[saag] Re: Fwd: New Version Notification for draft-moskowi tz-ads-b-auth-02.txt
John Mattsson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <AS4PR07MB8825DB4770329F7FAC3DEE1789A72@AS4PR07MB8825.eurprd07.prod.outlook.com> |
Hi Bob, (Answering generic as I have not read your draft) There is no practical risk at all from quantum attacks on symmetric cryptography. This is a misconception. https://datatracker.ietf.org/liaison/1942/ >If I drop the MACing You should absolutely not drop MACs. A short authentication tag is much better than no tag at all. >The TESLA MAC is 28 bits. 28 bits is short, but 5G uses 32-bit authentication tags, and I’m not aware of any attacks against them in practice. How problematic or not short tags are depends heavily on the use case. How many forgeries can an attacker send per minute/hour/year/millenia? Does a single successful forgery cause practical problems, or would an attacker need to make several successful forgeries? Do the forgeries need to be sequential? Do forgery result in chosen or random plaintext? Is the risk of forgery larger than e.g., cosmic radiation corrupting data? KMAC is a strong MAC that behaves like an ideal MAC, including reforgeability resistance. >But as the authentication key as from a hash-chain and ONLY used for ~31 messages I don't think this is relevant. The integrity advantage per key is completely irrelevant. Cheers, John Preuß Mattsson _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]