Matt Blaze wrote: > > I should point out that this construction is not designed to obscure the > input from the output (especially under differential probing), only > to give you m output bits that depend (each in a different way) on > the entire input. Perhaps I should add that as a requirement. OTOH, assuming H is perfect, wouldn't that make this construction resistant? But I assume you are reluctant to attempt to prove that. Cheers, Ben. -- http://www.apache-ssl.org/ben.html Coming to ApacheCon Europe 2000? http://apachecon.com/
- Re: Extracting Entropy? Bodo Moeller
- Re: Extracting Entropy? Niels Möller
- Re: Extracting Entropy? Bodo Moeller
- Re: Extracting Entropy? Paul Crowley
- Re: Extracting Entropy? John Kelsey
- Re: Extracting Entropy? Paul Crowley
- Re: Extracting Entropy? John Kelsey
- Re: Extracting Entropy? Paul Crowley
- Re: Extracting Entropy? Arnold G. Reinhold
- Re: Extracting Entropy? Matt Blaze
- Re: Extracting Entropy? Ben Laurie
- Re: Extracting Entropy? Matt Blaze
- Re: Extracting Entropy? dmolnar
- Re: Extracting Entropy? Matt Blaze
- Re: Extracting Entropy? Peter Gutmann
- Re: Extracting Entropy? Pete Chown