[17654] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Time-Memory-Key tradeoff attacks?

daemon@ATHENA.MIT.EDU (D. J. Bernstein)
Fri Jul 8 15:40:12 2005

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: 6 Jul 2005 06:50:42 -0000
From: "D. J. Bernstein" <djb@cr.yp.to>
To: cryptography@metzdowd.com

My paper ``Understanding brute force'' explains an attack with a much
better price-performance ratio than the attack described by Biryukov:

   http://cr.yp.to/talks.html#2005.05.27
   http://cr.yp.to/papers.html#bruteforce

Biryukov's central point regarding key amortization was made earlier
(and, I think, more clearly) in my paper. My paper also analyzes the
merits of various defenses against the attack.

---D. J. Bernstein, Associate Professor, Department of Mathematics,
Statistics, and Computer Science, University of Illinois at Chicago

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post