[noise] KDF, part 9281274

Rhys Weatherley rhys.weatherley at gmail.com
Fri Apr 22 13:15:19 PDT 2016


On Sat, Apr 23, 2016 at 1:18 AM, Jason A. Donenfeld <Jason at zx2c4.com> wrote:

> What precisely prevents you from using these?
>

Embedded systems.  The state and stack sizes of BLAKE2b and SHA512 may put
too much pressure on the RAM size of low-end devices in software
implementations.

Some embedded chips have hardware support for SHA256 and HMAC-SHA256 now
which reduces memory pressure, but SHA512 hardware support is non-existent
in this space.

I'd prefer to keep BLAKE2s and SHA256 as an option.

Cheers,

Rhys.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20160423/4e75c0f1/attachment.html>


More information about the Noise mailing list