[111965] in cryptography@c2.net mail archive
Philips/NXP/Mifare CRYPTO1 mostly reverse-engineered
daemon@ATHENA.MIT.EDU (Ralf-Philipp Weinmann)
Sun Dec 30 16:08:20 2007
From: Ralf-Philipp Weinmann <weinmann@cdc.informatik.tu-darmstadt.de>
To: Cryptography <cryptography@metzdowd.com>
Date: Sun, 30 Dec 2007 11:29:32 +0100
X-MailScanner-From: weinmann@cdc.informatik.tu-darmstadt.de
=46rom http://cryptanalysis.eu/blog/2007/12/29/mifare-crypto1:
"MiFare=92s CRYPTO1 stream cipher has captured my attention for a while. =
=20
However, hardware reverse-engineering is not a field I actively engage =20=
in. So I was very happy when Karsten Nohl (University of Virginia), =20
Starbug and Henryk Pl=F6tz gave a talk at the 24C3 [the 24th Congress of =
=20
the Chaos Computer Club taking place in Berlin at this very moment] =20
yesterday evening showing that they have reverse-engineered most parts =20=
of this cipher. CRYPTO1 uses a 48-bit LFSR-based filter generator to =20
generate key stream.
The filter function - if I understood correctly - uses 20 taps (this =20
was not mentioned in the talk, I asked Karsten privately about this) =20
however the degree of the boolean function implementing the filter, =20
thus it remains to be seen whether algebraic attacks can be applied. =20
Even if no algebraic attacks are applied, a BSW sampling TMTO will =20
break CRYPTO1 completely. This was pretty obvious before they gave =20
their talk, but now vendors actually have to worry about this being =20
out in the wild once the feedback and the filter function have been =20
revealed.
My colleague Erik took photos of the slides which I put up on Zooomr =20
[0]. A video recording of the talk should be available shortly and =20
will be linked here."
[0] http://www.zooomr.com/photos/ralf/sets/26758/=
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com