[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: GOST for sale

At 03:43 AM 11/24/95 +0100, Mats Bergstrom <[email protected]> wrote:
>According to a short article in a Swedish newspaper (DN)
>with the title 'Spy Code of KGB can make computers safe', 
>JETICO INC., located in Finland (Tammerfors), introduced
>a new crypto system on the world market last week. It's 
>based on GOST, the Russian federal standard algorithm.
>This product, called BestCrypt, is implemented at least
>partly in hardware. Alledgedly it uses 'GOST 28147-89',
>whatever that stands for.
>GOST is probably very secure - a huge keyspace (256 bits) and
>KGB would not have left a trapdoor for NSA to take advantage
>of, would they?

>From what I've read of GOST, it's really a family of cyphers with
different sets of S-boxes - routine military gets one set, top secret
gets another, civilian govt another, etc.  Aside from possible
differences in security level for the S-boxes, one motivation is
that you can't take civilian govt decryptors and use them to read
or forge top secret military crypto, etc.  If this is correct,
then some sets of S-boxes probably do have trapdoors (at least
susceptibility to differential cryptanalysis_; how good are the
ones that Jetico is selling, what credentials do they have to
convince us their cryptanalysis is good enough, and why are they
doing parts of it in hardware?
#				Thanks;  Bill
# Bill Stewart, Freelance Information Architect, [email protected]
# Phone +1-510-247-0663 Pager/Voicemail 1-408-787-1281