NODE 1ad59e0athe rest of the key
Brian D Williams <talon57@well.sf.ca.us>Wed, 30 Mar 94 09:05:28 PST
-----BEGIN PGP SIGNED MESSAGE-----
I was just wondering.... If the NSA could get it's hands on half
(40) of any particular clipper key, wouldn't that just leave 2^40
to compute? Even with brute force, it's trivial even next to DES.
Brian Williams
Extropian
Cypherpatriot
"Cryptocosmology: Sufficently advanced comunication is
indistinguishable from noise." --Steve Witham
"Have you ever had your phones tapped by the government? YOU WILL
and the company that'll bring it to you.... AT&T" --James Speth
-----BEGIN PGP SIGNATURE-----
Version: 2.3a
iQCVAgUBLZmvbtCcBnAsu2t1AQE5MwP9E46rrqaqqDRASdd5EHuRgkvGmax3y/3n
RQ7xIRT+ixXBfKMnSDdcScdV9OqR6JcQJFru88zynqj4XaU6u1olYKPKJhjpO1ry
nE8vHi4UO8qkg4B3cnf2XZVlkwrICTzGGhZjHuqws0R3C++1AGmVBA/UrlHQxwZn
h9jU4GRUHQI=
=xVfX
-----END PGP SIGNATURE-----
NODE 51bc7b19Re: the rest of the key
Jim Gillogly <jim@rand.org>Wed, 30 Mar 94 09:28:10 PST
> I was just wondering.... If the NSA could get it's hands on half
> (40) of any particular clipper key, wouldn't that just leave 2^40
> to compute? Even with brute force, it's trivial even next to DES.
No -- not like that, anyway. The two halves are each 80-bit numbers
constructed from the key generation process, and the unit key is the XOR
of the two of them. Having one doesn't give any information about the
key, if the key generation people are behaving honestly. Obviously if
one of the halves is supplied by somebody sneaky they don't need the other
half; but the procedure as outlined by Denning would make this impossible
if Skipjack is as strong as she believes.
I understand the Skipjack review committee will be looking into the key
generation process at Mykotronx also. The procedures originally proposed
for burning in the keys has some annoying flaws that have been pointed out
frequently, like the existence of both halves in the same room at the same
time, which would be a tempting target for somebody siphoning them off to
a private single-site escrow. :) Various people have suggested that the
two halves of the key could be burned in at separate locations, so that the
only place they're put together is in the key itself; this was not part of
the proposal as we've seen it so far out here.
Jim Gillogly
Sterday, 8 Astron S.R. 1994, 17:25
NODE 1dacd72bthe rest of the key
hughes@ah.com (Eric Hughes)Wed, 30 Mar 94 10:04:20 PST
> I was just wondering.... If the NSA could get it's hands on half
>(40) of any particular clipper key, wouldn't that just leave 2^40
>to compute? Even with brute force, it's trivial even next to DES.
"half" is a a random number which is XOR'd with 80 bits. Both halves
look random. The XOR of the two halves is not.
Eric