Re: [AVTCORE] [Sframe] [Moq] FW: New Version Notification for draft-mattsson-cfrg-aes-gcm-sst-00.txt

Roman Shpount <[email protected]> Mon, 8 May 2023 17:04:51 -0400
Newsgroups gmane.ietf.irtf.cfrg,gmane.ietf.avt
Message-ID <CAD5OKxuNV1Ho8ayePwMBByWY9ce0f3SWdVe2z+eXOo1RdZnQ+g@mail.gmail.com>
This is extremely interesting. I support adopting this.
_____________
Roman Shpount


On Mon, May 8, 2023 at 12:59 PM Jonathan Lennox <[email protected]>
wrote:

> This is interesting for SRTP as well, so I suggest adding the AVTCore
> mailing list.
>
> > On May 7, 2023, at 2:06 PM, Christian Huitema <[email protected]>
> wrote:
> >
> > John,
> >
> > You should probably send this to the QUIC list as well. Media over QUIC
> is just one application of QUIC. If the "short tags" can save per packet
> overhead while maintaining security properties, then they are interesting
> for many QUIC applications.
> >
> > -- Christian Huitema
> >
> > On 5/5/2023 7:45 AM, John Mattsson wrote:
> >> Hi,
> >> We just submitted draft-mattsson-cfrg-aes-gcm-sst-00. Advanced
> Encryption Standard (AES) with Galois Counter Mode with Secure Short Tags
> (AES-GCM-SST) is very similar to AES-GCM but have short tags with forgery
> probabilities close to ideal. The changes to AES-GCM were suggested by
> Nyberg et al. in 2005 as a comment to NIST and are based on proven
> theoretical constructions.
> >> AES-GCM performance with secure short tags have many applications, one
> of them is media encryption. Audio packets are small, numerous, and
> ephemeral, so on the one hand, they are very sensitive in percentage terms
> to crypto overhead, and on the other hand, forgery of individual packets is
> not a big concern.
> >> Cheers,
> >> John
> >> From: [email protected] <[email protected]>
> >> Date: Friday, 5 May 2023 at 16:33
> >> To: John Mattsson <[email protected]>, Alexander Maximov <
> [email protected]>, John Mattsson <[email protected]>,
> Matt Campagna <[email protected]>, Matthew Campagna <[email protected]
> >
> >> Subject: New Version Notification for
> draft-mattsson-cfrg-aes-gcm-sst-00.txt
> >> A new version of I-D, draft-mattsson-cfrg-aes-gcm-sst-00.txt
> >> has been successfully submitted by John Preuß Mattsson and posted to the
> >> IETF repository.
> >> Name:           draft-mattsson-cfrg-aes-gcm-sst
> >> Revision:       00
> >> Title:          Galois Counter Mode with Secure Short Tags (GCM-SST)
> >> Document date:  2023-05-05
> >> Group:          Individual Submission
> >> Pages:          16
> >> URL:
> https://www.ietf.org/archive/id/draft-mattsson-cfrg-aes-gcm-sst-00.txt
> >> Status:
> https://datatracker.ietf.org/doc/draft-mattsson-cfrg-aes-gcm-sst/
> >> Html:
> https://www.ietf.org/archive/id/draft-mattsson-cfrg-aes-gcm-sst-00.html
> >> Htmlized:
> https://datatracker.ietf.org/doc/html/draft-mattsson-cfrg-aes-gcm-sst
> >> Abstract:
> >>    This document defines the Galois Counter Mode with Secure Short Tags
> >>    (GCM-SST) Authenticated Encryption with Associated Data (AEAD)
> >>    algorithm.  GCM-SST can be used with any keystream generator, not
> >>    just a block cipher.  The main differences compared to GCM [GCM] is
> >>    that GCM-SST uses an additional subkey Q, that fresh subkeys H and Q
> >>    are derived for each nonce, and that the POLYVAL function from AES-
> >>    GCM-SIV is used instead of GHASH.  This enables short tags with
> >>    forgery probabilities close to ideal.  This document also registers
> >>    several instances of Advanced Encryption Standard (AES) with Galois
> >>    Counter Mode with Secure Short Tags (AES-GCM-SST).
> >>    This document is the product of the Crypto Forum Research Group.
> >> The IETF Secretariat
> >
> > --
> > Sframe mailing list
> > [email protected]
> > https://www.ietf.org/mailman/listinfo/sframe
>
> _______________________________________________
> Audio/Video Transport Core Maintenance
> [email protected]
> https://www.ietf.org/mailman/listinfo/avt
>

_______________________________________________
CFRG mailing list
[email protected]
https://www.irtf.org/mailman/listinfo/cfrg