Common cryptographic algorithms used in PFC

---
MD4
---
MD4 (Message Digest 4) is a hash function designed by Ronald Rivest
 [1990/1991].
It's a 128bit hash function (message digest) having 3(x16) rounds.

Best known attacks on MD4:
 Collision found for its full 3 rounds requiring 2^22 complexity
  [Hans Dobbertin a German cryptographer, fall of 1995]
 Collision found for its full 3 rounds requiring 2^8 complexity
  [Wang et al., 2005]
 Pres func attack requiring 2^64 [Guo, Ling, Rechberger, Wang, 2010]
 Preimage attack requiring 2^97 time [Guo, Ling, Rechberger, Wang, 2010]
  using pre-compute, can be reduced to be 2^70.4 time
 2nd preimage attack (using pre-compute) requiring 2^64 time
  [Guo, Ling, Rechberger, Wang, 2010]

Unbroken status: broken.

Requirements:
Limitations: max message length is (2^64) -1 bits

---
SHA-256
---
SHA-256 is 256bit hash function designed by NSA & published by NIST [2000].
It's a hash function with 512bit block size & 64 steps. Along with SHA-384,
SHA-512, & later SHA-224, they are known collectively as SHA-2. Along with
RIPEMD160 & Whirlpool, they are the remaining unbroken hash functions as of 2015.

Best known attacks on SHA-256:
 Collision attack on 24 steps requiring 2^28.5 calls
  [Indesteege et al., 2008]
 Preimage attack on 42 steps requiring 2^248.4 time & 2^12 mem
  [Guo, Matusiewicz, 2009]
 Preimage attack on 43 steps requiring 2^254.9 time
  [Aoki, Guo, Matusiewicz, Sasaki, Wang, et al., 2009]
 Higher-order differential attack on 46 steps of pres func requiring
  < 2^46 pres func evals [Lamberger, Mendel, 2011]
 ? attack on 52 steps [?, ?]

IP status: standard.
Unbroken status: as of 2015, 15 years.

Requirements:
Limitations: max message length is (2^128) -1 bits

---
SHA-512
---
SHA-512 is 512bit hash function designed by NSA & published by NIST [2000].
It's a hash function with 1,024bit block size & 80 steps. Along with SHA-256,
SHA-384, & later SHA-224, they are known collectively as SHA-2. Along with
RIPEMD160 & Whirlpool, they are the remaining unbroken hash functions as 2010.

Best known attacks on SHA-512:
 Collision attack on 24 steps requiring 2^32.5 calls [Sanadhya, Sarkar, 2008].
 Preimage attack on 42 steps requiring 2^494.6 time & 2^22 mem
  [Guo, Ling, Rechberger, Wang, 2010].
 Preimage attack on 46 steps requiring 2^511.5 pres func & (2^3)10 words
  mem [Yu, Lei, Aoki, 2009].
 ? attack on 57 steps [?, ?]

IP status: standard.
Unbroken status: as of 2015, 15 years.

Requirements:
Limitations: max message length is (2^64) -1 bits

---
Whirlpool
---
Whirlpool is a hash function designed by Paulo S.L.M. Barreto & Vincent Rijmen
 [2000].
It's a 512bit hash function (message digest) having 10 rounds.
It's a submission to NESSIE process, tweaked two times during NESSIE process,
 and chosen by NESSIE [2003].

Best known attack on W block cipher is
 key recovery attack on 7 of 10 rounds requiring 2^512 Sbox lookups,
  2^128 space, & O(2^512) plaintexts [by authors themselves].
  = effort to find preimage & 2nd preimage, > effort to find collision
  using birthday paradox.
Best known attacks on Whirlpool are
 rebound attack on 4.5 round [?, 2009]
 collision on 5.5 round requiring 2^(184-n) complexity & 2^(n) mem,
  (n=0-64) [Lamberger et al., 2010]
 near-collision on 7.5 round requiring 2^(192-n) complexity & 2^(n) mem,
  (n=0-64) [Lamberger et al., 2010]
 semi-free-start near-collision on 9.5 pres func round
  [Lamberger et al., 2010]
 chosen-key distinguisher on 10 round [Lamberger et al., 2010]

Unbroken status: as of 2015, 12-15 years.

Requirements: ~8kb static mem for tables.
Limitations: message length must be < 2^256 bits
 but note that WE implementation is 'only' < 2^128 bits

---
HMAC
---
HMAC is a Hash-based keyed Message Authentication Code by Hugo Krawczyk,
 Mihir Bellare, & R. Canneti [1996].

Limitations:
 Max key size for HMAC is the block size of hash function used
  (ex: MD4/MD5/SHA-1/SHA-256 has 512bit block, thus max key size is 512bit,
       SHA-512 has 1024bit block, thus max key is 1024bit)
  If the key is larger, HMAC will simply hash it & treats the hash as the key.
 Truncated output size should be at least 80bit or half of original hash size.

---
PbKDF2
---
PbKDF2 is Password-based Key Derivation Function 2 from PKCS #5 v2.0 by
 Burt Kaliski /RSA Labs [2000], supporting salt, iterations, and variable
 output. It uses HMAC as its PRF (thus it also use a hash function).
The construction of the function F in PbKDF2 follows a "belt-and-suspenders"
 approach. The iterated U_i are computed recursively to remove a degree of
 parallelism from an opponent; they are exclusive-ored together to reduce
 concerns about the recursion degenerating into a small set of values.

IP status: not patented.

Limitations: input/output larger than underlying hash size doesn't give more
 strength.

---
CFB
---
CFB (Cipher FeedBack) is one of operation modes for block cipher recommended
 by NIST USA.
This mode turns the block cipher into self-synchronizing stream cipher, and
 thus lie in the same group with CTR and OFB modes where they only require
 the encryption (forward) function of the block cipher.
What is used in PFC is actually CFB128: the whole previous ciphertext (128bit)
 becomes the feedback for encrypting current plaintext.

Limitations: as with any block cipher mode, any given key shouldn't be allowed
 to encrypt > 2^64 blocks to avoid collision attacks.

End.