cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
AppDefects
Community Champion

Defect in Russian Cryptographic Algorithms. Coincidence?

At a recent ISO/IEC Joint Technical Committee meeting in Tel Aviv the Russian delegation did not offer convincing arguments that their countries cryptographic algorithms STREEBOG (256/512 hashing functions) and KUZNYECHIK (64/128 block cipher) coincidentally shared the same flaw in their S-Box design. This was discovered by Léo Perrin (IACR reprint here). The ISO/IEC working group plans to take 6 months to investigate the potential for the flaw to be exploited. Streebog is already an ISO/IEC standard and was developed by the Center for Information Protection and Special Communications of the Federal Security Service, Russia’s main security agency. Notably, this is not the first time ISO/IEC has seen a government entity ask it to approve its own cryptographic algorithms, remember our good friends at the NSA tried this last year with "SIMON" and "SPECK" for IoT and they were not accepted.

1 Reply
CraginS
Defender I

What? A National Intelligence Service fielded a crypto algorithm with an exploitable defect???

 

 

 

D. Cragin Shelton, DSc
Dr.Cragin@iCloud.com
My Blog
My LinkeDin Profile
My Community Posts