[144607] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: work factor calculation for brute-forcing crypto

daemon@ATHENA.MIT.EDU (David Malone)
Sun Jul 19 14:35:49 2009

Date: Sun, 19 Jul 2009 12:43:33 +0100
From: David Malone <dwmalone@maths.tcd.ie>
To: cryptography@metzdowd.com
In-Reply-To: <20090717183743.GH6065@subspacefield.org>

On Fri, Jul 17, 2009 at 01:37:43PM -0500, travis+ml-cryptography@subspacefield.org wrote:
> I'm curious if there's a way to express this calculation as a
> mathematical formula, rather than an algorithm, but right now I'm just
> blanking on how I could do it.

This has been dubbed the "guesswork" of a distribution by some authors,
I think originating with:

	John O. Pliam. The disparity between work and entropy in
	cryptology. http://philby.ucsd.edu/cryptolib/1998/98-24.html,
	February 1999

It turns out that its asymoptic behaviour is bit like that of Renyi
entropy, see:

	E. Arikan. An inequality on guessing and its application
	to sequential decoding. IEEE Transactions on Information
	Theory, 42:99105, Janurary 1996.

I did an explanitory writeup of this with some experiments at:

	http://www.maths.tcd.ie/~dwmalone/p/itt05.pdf

David.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post