Re: aes/gcm maximum plaintext size; handling of large files
Jeffrey Walton <[email protected]> Wed, 13 Aug 2025 06:45:53 -0400
| Newsgroups | gmane.comp.encryption.cryptopp |
|---|---|
| Message-ID | <CAH8yC8=aTnOxAvMWbOOFto2RnUtqPecxTW_k-=mBNaXLt8Mq1A@mail.gmail.com> |
--0000000000009168b4063c3cdea3 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Tue, Aug 12, 2025 at 5:07=E2=80=AFPM Lana Deere <[email protected]> w= rote: > On Tuesday, August 12, 2025 at 8:10:03=E2=80=AFAM UTC-4 Jeffrey Walton wr= ote: > > GCM plaintext maximum length is specified in bits, not bytes. See > SP800-39D, Section 5.2.1.1 Input Data, p. 8, < > https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d= .pdf>. > That leads to: > > 2^39 - 256 =3D 549755813632 > 549755813632 / 8 =3D 68719476704 > > > Is there a standard practice for handling AES encryption of large files? > E.g., create a new IV and resume encryption? Use something other than GC= M > which has a higher limit? > The limit you are encountering in GCM mode is due to an internal 32-bit counter. The limit is not directly due to AES. You could use a block cipher and mode of operation with a 64-bit counter, or a stream cipher with a 64-bit counter. Bernstein's original ChaCha20 has an internal 64-bit counter. So Bernstein's ChaCha20 paired with Poly1305 could be a good replacement for you. See < https://www.cryptopp.com/wiki/ChaCha20>. The IETF's version of ChaCha20 used in TLS regresses to a 32-bit counter, so don't use it. Jeff --=20 You received this message because you are subscribed to the Google Groups "= Crypto++ Users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/cryptopp-us= ers/CAH8yC8%3DaTnOxAvMWbOOFto2RnUtqPecxTW_k-%3DmBNaXLt8Mq1A%40mail.gmail.co= m. --0000000000009168b4063c3cdea3 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Aug 12,= 2025 at 5:07=E2=80=AFPM Lana Deere <<a href=3D"mailto:lana.deere@gmail.= com">[email protected]</a>> wrote:<br></div><blockquote class=3D"gmai= l_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,20= 4,204);padding-left:1ex"><div><div dir=3D"auto">On Tuesday, August 12, 2025= at 8:10:03=E2=80=AFAM UTC-4 Jeffrey Walton wrote:<br></div><blockquote sty= le=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddi= ng-left:1ex"><div dir=3D"ltr"><div><div>GCM plaintext maximum length is spe= cified in bits, not bytes. See SP800-39D, Section 5.2.1.1 Input Data, p. 8,= <<a href=3D"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpubl= ication800-38d.pdf" rel=3D"nofollow" target=3D"_blank">https://nvlpubs.nist= .gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf</a>>. That lea= ds to:</div><div><br></div><div>=C2=A0 =C2=A0 2^39 - 256 =3D=C2=A0<span>549= 755813632</span></div><div><span>=C2=A0 =C2=A0 549755813632 / 8 =3D=C2=A0</= span><span>68719476704</span></div></div></div></blockquote><div><br></div>= <div>Is there a standard practice for handling AES encryption of large file= s?=C2=A0 E.g., create a new IV and resume encryption?=C2=A0 Use something o= ther than GCM which has a higher limit?</div></div></blockquote><div><br></= div><div>The limit you are encountering in GCM mode is due to an internal 3= 2-bit counter. The limit is not directly due to AES.</div><div><br></div><d= iv>You could use a block cipher and mode of operation with a 64-bit counter= , or a stream cipher with a 64-bit counter. Bernstein's original ChaCha= 20 has an internal 64-bit counter. So Bernstein's ChaCha20 paired with = Poly1305 could be a good replacement for you. See <<a href=3D"https://ww= w.cryptopp.com/wiki/ChaCha20">https://www.cryptopp.com/wiki/ChaCha20</a>>= ;.</div><div><br></div><div>The IETF's version of ChaCha20 used in TLS = regresses to a 32-bit counter, so don't use it.</div><div><br></div><di= v>Jeff</div></div></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;Crypto++ Users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">cryp= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/d/msgid/= cryptopp-users/CAH8yC8%3DaTnOxAvMWbOOFto2RnUtqPecxTW_k-%3DmBNaXLt8Mq1A%40ma= il.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.= com/d/msgid/cryptopp-users/CAH8yC8%3DaTnOxAvMWbOOFto2RnUtqPecxTW_k-%3DmBNaX= Lt8Mq1A%40mail.gmail.com</a>.<br /> --0000000000009168b4063c3cdea3--