home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: sci.crypt
- Path: sparky!uunet!munnari.oz.au!cs.mu.OZ.AU!mkwan
- From: mkwan@cs.mu.OZ.AU (Matthew Kwan)
- Subject: Re: Does Lucifer have weaknesses?
- Message-ID: <9222611.17068@mulga.cs.mu.OZ.AU>
- Organization: Computer Science, University of Melbourne, Australia
- References: <1992Aug6.215610.10235@bvsd.co.edu> <1357@eouk9.eoe.co.uk>
- Date: Thu, 13 Aug 1992 01:22:18 GMT
- Lines: 20
-
- ahaley@eoe.co.uk (Andrew Haley) writes:
-
- >: Does the Lucifer algorithm have any weaknesses?
-
- >Yes. Lucifer with eight rounds and 128-bit blocks is breakable within
- >2**21 steps using 24 chosen ciphertext pairs. DES is a great
- >improvement over this.
-
- >Biham & Shamir, _Differential cryptanalysis of Snefru, Khafre,
- >REDOC-II, LOKI and Lucifer_, Proceedings of CRYPTO '91.
-
- Yes, but remember that DES is a 16-round cipher. An 8-round version
- of Lucifer has been broken, but the last time I spoke to Eli Biham
- he hadn't succeeded in breaking the 16-round (standard) version.
-
- However, Lucifer has quite a few weak keys, and a few easily found
- (key, plaintext, ciphertext) triplets where plaintext = ciphertext.
- Not a fatal weakness, but it can be a problem when hashing.
-
- mkwan
-