[TLS] Re: Aes cipher

Loganaden Velvindron <[email protected]> Wed, 29 Jul 2026 14:42:11 +0400
Newsgroups gmane.ietf.tls
Message-ID <CAOp4FwTLOmW9NYOhuWtOLgyrKF1vmhx7ohmwOD=8xdx_VqnX+A@mail.gmail.com>
--===============6123426980745771625==
Content-Type: multipart/alternative; boundary="0000000000004f4d510657bd9c03"

--0000000000004f4d510657bd9c03
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Wed, 29 Jul 2026, 13:08 John Mattsson, <[email protected]>
wrote:

> Hi Loganaden,
>
> I think there is a significant difference between non-standardized
> asymmetric cryptography based on new hardness assumptions such as LIP and
> widely-deployed standardized symmetric cryptography. So far, AI has broke=
n
> HAWK, but that is not more impressive than the human attacks on SIKE,
> Rainbow, and the Hedge attacks on multivariate quadratic (MQ) schemes, et=
c.
> Of course, this could change in the future as AI capabilities improve.
>
> For encryption, TLS 1.3 already supports AES- and ChaCha20-based cipher
> suites, which rely on quite different constructions. The main
>
How about we make chacha20 a "must" ?

> concern with TLS 1.3 is that it (ignoring regional algorithms) relies
> entirely on SHA-2 for its key schedule. This will hopefully be addressed =
by
> standardizing a way for TLS 1.3 to use a Keccak-based deck function inste=
ad
> of SHA-2/HMAC/HKDF. I think this should be a priority. In the future I al=
so
> think that Keccak based cipher suites should be added.
>
> For key exchange, the only standardized quantum-resistant algorithm
> currently available is ML-KEM. I think TLS 1.3 should standardize support
> for HQC-KEM as soon as possible, but this will need to wait until the
> publication of FIPS 207. Other structured lattice algorithms like NTRU,
> NTRU+, NTRU Prime, Saber, Dawn, Bat does not add
>
SNtru prime seems to have been well deployed and has survived many reviews
and audits.

There is a draft by Simon Josefsson for ntru prime as well.



much diversity, but Dawn/Bat could be useful as more lightweight algorithms=
.
> Cheers,
> John Preu=C3=9F Mattsson
>
> *From: *Loganaden Velvindron <[email protected]>
> *Date: *Wednesday, 29 July 2026 at 10:42
> *To: *
> <[email protected]>
> *Subject: *[TLS] Aes cipher
>
> After reading
> https://www.anthropic.com/research/discovering-cryptographic-weaknesses,
>
> I would like to know whether we should look at having more diversity for
> tls 1.3 ciphers ?
>
>
>

--0000000000004f4d510657bd9c03
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div><br><br><div class=3D"gmail_quote gmail_quote_contai=
ner"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, 29 Jul 2026, 13:08 John =
Mattsson, &lt;<a href=3D"mailto:[email protected]">john.mattsson@e=
ricsson.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div>
<div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo=
nt-size:12pt;color:rgb(0,0,0)">
Hi Loganaden,</div>
<p style=3D"direction:ltr;text-align:left;text-indent:0px;text-transform:no=
ne">
<span style=3D"font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;=
color:rgb(0,0,0)">I think there is a significant difference between non-sta=
ndardized asymmetric cryptography based on new hardness assumptions such as=
 LIP and widely-deployed
 standardized symmetric cryptography. So far, AI has broken HAWK, but that =
is not more impressive than the human attacks on SIKE, Rainbow, and the Hed=
ge attacks on multivariate quadratic (MQ) schemes, etc. Of course, this cou=
ld change in the future as AI capabilities
 improve.</span></p>
<p style=3D"text-align:left;text-indent:0px"><span style=3D"font-size:16px"=
>For encryption, TLS 1.3 already supports AES- and ChaCha20-based cipher su=
ites, which rely on quite different constructions. The main</span></p></div=
></blockquote></div></div><div dir=3D"auto">How about we make chacha20 a &q=
uot;must&quot; ?</div><div dir=3D"auto"><div class=3D"gmail_quote gmail_quo=
te_container"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;=
border-left:1px #ccc solid;padding-left:1ex"><div><p style=3D"text-align:le=
ft;text-indent:0px"><span style=3D"font-size:16px"> concern with TLS 1.3 is
 that it (ignoring regional algorithms) relies entirely on SHA-2 for its ke=
y schedule. This will hopefully be addressed by standardizing a way for TLS=
 1.3 to use a Keccak-based deck function instead of SHA-2/HMAC/HKDF. I thin=
k this should be a priority. In
 the future I also </span>think<span style=3D"font-size:16px">=C2=A0that Ke=
ccak based cipher suites should be added.</span></p>
<p style=3D"text-align:left;text-indent:0px"><span style=3D"font-size:16px"=
>For key exchange, the only standardized quantum-resistant algorithm curren=
tly available is ML-KEM. I think TLS 1.3 should standardize support for HQC=
-KEM as
 soon as possible, but this will need to wait until the publication of FIPS=
 207. Other structured lattice algorithms like NTRU, NTRU+, NTRU Prime, Sab=
er,
</span>Dawn, Bat=C2=A0does not add</p></div></blockquote></div></div><div d=
ir=3D"auto">SNtru prime seems to have been well deployed and has survived m=
any reviews and audits.</div><div dir=3D"auto"><br></div><div dir=3D"auto">=
There is a draft by Simon Josefsson for ntru prime as well.=C2=A0</div><div=
 dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br><=
/div><div dir=3D"auto"><div class=3D"gmail_quote gmail_quote_container"><bl=
ockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #=
ccc solid;padding-left:1ex"><div><p style=3D"text-align:left;text-indent:0p=
x"> much diversity, but Dawn/Bat could be useful as more lightweight algori=
thms.</p>
<div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo=
nt-size:12pt;color:rgb(0,0,0)">
Cheers,</div>
<div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo=
nt-size:12pt;color:rgb(0,0,0)">
John Preu=C3=9F Mattsson</div>
<div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo=
nt-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style=3D"padding:3pt 0in 0in;border-width:1pt medium medium;border-sty=
le:solid none none;border-color:rgb(181,196,223) currentcolor currentcolor"=
>
<div style=3D"text-align:left;font-family:Aptos;font-size:12pt;color:black"=
>
<b>From: </b>Loganaden Velvindron &lt;<a href=3D"mailto:[email protected]=
" target=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt;<br>
<b>Date: </b>Wednesday, 29 July 2026 at 10:42<br>
<b>To: </b>=C2=A0<u></u>
<div style=3D"text-align:left">&lt;<a href=3D"mailto:[email protected]" target=
=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt;<br>
<b>Subject: </b>[TLS] Aes cipher<br>
<br>
</div>
<u></u></div>
</div>
<div id=3D"m_-5217991603687314613mail-editor-reference-message-container">
<div style=3D"direction:ltr">
After reading <a href=3D"https://www.anthropic.com/research/discovering-cry=
ptographic-weaknesses" rel=3D"noreferrer noreferrer" target=3D"_blank">
https://www.anthropic.com/research/discovering-cryptographic-weaknesses</a>=
,=C2=A0=C2=A0</div>
<div style=3D"direction:ltr">
<br>
</div>
<div style=3D"direction:ltr">
I would like to know whether we should look at having more diversity for tl=
s 1.3 ciphers ?</div>
<div style=3D"direction:ltr">
<br>
</div>
<div style=3D"direction:ltr">
<br>
</div>
</div>
</div>

</blockquote></div></div></div>

--0000000000004f4d510657bd9c03--


--===============6123426980745771625==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK

--===============6123426980745771625==--