Perry E. Metzger (perry@piermont.com)
Thu, 25 Jun 1998 23:04:38 -0400
Paulo Barreto writes:
> At 12:02 1998.06.25 -0400, you wrote:
> >And how much analysis has been done on Square, compared with, say,
> >3DES?
>
> Hmmm... if you really expect an answer, please tell me exactly how much
> analysis has been done on 3DES :-)
At this point, I'd say somewhere on the order tens to a hundred man
years. The question of whether DES was a group alone recieved probably
a couple of man years of work between a number of people.
> Seriously, take a look at the Square paper (or at the Rijndael documents).
> the whole theory behind Square was distilled from all published analyses of
> known ciphers (plus new results by Joan Daemen and Vincent Rijmen). This
> way you could almost say that the 3DES analyses are integrated in the
> design of Square.
No, you couldn't say that. You'll know if Square withstands attack as
well as 3DES when you *know* that lots of serious analysis has hit it,
and I suspect it has not. It hasn't even been around that long.
I'm sorry to sound sour, but I am not nearly as enthusiastic about
early incorporation of new cryptosystems into production use as many
people around here seem to be.
Perry
The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:19:06 ADT