[Cfrg] Second RGLC on "AES-GCM-SIV"

"Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk> Tue, 16 January 2018 16:35 UTC

Return-Path: <Kenny.Paterson@rhul.ac.uk>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10BFC1315E3 for <cfrg@ietfa.amsl.com>; Tue, 16 Jan 2018 08:35:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level:
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=rhul.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MOWtEoOV3olj for <cfrg@ietfa.amsl.com>; Tue, 16 Jan 2018 08:35:01 -0800 (PST)
Received: from EUR02-AM5-obe.outbound.protection.outlook.com (mail-eopbgr00078.outbound.protection.outlook.com [40.107.0.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8D9AF12E035 for <cfrg@irtf.org>; Tue, 16 Jan 2018 08:32:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rhul.onmicrosoft.com; s=selector1-rhul-ac-uk; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=zT26Pt2kgfJKCjnszElPKy2O72RPvuV6bBCh4c/k9cE=; b=HY/aY39kiNVUbIMBqQ9aFZlUCU/ZCqilPTd8SsppFTz5WTT4gYCIgpReuvdklbO2rshcOWTU/AyP5IKYmCc6vUEaldc5hoaxlt6iar/JlgVgL4csx7TYiy0N8jDVa8UK/rGPn6xMs/xV73toIBOyjj4UunmSbUY4kKLljkPeOQc=
Received: from AM4PR0301MB1906.eurprd03.prod.outlook.com (10.168.2.156) by AM4PR0301MB1908.eurprd03.prod.outlook.com (10.168.3.8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.407.7; Tue, 16 Jan 2018 16:32:35 +0000
Received: from AM4PR0301MB1906.eurprd03.prod.outlook.com ([fe80::6159:c0ab:3c77:2083]) by AM4PR0301MB1906.eurprd03.prod.outlook.com ([fe80::6159:c0ab:3c77:2083%13]) with mapi id 15.20.0407.009; Tue, 16 Jan 2018 16:32:35 +0000
From: "Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk>
To: "cfrg@irtf.org" <cfrg@irtf.org>
CC: Alexey Melnikov <alexey.melnikov@isode.com>, Yehuda Lindell <Yehuda.Lindell@biu.ac.il>, Adam Langley <agl@imperialviolet.org>, Shay Gueron <shay.gueron@gmail.com>
Thread-Topic: Second RGLC on "AES-GCM-SIV"
Thread-Index: AQHTjuedRk3NkCRPO0ONUYyfhtg7QA==
Date: Tue, 16 Jan 2018 16:32:35 +0000
Message-ID: <E16F508E-7C08-4DB2-A570-DDACC162F435@rhul.ac.uk>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/f.28.0.171108
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Kenny.Paterson@rhul.ac.uk;
x-originating-ip: [134.219.227.30]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; AM4PR0301MB1908; 7:q1BXvGY0LFLbeiormlnJ8d1xf4CcCZCkQcGpE6MJRrNf+lxEl7xnkvwMSwSsSZOZoY0n9DP++SfkM8IW+/nvsUq/boMXQ9iuVqXNKabtO9iPFJ3daT1J2X7bSaM/8fpdnAP14sNrkx1uRob//I7NelraMni30RPDTI5z3mFPBnPSKjNIG8dnDmt66e9cfmsBDd3+HuSthD6dttxKk6Hg9juiuOfQhOeCY8snEQwwt26MOFg6rBhFd7hwJHW/UCbE
x-ms-exchange-antispam-srfa-diagnostics: SSOS;SSOR;
x-forefront-antispam-report: SFV:SKI; SCL:-1; SFV:NSPM; SFS:(10009020)(376002)(346002)(39380400002)(366004)(396003)(39860400002)(189003)(199004)(14454004)(6916009)(42882006)(8676002)(478600001)(3846002)(6116002)(6306002)(6512007)(6436002)(83716003)(5250100002)(3280700002)(5640700003)(53936002)(786003)(1730700003)(81166006)(99286004)(316002)(97736004)(26005)(2906002)(6486002)(54906003)(72206003)(966005)(5660300001)(58126008)(68736007)(83506002)(8936002)(81156014)(413944005)(6506007)(59450400001)(25786009)(102836004)(7736002)(2351001)(2501003)(105586002)(39060400002)(305945005)(86362001)(66066001)(33656002)(2900100001)(230783001)(74482002)(3660700001)(82746002)(4326008)(36756003)(106356001); DIR:OUT; SFP:1101; SCL:1; SRVR:AM4PR0301MB1908; H:AM4PR0301MB1906.eurprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
x-ms-office365-filtering-correlation-id: 4bac18e6-72bb-41f1-b62d-08d55cfebfe8
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(8989060)(5600026)(4604075)(3008032)(2017052603307)(7153060)(7193020); SRVR:AM4PR0301MB1908;
x-ms-traffictypediagnostic: AM4PR0301MB1908:
x-microsoft-antispam-prvs: <AM4PR0301MB1908DF92AA638D51AD4BDAF2BCEA0@AM4PR0301MB1908.eurprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(120809045254105)(192374486261705);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040470)(2401047)(8121501046)(5005006)(10201501046)(3002001)(93006095)(93001095)(3231023)(944501161)(6041268)(20161123564045)(20161123558120)(201703131423095)(201702281529075)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123562045)(20161123560045)(6072148)(201708071742011); SRVR:AM4PR0301MB1908; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:AM4PR0301MB1908;
x-forefront-prvs: 0554B1F54F
received-spf: None (protection.outlook.com: rhul.ac.uk does not designate permitted sender hosts)
x-microsoft-antispam-message-info: PXenHbnv7gcTzTQTODE8T/oQbO2sLKzIvKxYv1v0p7Flx9FQsVk8b++Z0nhUP5e+GEOCAFW8/vCqzAKFD/V1Mw==
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <69A30979B3F2574A8D520D16967DDFF7@eurprd03.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: rhul.ac.uk
X-MS-Exchange-CrossTenant-Network-Message-Id: 4bac18e6-72bb-41f1-b62d-08d55cfebfe8
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Jan 2018 16:32:35.2691 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2efd699a-1922-4e69-b601-108008d28a2e
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR0301MB1908
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/-RR0N7-j1mg79OWTHKp7fko2k2M>
Subject: [Cfrg] Second RGLC on "AES-GCM-SIV"
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Jan 2018 16:35:08 -0000

Dear CFRG participants,

This message starts a second 2-week RGLC on "AES-GCM-SIV: Nonce Misuse-Resistant Authenticated Encryption" (draft-irtf-cfrg-gcmsiv-07), that will end on January 30th. See https://datatracker.ietf.org/doc/draft-irtf-cfrg-gcmsiv for the latest version of the draft.

We are having a second last call because, although there only were small changes to the draft in going from 06 to 07, we also had the benefit of new security analysis on the draft:

http://www.cs.ucsb.edu/~tessaro/papers/BHT17.pdf

We also had some productive discussion on the benefits of using POLYVAL versus GHASH during the previous last call period, with the thread beginning at:

https://www.ietf.org/mail-archive/web/cfrg/current/msg09333.html


Please send your comments, as well as expression of support to publish as an RFC (or possible reasons for not doing so) in reply to this message or directly to CFRG chairs. Your feedback will help chairs to decide whether the document is ready for review by IRSG and subsequent publication as an RFC.

Thank you,

Alexey and Kenny