[saag] Re: Fwd: New Version Notification for draft-moskowi tz-ads-b-auth-02.txt

John Mattsson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <AS4PR07MB8825DB4770329F7FAC3DEE1789A72@AS4PR07MB8825.eurprd07.prod.outlook.com>
Hi Bob,

(Answering generic as I have not read your draft)

There is no practical risk at all from quantum attacks on symmetric cryptography. This is a misconception.
https://datatracker.ietf.org/liaison/1942/

>If I drop the MACing

You should absolutely not drop MACs. A short authentication tag is much​ better than no tag at all.

>The TESLA MAC is 28 bits.

28 bits is short, but 5G uses 32-bit authentication tags, and I’m not aware of any attacks against them in practice. How problematic or not short tags are depends heavily on the use case. How many forgeries can an attacker send per minute/hour/year/millenia? Does a single successful forgery cause practical problems, or would an attacker need to make several successful forgeries? Do the forgeries need to be sequential? Do forgery result in chosen or random plaintext? Is the risk of forgery larger than e.g., cosmic radiation corrupting data?

KMAC is a strong MAC that behaves like an ideal MAC, including reforgeability resistance.

>But as the authentication key as from a hash-chain and ONLY used for ~31 messages

I don't think this is relevant. The integrity advantage per key is completely irrelevant.

Cheers,
John Preuß Mattsson

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.