From: "George Spelvin" <linux@horizon.com>
To: linux@horizon.com, nhorman@tuxdriver.com
Cc: herbert@gondor.apana.org.au, jarod@redhat.com,
linux-crypto@vger.kernel.org, smueller@chronox.de
Subject: Re: Is ansi_cprng.c supposed to be an implmentation of X9.31?
Date: 2 Dec 2014 12:56:15 -0500 [thread overview]
Message-ID: <20141202175615.31851.qmail@ns.horizon.com> (raw)
In-Reply-To: <20141202132233.GB3388@hmsreliant.think-freely.org>
> That is an old version. The updated version (published in 2005), and
> specified in the ansi_cprng.c file removes that language.
Oh! Thank you! I'm pretty sure I read the 1998 version.
In fact, apparently there's a 2010 version:
http://www.codesdownload.org/3761-ANSI-X9-TR-31-2010.html
I need to figure out how to get my hands on that.
Presumably this is the 2005 version with the 2009 supplement incorporated.
If I could read Chinese, I might be able to find it here:
http://www.docin.com/p-524511188.html
> The long and the short of it is that, if you want a cprng who's output can be
> predicted by any entity with the IV and KEY values, then DT has to be known
> initially and updated in a predictable fashion that is independent of the data
> being transmitted. Using a real date/time vector can't do that.
Er, yes, this is all extremely obvious; I'm not quite sure why we're
belabouring it. Fully deterministic generators have their uses, which
is why I had to ask in the beginning what the design intent was.
If this is *intended* to be purely deterministic, there's nothing to fix.
I'd like to propose a small comment clarification because a quick reading
confused me.
But when I talked about making it random, you said "send a patch", so
I did. If you don't want the semantic change, I'm not upset. The other
code cleanups are hopefully (after I've finished polishing them) useful;
just stop before the whole "union block" business.
next prev parent reply other threads:[~2014-12-02 17:56 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-28 23:23 Is ansi_cprng.c supposed to be an implmentation of X9.31? George Spelvin
2014-11-29 17:58 ` Neil Horman
2014-11-29 19:32 ` George Spelvin
2014-11-30 1:16 ` Neil Horman
2014-11-30 14:36 ` Stephan Mueller
2014-12-02 4:55 ` George Spelvin
2014-12-02 13:22 ` Neil Horman
2014-12-02 17:56 ` George Spelvin [this message]
2014-11-30 14:31 ` Stephan Mueller
2014-11-30 14:26 ` Stephan Mueller
2014-12-02 5:39 ` George Spelvin
2014-12-02 13:44 ` Neil Horman
2014-12-02 19:43 ` George Spelvin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20141202175615.31851.qmail@ns.horizon.com \
--to=linux@horizon.com \
--cc=herbert@gondor.apana.org.au \
--cc=jarod@redhat.com \
--cc=linux-crypto@vger.kernel.org \
--cc=nhorman@tuxdriver.com \
--cc=smueller@chronox.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox