Re: [AVTCORE] [Sframe] [Moq] FW: New Version Notification for draft-mattsson-cfrg-aes-gcm-sst-00.txt
Roman Shpount <[email protected]> Mon, 8 May 2023 17:04:51 -0400
| Newsgroups | gmane.ietf.irtf.cfrg,gmane.ietf.avt |
|---|---|
| Message-ID | <CAD5OKxuNV1Ho8ayePwMBByWY9ce0f3SWdVe2z+eXOo1RdZnQ+g@mail.gmail.com> |
This is extremely interesting. I support adopting this. _____________ Roman Shpount On Mon, May 8, 2023 at 12:59 PM Jonathan Lennox <[email protected]> wrote: > This is interesting for SRTP as well, so I suggest adding the AVTCore > mailing list. > > > On May 7, 2023, at 2:06 PM, Christian Huitema <[email protected]> > wrote: > > > > John, > > > > You should probably send this to the QUIC list as well. Media over QUIC > is just one application of QUIC. If the "short tags" can save per packet > overhead while maintaining security properties, then they are interesting > for many QUIC applications. > > > > -- Christian Huitema > > > > On 5/5/2023 7:45 AM, John Mattsson wrote: > >> Hi, > >> We just submitted draft-mattsson-cfrg-aes-gcm-sst-00. Advanced > Encryption Standard (AES) with Galois Counter Mode with Secure Short Tags > (AES-GCM-SST) is very similar to AES-GCM but have short tags with forgery > probabilities close to ideal. The changes to AES-GCM were suggested by > Nyberg et al. in 2005 as a comment to NIST and are based on proven > theoretical constructions. > >> AES-GCM performance with secure short tags have many applications, one > of them is media encryption. Audio packets are small, numerous, and > ephemeral, so on the one hand, they are very sensitive in percentage terms > to crypto overhead, and on the other hand, forgery of individual packets is > not a big concern. > >> Cheers, > >> John > >> From: [email protected] <[email protected]> > >> Date: Friday, 5 May 2023 at 16:33 > >> To: John Mattsson <[email protected]>, Alexander Maximov < > [email protected]>, John Mattsson <[email protected]>, > Matt Campagna <[email protected]>, Matthew Campagna <[email protected] > > > >> Subject: New Version Notification for > draft-mattsson-cfrg-aes-gcm-sst-00.txt > >> A new version of I-D, draft-mattsson-cfrg-aes-gcm-sst-00.txt > >> has been successfully submitted by John Preuß Mattsson and posted to the > >> IETF repository. > >> Name: draft-mattsson-cfrg-aes-gcm-sst > >> Revision: 00 > >> Title: Galois Counter Mode with Secure Short Tags (GCM-SST) > >> Document date: 2023-05-05 > >> Group: Individual Submission > >> Pages: 16 > >> URL: > https://www.ietf.org/archive/id/draft-mattsson-cfrg-aes-gcm-sst-00.txt > >> Status: > https://datatracker.ietf.org/doc/draft-mattsson-cfrg-aes-gcm-sst/ > >> Html: > https://www.ietf.org/archive/id/draft-mattsson-cfrg-aes-gcm-sst-00.html > >> Htmlized: > https://datatracker.ietf.org/doc/html/draft-mattsson-cfrg-aes-gcm-sst > >> Abstract: > >> This document defines the Galois Counter Mode with Secure Short Tags > >> (GCM-SST) Authenticated Encryption with Associated Data (AEAD) > >> algorithm. GCM-SST can be used with any keystream generator, not > >> just a block cipher. The main differences compared to GCM [GCM] is > >> that GCM-SST uses an additional subkey Q, that fresh subkeys H and Q > >> are derived for each nonce, and that the POLYVAL function from AES- > >> GCM-SIV is used instead of GHASH. This enables short tags with > >> forgery probabilities close to ideal. This document also registers > >> several instances of Advanced Encryption Standard (AES) with Galois > >> Counter Mode with Secure Short Tags (AES-GCM-SST). > >> This document is the product of the Crypto Forum Research Group. > >> The IETF Secretariat > > > > -- > > Sframe mailing list > > [email protected] > > https://www.ietf.org/mailman/listinfo/sframe > > _______________________________________________ > Audio/Video Transport Core Maintenance > [email protected] > https://www.ietf.org/mailman/listinfo/avt > _______________________________________________ CFRG mailing list [email protected] https://www.irtf.org/mailman/listinfo/cfrg