Black Eye for NSA, NIST, and Denning

Perry E. Metzger perry at imsi.com
Fri Jun 3 05:02:27 PDT 1994



Derek Atkins says:
> > brute force search for one quite practical -- especially since it only
> > need be done once.
> 
> actually, it needs to be done once per session key (i.e., when you
> change the session key, you need to re-issue a LEAF)

However, it can be done in advance, and you can conceivably reuse
forged LEAFs.

I've come up with what I believe to be a pretty good algorithm to
prevent this problem. I would like to patent it so that I can then
charge exhorbitant sums of manufacturers should the technique be
incorporated in a future EES design. Anyone know where I can find a
cheap patent attorney?

Perry






More information about the cypherpunks-legacy mailing list