Matt Blaze wrote:
> 
> I should point out that this construction is not designed to obscure the
> input from the output (especially under differential probing), only
> to give you m output bits that depend (each in a different way) on
> the entire input.

Perhaps I should add that as a requirement. OTOH, assuming H is perfect,
wouldn't that make this construction resistant? But I assume you are
reluctant to attempt to prove that.

Cheers,

Ben.

--
http://www.apache-ssl.org/ben.html

Coming to ApacheCon Europe 2000? http://apachecon.com/

Reply via email to