FW: New Version Notification for draft-mattsson-cfrg-aes-gcm-sst-01.txt

John Mattsson <[email protected]> Sat, 24 Feb 2024 10:19:14 +0000
Newsgroups gmane.ietf.irtf.cfrg,gmane.ietf.avt
Message-ID <GVXPR07MB967841BBA16AD3A8797C4C3D89542@GVXPR07MB9678.eurprd07.prod.outlook.com>
Hi,

We submitted -01 of Galois Counter Mode with Secure Short Tags (GCM-SST).

Our paper on AES-GCM-SST was accepted to the recent NIST workshop on encryption and presented there.

https://csrc.nist.gov/Events/2023/third-workshop-on-block-cipher-modes-of-operation

https://csrc.nist.gov/csrc/media/Events/2023/third-workshop-on-block-cipher-modes-of-operation/documents/accepted-papers/Galois%20Counter%20Mode%20with%20Secure%20Short%20Tags.pdf

https://csrc.nist.gov/Presentations/2023/galois-counter-mode-with-secure-short-tags

3GPP has started work on standardizing code points for the use of GCM-SST with AES-256 and SNOW 5G in 5G Advance (and very likely 6G). The algorithm specification is already done.

Changes from -00 to -01:

   *  Link to NIST decision to remove support for GCM with tags shorter
      than 96-bits based on Mattsson et al.

   *  Mention that 3GPP 5G Advance will use GCM-SST with AES-256 and
      SNOW 5G.

   *  Corrected reference to step numbers during decryption

   *  Changed T to full_tag to align with tag and expected_tag

   *  Link to images from the NIST encryption workshop illustrating the
      GCM-SST encryption and decryption functions.

   *  Updated definitions

   *  Editorial changes.

We are planning to ask for presentation time in CFRG at IETF in Brisbane. We would be happy to present in some media group as well if there is interest.

Cheers,
John Preuß Mattsson

From: [email protected] <[email protected]>
Date: Saturday, 24 February 2024 at 09:29
To: John Mattsson <[email protected]>, Alexander Maximov <[email protected]>, John Mattsson <[email protected]>, Matt Campagna <[email protected]>, Matthew Campagna <[email protected]>
Subject: New Version Notification for draft-mattsson-cfrg-aes-gcm-sst-01.txt
A new version of Internet-Draft draft-mattsson-cfrg-aes-gcm-sst-01.txt has
been successfully submitted by John Preuß Mattsson and posted to the
IETF repository.

Name:     draft-mattsson-cfrg-aes-gcm-sst
Revision: 01
Title:    Galois Counter Mode with Secure Short Tags (GCM-SST)
Date:     2024-02-24
Group:    Individual Submission
Pages:    18
URL:      https://www.ietf.org/archive/id/draft-mattsson-cfrg-aes-gcm-sst-01.txt
Status:   https://datatracker.ietf.org/doc/draft-mattsson-cfrg-aes-gcm-sst/
HTML:     https://www.ietf.org/archive/id/draft-mattsson-cfrg-aes-gcm-sst-01.html
HTMLized: https://datatracker.ietf.org/doc/html/draft-mattsson-cfrg-aes-gcm-sst
Diff:     https://author-tools.ietf.org/iddiff?url2=draft-mattsson-cfrg-aes-gcm-sst-01

Abstract:

   This document defines the Galois Counter Mode with Secure Short Tags
   (GCM-SST) Authenticated Encryption with Associated Data (AEAD)
   algorithm.  GCM-SST can be used with any keystream generator, not
   just a block cipher.  The main differences compared to GCM [GCM] is
   that GCM-SST uses an additional subkey Q, that fresh subkeys H and Q
   are derived for each nonce, and that the POLYVAL function from AES-
   GCM-SIV is used instead of GHASH.  This enables short tags with
   forgery probabilities close to ideal.  This document also registers
   several instances of Advanced Encryption Standard (AES) with Galois
   Counter Mode with Secure Short Tags (AES-GCM-SST).

   This document is the product of the Crypto Forum Research Group.



The IETF Secretariat

_______________________________________________
CFRG mailing list
[email protected]
https://mailman.irtf.org/mailman/listinfo/cfrg