[cryptography] ciphers with keys modifying control flow?

Steven Bellovin smb at cs.columbia.edu
Sun Sep 26 21:14:12 EDT 2010

Does anyone know of any ciphers where bits of keys modify the control path, rather than just data operations?  Yes, I know that that's a slippery concept, since ultimately things like addition and multiplication can be implemented with loops in the hardware or firmware.  I also suspect that it's potentially dangerous, since it might create very hard-to-spot classes of weak keys.  The closest I can think of is SIGABA, where some of the keying controlled the stepping of the other rotors.

		--Steve Bellovin, http://www.cs.columbia.edu/~smb

More information about the cryptography mailing list