Кіріспе
Ағыс шифрі Py – Eli Biham және Jennifer Seberry eSTREAM-ге ұсынған ағыс шифрі. Бұл кейбір платформаларда байтқа шамамен 2,6 циклмен ең жылдам eSTREAM кандидаттарының бірі. Оның құрылымы RC4 сияқты, бірақ байттардың ауысуы арқылы индекстелетін 260 32 биттік сөздер массивін қосады және әр раундта 64 бит шығарады. Авторлар «Py» әріптерін латын емес, кириллица (Ру) ретінде оқып, атаудың «Ру» деп айтылуын қалайды, бұл шифрдің австралиялық тегіне сілтеме. Бұл біршама ерекше айтылу олардың әзіл-қалжың ретіндегі жауабы деп түсініледі, Advanced Encryption Standard ретінде қабылданған шифрдің қиын айтылатын «Rijndael» атауына. 2005 жылғы сәуірдегі бастапқы ұсыныста Py шифрі және Py6 жеңілдетілген нұсқасы кірген. Соңғысы кейбір ішкі кестелердің көлемін азайтады, кілттік кесте құру шығындарын төмендетіп, максималды шығыс ұзындығын қысқартады. 2006 жылғы маусымда авторлар Pypy (одан да шатастыратын, жартылай кириллицадағы Пиру және осылайша «Пироу» деп айтылады) нұсқасын қалаулы, күшті нұсқа ретінде сипаттады. Бұл Py-дің әрбір итерациясынан бір сөзді алып тастайды, сондықтан Py жылдамдығының жартысынан сәл жоғары жылдамдықпен жұмыс істейді (шамамен 0,6 есе). 2007 жылғы қаңтарда негізгі кесте алгоритмі өзгертілді, нәтижесінде «түзетілген» нұсқалар TPy, TPypy және TPy6 пайда болды. Нақтырақ айтқанда, бірінші (кілтке тәуелді) кезең өзгеріссіз қалды, бірақ екінші (IV) кезеңдегі қате түзетілді. Шығысты жасау үшін қолданылатын раунд функциялары өзгерген жоқ. Indocrypt 2007 конференциясында Гаутам Секар, Сурадюти Пол және Барт Пренел Pypy және Py жобалау принциптеріне негізделген екі жаңа шифр – RCR 32 және RCR 64 ұсынды. Бұл Py-дегі айнымалы айналымды тұрақты айналыммен алмастырады, шабуылды жояды және шифрлеуді сәл жылдамдатады. TPy кілті кестесі өзгеріссіз қолданылады.
Py is a stream cipher submitted to eSTREAM by Eli Biham and Jennifer Seberry. It is one of the fastest eSTREAM candidates at around 2.6 cycles per byte on some platforms. It has a structure a little like RC4, but adds an array of 260 32 bit words which are indexed using a permutation of bytes, and produces 64 bits in each round. The authors assert that the name be pronounced "Roo", a reference to the cipher's Australian origin, by reading the letters "Py" as Cyrillic (Ру) rather than Latin characters. This somewhat perverse pronunciation is understood to be their answer, in jest, to the difficult to pronounce name Rijndael for the cipher which was adopted as the Advanced Encryption Standard. The original April 2005 proposal included the cipher Py, and a simplified version Py6. The latter reduces the size of some internal tables, providing greatly reduced key scheduling cost, at the expense of a shorter maximum output length. In June 2006, the authors described Pypy (even more confusingly, half Cyrillic Pyру and thus pronounced "Pyroo") as an optional stronger variant. This omits one of the output words from each iteration of Py, and thus operates at slightly over half the speed of Py. (Actually about 0.6×.) In January 2007, the key schedule algorithm was changed, producing "tweaked" variants TPy, TPypy and TPy6. To be precise, the first (key dependent) phase is unmodified, but the second (IV setup) phase has an error corrected. The round functions used to produce output are identical. At Indocrypt 2007, Gautham Sekar, Souradyuti Paul and Bart Preneel proposed two new ciphers RCR 32 and RCR 64 based on the design principles of Pypy and Py, respectively. These replace a variable rotate in Py with a fixed rotate, eliminating an attack and speeding up the cipher slightly. The TPy key schedule is used unmodified.
Py-отбасына шабуыл
2006 жылдан бастап, Py шифріне ең тиімді криптоаналитикалық шабуыл (Хонгжун Ву мен Барт Пренелдің) кейбір жағдайларда (мысалы, IV кілттен әлдеқайда ұзын болғанда) 224 таңдалған IV үшін кілт ағынының ішінара бөлігін қалпына келтіре алады. Шабуылшы үшін қиынырақ сценарийде, тек белгілі ашық мәтін (таңдалған ашық мәтін емес) берілген жағдайда, кілт ағынына қатысты ерекшелендіру шабуылы (Пол Кроулидің) бар, ол шамамен 272 байт дерек және соған сәйкес уақытты қажет етеді. Бұл Гаутам Секар, Сурадюти Пол және Барт Пренел ұсынған 288 байтты қажет ететін шабуылдан жақсы нәтиже. Бұл шабуылдар Py шифрін академиялық тұрғыдан бұза ма, жоқ па деген пікірталас әлі де жалғасуда. Шабуылшылар аталған шабуылдарды Py шифрінің жобалау талаптарына сәйкес, толық іздеуден кем жүктемемен жасауға болатынын мәлімдесе, бұл шифрдің теориялық бұзылуы болып саналады. Алайда, дизайнерлер шабуылдарды жоққа шығарады, себебі Py шифрінің қауіпсіздік шектеулері кез келген шабуылшыны барлық кілт ағындарындағы барлық деректер бойынша 264 байттан аспайтын көлемге шектейді. Пауль, Пренель және Секардың мақаласының жаңа редакциясы 9-бөлімде осы мәселенің егжей-тегжейлі талқылануын қамтиды. Ву мен Пренелдің шабуылының заңдылығына күмән жоқ. Py шифрі eSTREAM жобасы бойынша 2-кезеңдегі 1-профильге (бағдарламалық қамтамасыз ету) іріктелді, бірақ Ву мен Пренелдің таңдалған IV шабуылына байланысты 3-кезеңге өте алмады. 2007 жылдың қаңтар айында Py шифрінің авторлары жоғарыда аталған шабуылдарды жою мақсатында TPy, TPypy және TPy6 атты үш жаңа шифрді ұсынды. TPy шифрі әлі де Пауль және тағы басқалардың аталған ерекшелендіру шабуылдарына (күрделілігі 288) және Кроулидің шабуылына (күрделілігі 272) бейім, олар кілт кестесіне байланысты емес. Py шифрлер отбасының ең күштісі деп саналатын TPypy шифріне жасалған ең тиімді шабуыл – Секар және тағы басқалар жасаған, дерек көлемі 2281 болатын ерекшелендіру шабуылы. Бұл шабуыл тек TPypy шифрінің кілті 281 биттен ұзын болған жағдайда ғана мағыналы. TPy және TPypy шифрлеріне қарсы шабуылдарды жою үшін Секар, Пол және Пренел Indocrypt 2007 конференциясында RCR 32 және RCR 64 атты екі жаңа шифрді ұсынды. Қазіргі таңдағы RCR 32 және RCR 64 шифрлеріне қарсы шабуылдар белгілі емес.
In a more difficult scenario from the point of view of attacker, given only known plaintext (rather than chosen plaintext), there is also a distinguishing attack on the keystream (by Paul Crowley) which requires around 272 bytes of output and comparable time. This is an improvement on an attack presented by Gautham Sekar, Souradyuti Paul and Bart Preneel which requires 288 bytes. There is a still a debate whether these attacks constitute an academic break of Py. When the attackers claim that the above attacks can be built with workload less than the exhaustive search under the design specifications of Py and therefore, it is clearly a theoretical break of the cipher, the designers rule out the attacks because Py's security bounds limit any attacker to a total of 264 bytes of output across all keystreams everywhere. A recent revision of the Paul, Preneel, and Sekar paper includes a detailed discussion of this issue in section 9. There are no doubts about the legitimacy of the Wu and Preneel attack. Py was selected as Phase 2 Focus Candidate for Profile 1 (software) by the eSTREAM project but did not advance to Phase 3 due to the Wu and Preneel chosen IV attack. In January 2007, three new ciphers namely TPy, TPypy and TPy6 have been proposed by the designers of Py to eliminate the above attacks. The TPy is still vulnerable against the above distinguishing attacks by Paul et al. (complexity 288) and Crowley (complexity 272), which do not depend on the key schedule. The best attack so far on the TPypy, which is conjectured to be the strongest of the Py family of ciphers, is by Sekar et al. which is a distinguishing attack with data complexity 2281. This attack is only meaningful if the key size of TPypy is longer than 281 bits. To remove attacks on TPy and TPypy, Sekar, Paul and Preneel at Indocrypt 2007 gave proposals for two new ciphers RCR 32 and RCR 64. So far there are no attacks against the RCR 32 and RCR 64.