Re: [Cfrg] I-D Action: draft-irtf-cfrg-xchacha-01.txt

"Paterson Kenneth" <> Fri, 26 July 2019 13:04 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id ADAF71202BE for <>; Fri, 26 Jul 2019 06:04:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -6.897
X-Spam-Status: No, score=-6.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id BKYUZ6jMErsV for <>; Fri, 26 Jul 2019 06:04:52 -0700 (PDT)
Received: from ( []) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 1199412021D for <>; Fri, 26 Jul 2019 06:04:51 -0700 (PDT)
Received: from ( by ( with Microsoft SMTP Server (TLS) id 14.3.468.0; Fri, 26 Jul 2019 15:03:36 +0200
Received: from (2001:67c:10ec:5602::26) by (2001:67c:10ec:5603::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1779.2; Fri, 26 Jul 2019 15:03:16 +0200
Received: from ([fe80::7114:d795:2066:d254]) by ([fe80::7114:d795:2066:d254%3]) with mapi id 15.01.1779.004; Fri, 26 Jul 2019 15:03:16 +0200
From: "Paterson Kenneth" <>
To: "" <>
Thread-Topic: [Cfrg] I-D Action: draft-irtf-cfrg-xchacha-01.txt
Thread-Index: AQHVQOvIy9mqNJNlVUGxJ9poC65+kqbc4yIA
Date: Fri, 26 Jul 2019 13:03:16 +0000
Message-ID: <>
References: <>
In-Reply-To: <>
Accept-Language: de-CH, en-US
Content-Language: en-GB
x-originating-ip: []
x-tm-snts-smtp: 05D268D28E238B4A8F99D088184229D15026F4D2191F65BBCBD98A42F37D5A222000:8
Content-Type: text/plain; charset="utf-8"
Content-ID: <>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <>
Subject: Re: [Cfrg] I-D Action: draft-irtf-cfrg-xchacha-01.txt
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 26 Jul 2019 13:04:55 -0000

Dear CFRG,

Chairs would appreciate input on this new draft from the CFRG community. 

Specifically, we are looking for volunteers to read the draft and provide feedback on the list.


Kenny (for the chairs)


-----Original Message-----
From: Cfrg <>; on behalf of ""; <>;
Reply to: ""; <>;
Date: Tuesday, 23 July 2019 at 02:15
To: ""; <>;
Cc: ""; <>;
Subject: [Cfrg] I-D Action: draft-irtf-cfrg-xchacha-01.txt

    A New Internet-Draft is available from the on-line Internet-Drafts directories.
    This draft is a work item of the Crypto Forum RG of the IRTF.
            Title           : XChaCha: eXtended-nonce ChaCha and AEAD_XChaCha20_Poly1305
            Author          : Scott Arciszewski
    	Filename        : draft-irtf-cfrg-xchacha-01.txt
    	Pages           : 18
    	Date            : 2019-07-22
       The eXtended-nonce ChaCha cipher construction (XChaCha) allows for
       ChaCha-based ciphersuites to accept a 192-bit nonce with similar
       guarantees to the original construction, except with a much lower
       probability of nonce misuse occurring.  This helps for long running
       TLS connections.  This also enables XChaCha constructions to be
       stateless, while retaining the same security assumptions as ChaCha.
       This document defines XChaCha20, which uses HChaCha20 to convert the
       key and part of the nonce into a subkey, which is in turn used with
       the remainder of the nonce with ChaCha20 to generate a pseudorandom
       keystream (e.g. for message encryption).
       This document also defines AEAD_XChaCha20_Poly1305, a variant of
       [RFC7539] that utilizes the XChaCha20 construction in place of
    The IETF datatracker status page for this draft is:
    There are also htmlized versions available at:
    A diff from the previous version is available at:
    Please note that it may take a couple of minutes from the time of submission
    until the htmlized version and diff are available at
    Internet-Drafts are also available by anonymous FTP at:
    Cfrg mailing list