Re: [Cfrg] What are the goals of the AEAD bakeoff?

"Blumenthal, Uri - 0553 - MITLL" <> Mon, 22 June 2020 16:33 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 848D53A0F78 for <>; Mon, 22 Jun 2020 09:33:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.894
X-Spam-Status: No, score=-1.894 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id H9gZbo9elvn8 for <>; Mon, 22 Jun 2020 09:33:26 -0700 (PDT)
Received: from (LLMX3.LL.MIT.EDU []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 7FDF03A0F74 for <>; Mon, 22 Jun 2020 09:33:26 -0700 (PDT)
Received: from ( by (unknown) with ESMTPS id 05MGXLCJ013367; Mon, 22 Jun 2020 12:33:21 -0400
From: "Blumenthal, Uri - 0553 - MITLL" <>
To: Dmitry Belyavsky <>, Paul Grubbs <>
Thread-Topic: [Cfrg] What are the goals of the AEAD bakeoff?
Thread-Index: AQHWR/5ennqSqGghnkSlJA+uwd9mqajjhdEAgAGKZYCAAACcAP//xN4A
Date: Mon, 22 Jun 2020 16:33:20 +0000
Message-ID: <>
References: <> <> <> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
user-agent: Microsoft-MacOutlook/16.37.20051002
x-originating-ip: []
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha256; boundary="B_3675674000_1910459222"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.216, 18.0.687 definitions=2020-06-22_09:2020-06-22, 2020-06-22 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-2004280000 definitions=main-2006220118
Archived-At: <>
Subject: Re: [Cfrg] What are the goals of the AEAD bakeoff?
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 22 Jun 2020 16:33:29 -0000

Do we really need competition instead of classification?


IMHO, no we don’t.



On Mon, Jun 22, 2020 at 7:03 PM Paul Grubbs <> wrote:

I agree that there are a lot of potentially important goals, and that more clarity is needed before choosing design targets. This seems like a good use case for a multi-round competition: in the first round, people can propose design goals, then the CFRG can select a few goals for which people propose concrete schemes in subsequent rounds. 


On Sun, Jun 21, 2020 at 4:31 PM Blumenthal, Uri - 0553 - MITLL <> wrote:

I concur with Watson. Different use cases need different "winners".

On 6/21/20, 15:01, "Cfrg on behalf of Watson Ladd" < on behalf of> wrote:

    Unlike PAKE, where a multitude of designs all claimed to have achieved
    the same security and usability goals, the goals of this competition
    seem multifaceted and in tension. On the one side is a desire for
    larger encrypted data volumes, either via big blocks or beyond
    birthday techniques. Evaluating a big-block construction is likely to
    involve substantial symmetric cryptanalysis knowledge.

    On the other is a demand for key-committing schemes and nonce hiding
    schemes. Both of these are likely to have efficiency costs compared to
    potentially one-pass big block (or tweaked) schemes.

    I don't think it makes sense to have a competition. I think it makes
    sense to articulate the problems and present them to get people
    interested in proposing designs/understanding the tradeoffs, and then
    maybe have a competition once that is clearer.


    Cfrg mailing list
Cfrg mailing list

Cfrg mailing list



SY, Dmitry Belyavsky