[TLS] Re: Aes cipher
Loganaden Velvindron <[email protected]> Wed, 29 Jul 2026 14:42:11 +0400
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <CAOp4FwTLOmW9NYOhuWtOLgyrKF1vmhx7ohmwOD=8xdx_VqnX+A@mail.gmail.com> |
--===============6123426980745771625== Content-Type: multipart/alternative; boundary="0000000000004f4d510657bd9c03" --0000000000004f4d510657bd9c03 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Wed, 29 Jul 2026, 13:08 John Mattsson, <[email protected]> wrote: > Hi Loganaden, > > I think there is a significant difference between non-standardized > asymmetric cryptography based on new hardness assumptions such as LIP and > widely-deployed standardized symmetric cryptography. So far, AI has broke= n > HAWK, but that is not more impressive than the human attacks on SIKE, > Rainbow, and the Hedge attacks on multivariate quadratic (MQ) schemes, et= c. > Of course, this could change in the future as AI capabilities improve. > > For encryption, TLS 1.3 already supports AES- and ChaCha20-based cipher > suites, which rely on quite different constructions. The main > How about we make chacha20 a "must" ? > concern with TLS 1.3 is that it (ignoring regional algorithms) relies > entirely on SHA-2 for its key schedule. This will hopefully be addressed = by > standardizing a way for TLS 1.3 to use a Keccak-based deck function inste= ad > of SHA-2/HMAC/HKDF. I think this should be a priority. In the future I al= so > think that Keccak based cipher suites should be added. > > For key exchange, the only standardized quantum-resistant algorithm > currently available is ML-KEM. I think TLS 1.3 should standardize support > for HQC-KEM as soon as possible, but this will need to wait until the > publication of FIPS 207. Other structured lattice algorithms like NTRU, > NTRU+, NTRU Prime, Saber, Dawn, Bat does not add > SNtru prime seems to have been well deployed and has survived many reviews and audits. There is a draft by Simon Josefsson for ntru prime as well. much diversity, but Dawn/Bat could be useful as more lightweight algorithms= . > Cheers, > John Preu=C3=9F Mattsson > > *From: *Loganaden Velvindron <[email protected]> > *Date: *Wednesday, 29 July 2026 at 10:42 > *To: * > <[email protected]> > *Subject: *[TLS] Aes cipher > > After reading > https://www.anthropic.com/research/discovering-cryptographic-weaknesses, > > I would like to know whether we should look at having more diversity for > tls 1.3 ciphers ? > > > --0000000000004f4d510657bd9c03 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div><br><br><div class=3D"gmail_quote gmail_quote_contai= ner"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, 29 Jul 2026, 13:08 John = Mattsson, <<a href=3D"mailto:[email protected]">john.mattsson@e= ricsson.com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style= =3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> <div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> Hi Loganaden,</div> <p style=3D"direction:ltr;text-align:left;text-indent:0px;text-transform:no= ne"> <span style=3D"font-family:Aptos,Arial,Helvetica,sans-serif;font-size:12pt;= color:rgb(0,0,0)">I think there is a significant difference between non-sta= ndardized asymmetric cryptography based on new hardness assumptions such as= LIP and widely-deployed standardized symmetric cryptography. So far, AI has broken HAWK, but that = is not more impressive than the human attacks on SIKE, Rainbow, and the Hed= ge attacks on multivariate quadratic (MQ) schemes, etc. Of course, this cou= ld change in the future as AI capabilities improve.</span></p> <p style=3D"text-align:left;text-indent:0px"><span style=3D"font-size:16px"= >For encryption, TLS 1.3 already supports AES- and ChaCha20-based cipher su= ites, which rely on quite different constructions. The main</span></p></div= ></blockquote></div></div><div dir=3D"auto">How about we make chacha20 a &q= uot;must" ?</div><div dir=3D"auto"><div class=3D"gmail_quote gmail_quo= te_container"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;= border-left:1px #ccc solid;padding-left:1ex"><div><p style=3D"text-align:le= ft;text-indent:0px"><span style=3D"font-size:16px"> concern with TLS 1.3 is that it (ignoring regional algorithms) relies entirely on SHA-2 for its ke= y schedule. This will hopefully be addressed by standardizing a way for TLS= 1.3 to use a Keccak-based deck function instead of SHA-2/HMAC/HKDF. I thin= k this should be a priority. In the future I also </span>think<span style=3D"font-size:16px">=C2=A0that Ke= ccak based cipher suites should be added.</span></p> <p style=3D"text-align:left;text-indent:0px"><span style=3D"font-size:16px"= >For key exchange, the only standardized quantum-resistant algorithm curren= tly available is ML-KEM. I think TLS 1.3 should standardize support for HQC= -KEM as soon as possible, but this will need to wait until the publication of FIPS= 207. Other structured lattice algorithms like NTRU, NTRU+, NTRU Prime, Sab= er, </span>Dawn, Bat=C2=A0does not add</p></div></blockquote></div></div><div d= ir=3D"auto">SNtru prime seems to have been well deployed and has survived m= any reviews and audits.</div><div dir=3D"auto"><br></div><div dir=3D"auto">= There is a draft by Simon Josefsson for ntru prime as well.=C2=A0</div><div= dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><br><= /div><div dir=3D"auto"><div class=3D"gmail_quote gmail_quote_container"><bl= ockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #= ccc solid;padding-left:1ex"><div><p style=3D"text-align:left;text-indent:0p= x"> much diversity, but Dawn/Bat could be useful as more lightweight algori= thms.</p> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> Cheers,</div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> John Preu=C3=9F Mattsson</div> <div style=3D"direction:ltr;font-family:Aptos,Arial,Helvetica,sans-serif;fo= nt-size:12pt;color:rgb(0,0,0)"> <br> </div> <div style=3D"padding:3pt 0in 0in;border-width:1pt medium medium;border-sty= le:solid none none;border-color:rgb(181,196,223) currentcolor currentcolor"= > <div style=3D"text-align:left;font-family:Aptos;font-size:12pt;color:black"= > <b>From: </b>Loganaden Velvindron <<a href=3D"mailto:[email protected]= " target=3D"_blank" rel=3D"noreferrer">[email protected]</a>><br> <b>Date: </b>Wednesday, 29 July 2026 at 10:42<br> <b>To: </b>=C2=A0<u></u> <div style=3D"text-align:left"><<a href=3D"mailto:[email protected]" target= =3D"_blank" rel=3D"noreferrer">[email protected]</a>><br> <b>Subject: </b>[TLS] Aes cipher<br> <br> </div> <u></u></div> </div> <div id=3D"m_-5217991603687314613mail-editor-reference-message-container"> <div style=3D"direction:ltr"> After reading <a href=3D"https://www.anthropic.com/research/discovering-cry= ptographic-weaknesses" rel=3D"noreferrer noreferrer" target=3D"_blank"> https://www.anthropic.com/research/discovering-cryptographic-weaknesses</a>= ,=C2=A0=C2=A0</div> <div style=3D"direction:ltr"> <br> </div> <div style=3D"direction:ltr"> I would like to know whether we should look at having more diversity for tl= s 1.3 ciphers ?</div> <div style=3D"direction:ltr"> <br> </div> <div style=3D"direction:ltr"> <br> </div> </div> </div> </blockquote></div></div></div> --0000000000004f4d510657bd9c03-- --===============6123426980745771625== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0 bHMtbGVhdmVAaWV0Zi5vcmcK --===============6123426980745771625==--