edit irRUPT security

[Imported from Trac: page Bibliography, version 35]
zooko 2009-03-04 21:50:18 +00:00
parent 2710a519dd
commit e5980fe8ed

@ -11,7 +11,7 @@ Here are some papers that are potentially of interest.
[ChaChaCha20](http://cr.yp.to/chacha.html) even better stream cipher; It is probably slightly safer than Salsa and it is certainly slightly faster.
[EnRUPT](http://enrupt.com) a very simple, fast, and flexible primitive which could be used as stream cipher, secure hash function, or MAC (the first two are primitives that we currently need, and the third one -- MAC -- is a primitive that we may want in the future) and which relies for its security on a large number of rounds. The question of how many rounds to use is decided by semi-automated cryptanalysis. (Note: the stream-hash version of enRUPT, known as "irRUPT" has been shown to be insecure in the SHA-3 contest. The traditional Merkle-Damgard variant -- mdRUPT -- is probably secure.)
[EnRUPT](http://enrupt.com) a very simple, fast, and flexible primitive which could be used as stream cipher, secure hash function, or MAC (the first two are primitives that we currently need, and the third one -- MAC -- is a primitive that we may want in the future) and which relies for its security on a large number of rounds. The question of how many rounds to use is decided by semi-automated cryptanalysis. (Note: the stream-hash version of enRUPT, known as "irRUPT" has been shown to be insecure in the SHA-3 contest when used with the number of rounds originally recommended. The traditional Merkle-Damgard variant -- mdRUPT -- is probably secure. Also irRUPT is probably secure, and still reasonably fast, with a few more rounds.)
[Cryptanalysis of the Tiger Hash Function](https://online.tu-graz.ac.at/tug_online/voe_main2.getvolltext?pDocumentNr=81263) by Mendel and RIjmen