3 ms·
The construction is at least at face value a pretty simple ARX cipher - the only real questions being why choose the specific rotation constants they do for eac
by wwwigham 7y ago
The construction is at least at face value a pretty simple ARX cipher - the only real questions being why choose the specific rotation constants they do for each round (ciphers developed in the open usually do things like key off digits of pi) and why compose specifically via xor, then add, then rotate in each round, rather than more of a blend.
If this style algorithm does indeed have an intentional backdoor: That's some crazy mathematic chops and I'd love to read the theory behind how it (the intentionally weak algorithm) was found (since hopefully that leads to a natural way to generate stronger algorithms, or at least check for weak ones). That'd be a valuable takeaway for the security community once the secret's spoiled, if it is the case.
- cyphar 7y ago> ciphers developed in the open usually do things like key off digits of pi It should be noted that we should be very wary of these types of "nothing up my sleeve" numbers. djb showed[1] that with enough effort you could come up with more than a million "obviously not backdoored" numbers (this was done in the context of elliptic curves) -- enough to exploit a million-to-one unknown-by-the-public vulnerability. [1]: https://youtu.be/Cj3PN5-n108 https://youtu.be/Cj3PN5-n108
- throwawaymath 7y agoThe context Bernstein is talking about is very meaningful here. The mathematics of public-key cryptography provides a rich tapestry for covering up hidden backdoors. ARX ciphers are very simple compared to elliptic curves, and the complexity of round constants isn't really comparable to that of curves.
- cyphar 7y agoRight, I should've added I agree with GP that ARX ciphers are incredibly simple and the ability to backdoor them would be a very novel (and concerning) discovery. My point is that "the values come from pi" is not necessarily proof that the constants really are "nothing up my sleeve". Bernstein was discussing this in the context of NIST curves (which could be backdoored), but the same one-in-a-million maths works for any constants (so long as you happen to know a weak-constants vulnerability that isn't known by the public).