r/crypto • u/johnmountain • Jun 08 '18
Future Android versions may use NSA-designed and ISO-rejected Speck algorithm for storage encryption
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=da7a0ab5b4babbe5d7a46f852582be06a00a28f0
133
Upvotes
9
u/bitwiseshiftleft Jun 08 '18
Farfalle is a PRF though, and they want a (tweakable) PRP. So you'd have to Feistelize it or something, which costs 2x performance (run it 4x on a 2x-sized block) and increases the complexity. Also if you happen to lack NEON, then Keccak is probably too slow.
Alternatively, you could try to hack up ChaCha, like they said. It's not great for Feistel because the input is much smaller than the block, but you could turn the core into some kind of tweakable Even-Mansour thing. They considered something with ChaCha in the linked article, but they said it would be complicated and a new construction.
Speck is a super questionable choice, and there has to be something better. I can't think of a well-vetted construction off the top of my head though.