypt.eu.org/stream/index.html) are not block-based. I think only Salsa20
by pbsd 8y ago
Most of the eSTREAM finalists (http://www.ecrypt.eu.org/stream/index.html http://www.ecrypt.eu.org/stream/index.html) are not block-based. I think only Salsa20 matches that description.
More generally, I think the distinction between a "block-based stream cipher" and a block cipher (or permutation) mode is the degree to which you abstract away the block cipher. Personally I wouldn't put them together. Counter mode completely abstracts away the cipher, assuming it is an idealized pseudorandom function; sponge-based modes also abstract away the permutation as ideal in most cases; stream ciphers usually do not do this, and use weaker (but still sometimes block-based) primitives to generate output. There are, for example, sponge modes that use very few rounds past the initialization, which makes them more streamy than spongy. So their cryptanalysis is often different.
- lvh 8y ago> More generally, I think the distinction between a "block-based stream cipher" and a block cipher (or permutation) mode is the degree to which you abstract away the block cipher. Just to make sure I understand you correctly, for example: - CTR: definitely a stream cipher, and a synchronous one at that - CBC: maybe a little like a stream cipher (you're e.g. exposed to the block width, and also less like most stream ciphers because asynchronous) - AEZ: extremely not (because you're exposed to round counts) That makes perfect sense to me, since that's where I felt the analogy started getting tenuous :)
- deleted 8y ago[deleted]