[saag] Re: Fwd: New Version Notification for draft-moskowi tz-ads-b-auth-02.txt

Robert Moskowitz <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Thanks John!

On the strength of this, which backs what I have seen elsewhere, I am 
going to drop TESLA keys larger that 128 bits.  Still have a discussion 
about this in Security Considerations.

With each key only valid for a 5 second interval and channel limitations 
of 6.2 msg/sec (and short burst mode at 7 msg/sec, easy to overwhelm the 
channel if more is done), a symmetric key attack is too much of a moving 
target.  We MAY increase the interval to 10s, but probably not.

Bob

On 8/17/26 6:23 AM, John Mattsson wrote:
> Hi Bob,
>
> (Answering generic as I have not read your draft)
>
> There is no practical risk at all from quantum attacks on symmetric 
> cryptography. This is a misconception.
> https://datatracker.ietf.org/liaison/1942/
>
> >If I drop the MACing
>
> You should absolutely not drop MACs. A short authentication tag is 
> /much/​ better than no tag at all.
>
> >The TESLA MAC is 28 bits.
>
> 28 bits is short, but 5G uses 32-bit authentication tags, and I’m not 
> aware of any attacks against them in practice. How problematic or not 
> short tags are depends heavily on the use case. How many forgeries can 
> an attacker send per minute/hour/year/millenia? Does a single 
> successful forgery cause practical problems, or would an attacker need 
> to make several successful forgeries? Do the forgeries need to be 
> sequential? Do forgery result in chosen or random plaintext? Is the 
> risk of forgery larger than e.g., cosmic radiation corrupting data?
>
> KMAC is a strong MAC that behaves like an ideal MAC, including 
> reforgeability resistance.
>
> >But as the authentication key as from a hash-chain and ONLY used for 
> ~31 messages
>
> I don't think this is relevant. The integrity advantage per key is 
> completely irrelevant.
>
> Cheers,
> John Preuß Mattsson
>
> _______________________________________________
> saag mailing list [email protected]
> To unsubscribe send an email [email protected]

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.