[DragonFlyBSD - Bug #2677] L15 Update

bugtracker-admin at leaf.dragonflybsd.org bugtracker-admin at leaf.dragonflybsd.org
Mon Jun 9 04:33:15 PDT 2014

Issue #2677 has been updated by alexh.

On 2014-06-09 11:29, bugtracker-admin at leaf.dragonflybsd.org wrote:
> Issue #2677 has been updated by robin.carey1.

> If you want to move to a more mainstream algorithm, consider using AES
> (AES-CTR; AES/Counter mode).
> AES is approved by NIST/NSA. I'm sure you must know that AES 
> instructions
> are built into some current CPUs
> from Intel/AMD.

I'm fully aware of the general availability of AES-related instructions 
in many modern CPUs. However, not all do, and when they do not, AES is 
rather expensive in terms of CPU cycles compared to stream ciphers such 
as Salsa20 or ChaCha.

Bug #2677: L15 Update

* Author: robin.carey1
* Status: New
* Priority: High
* Assignee: 
* Category: 
* Target version: 3.9.x
Dear DragonFlyBSD bugs,

Today I updated the L15 algorithm, available from:


The update is to the KSA (Key Scheduling Algorithm).

Perhaps DragonFlyBSD should consider updating their version,
as used for /dev/urandom ?


Also, I posted a bug report (some months ago now, I suspect),
which had to do with IBAA (as used for /dev/random), and specifically
relating to warming up the CSPRNG just before output in:


As opposed to doing the warm-up after seeding the CSPRNG,
which unless I am mistaken, is what DragonFlyBSD does at the

I think there might also be one other update to L15 which I
mentioned on bugs at dragonflybsd.org quite a while ago, which
I don't think was met with a response. That was to do with the
STATEINDEX_CARRY change that I made to L15.


In any case I am always happy to discuss these issues by E-mail ...

PS Good luck with the new 3.8.0 Release !!


Robin Carey BSc

You have received this notification because you have either subscribed to it, or are involved in it.
To change your notification preferences, please click here: http://bugs.dragonflybsd.org/my/account

More information about the Bugs mailing list