Re: [CFRG] SipHash recommendation?
Rene Struik <rstruik.ext@gmail.com> Wed, 16 December 2020 15:59 UTC
Return-Path: <rstruik.ext@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ABED53A1056 for <cfrg@ietfa.amsl.com>; Wed, 16 Dec 2020 07:59:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id clDd-N5J9B4o for <cfrg@ietfa.amsl.com>; Wed, 16 Dec 2020 07:59:26 -0800 (PST)
Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C89533A1052 for <cfrg@ietf.org>; Wed, 16 Dec 2020 07:59:25 -0800 (PST)
Received: by mail-qk1-x72a.google.com with SMTP id p14so13807002qke.6 for <cfrg@ietf.org>; Wed, 16 Dec 2020 07:59:25 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=to:cc:references:from:subject:message-id:date:user-agent :mime-version:in-reply-to:content-language; bh=8VHHLU0nbWqBANJHMqQDX3Pxp7httEOcBl98fVjK+FQ=; b=jXoh8Zy0SOkc0Iu+PyPC3hXnGwatSbt+9HOWHHfsvsOX7D7GMRW+9uQAK+/FFWS8PB pvqbVb0Q+sesVZxe3SB7G6PgbxWKskZ8O3FNFtrdL//lkXHZ3FMDEmd268wsi61SLoV8 yjc5m7LljG3s22F2XE54MUt0NafVuNsQ9P4W+GJupjYcOprrNA47a7bHgfNS+78TqfsY YeAQumrqAyobO8UeD6dEzAnYmTQrTa9sXSIrMwF4SgxhqdnhwoncuGqFs5QLFfShXYQH nKtnp9RBEAA63ulR3JvAfcxaxynlpLjbCxCBUlBmxNYo4LxY11gzdnfif28IU86bFpcR 1wYw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:cc:references:from:subject:message-id:date :user-agent:mime-version:in-reply-to:content-language; bh=8VHHLU0nbWqBANJHMqQDX3Pxp7httEOcBl98fVjK+FQ=; b=mq1l/47xPaZ1xKbcjiBa0xCmDQFC0sva49bBNIf3seyXtbpBm7Yp3BQFcP5MlFhRIw 9n1c6ZvdkzHy7jAIMB3gE/hXZd5dduKrXkG4I4mBKMjbCo5g8hyhXXnYN5c/DzO/9pns uxC5ZsrYXjOPDQ45YeLBPKO3lB8KvQ0ZwmgYw7hydBMcqo9tngq8TonjZyluuugb3ZWh zkhHYr7DDQipr4bLfVxDz95Bshc2ua473ASgwxOTcqwh0RnjAONgyrNk8Dii9ST4dLNn DD1xEqyHBrUKeuA/sRTC8IupzwtyrosluqJqXE7Ke4Z1KTWTBiI7qNbj1C51yvuMv7Fs w6DQ==
X-Gm-Message-State: AOAM533g6RuqFqbwXnZAkWRpb6ugR8JZQYdSBN8aFKc1mQGhR1sOEO7v gt5I65rgh1SWzZeAOA74VghY/hkpv1M=
X-Google-Smtp-Source: ABdhPJw8ik2Il6UjJMeNTmgDUe0Ox3/OfdWAe4ssyGMcl0UbHcQue+9t2qo4jgmYrBl5uL6Wvq4AFw==
X-Received: by 2002:a37:68c2:: with SMTP id d185mr43567827qkc.45.1608134363839; Wed, 16 Dec 2020 07:59:23 -0800 (PST)
Received: from ?IPv6:2607:fea8:8a0:1397:41ad:2c35:b491:93a2? ([2607:fea8:8a0:1397:41ad:2c35:b491:93a2]) by smtp.gmail.com with ESMTPSA id l11sm1193533qtn.83.2020.12.16.07.59.22 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 16 Dec 2020 07:59:23 -0800 (PST)
To: Jean-Philippe Aumasson <jeanphilippe.aumasson@gmail.com>, Benjamin Kaduk <kaduk@mit.edu>
Cc: cfrg@ietf.org
References: <20201216000229.GG64351@kduck.mit.edu> <CAGiyFdcaqyEhxhJTys0sZ6YvyRAZ9MM7=Kh1z2TqWVFckUrNrg@mail.gmail.com>
From: Rene Struik <rstruik.ext@gmail.com>
Message-ID: <db703fe0-073d-07d0-3c81-c820e9497970@gmail.com>
Date: Wed, 16 Dec 2020 10:59:20 -0500
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.5.1
MIME-Version: 1.0
In-Reply-To: <CAGiyFdcaqyEhxhJTys0sZ6YvyRAZ9MM7=Kh1z2TqWVFckUrNrg@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------A09B83A5DF2600A9E062E6B8"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/OY11tF8Aa4ddE1vusi9igPpxaWw>
Subject: Re: [CFRG] SipHash recommendation?
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Dec 2020 15:59:28 -0000
Hi Jean-Philippe: Section 3 of the SipHash paper [1] writes "We define SipHash-c-d for smaller c and d to provide targets for cryptanalysis. Cryptanalysts are thus invited to break", while Section 1 writes "Our concrete proposal SipHash-2-4 was designed and evaluated to be a cryptographically strong PRF (pseudorandom function), i.e., indistinguishable from a uniform random function. This implies its strength as a MAC." I am curious about the cryptanalysis that went into supporting the indistinguishability claim. From a cursory look at [1] and [2] I could not immediately find this. Is indistinguishability the (or one of the) "security goals" alluded to, but not mentioned, on the last slide of the presentation [2]? Best regards, Rene Ref: [1] Hash Functions - SipHash, A Fast Short-Input PRF (Jean-Philippe Aumasson, Daniel Bernstein, DIAC 2012) [2] https://cr.yp.to/talks/2012.12.12/slides.pdf On 2020-12-16 9:58 a.m., Jean-Philippe Aumasson wrote: > SipHash co-author here, that draft uses the 2-4 versions (like the > Linux kernel, > https://www.kernel.org/doc/html/latest/security/siphash.html > <https://www.kernel.org/doc/html/latest/security/siphash.html>), which > has lower security margin than 4-8, but I’m not aware of any > cryptanalysis result that would affect any of these in the context of > this proposed application. > > > > On Wed 16 Dec 2020 at 01:03, Benjamin Kaduk <kaduk@mit.edu > <mailto:kaduk@mit.edu>> wrote: > > Hi all, > > We have a document (draft-ietf-dnsop-server-cookies) in front of > the IESG > that proposes to use the SipHash-2-4 algorithm > (https://www.aumasson.jp/siphash/ <https://www.aumasson.jp/siphash/>, > https://www.aumasson.jp/siphash/siphash.pdf > <https://www.aumasson.jp/siphash/siphash.pdf>) as a MAC over what > is in some > sense a return-routability and freshness token, the "DNS cookie" > originally > specified in RFC 7873. > > Unfortunately, the authors of this draft have not yet written down > a clear > description of what properties they believe are needed from this > MAC for > this usage, which makes it slightly hard to confirm that SipHash is a > suitable algorithm for this purpose, though that is certainly a > question > that I am interested in. > > Regardless of that, I would also like to get the CFRG's input on > whether > SipHash is a suitable algorithm for its stated goals (paraphrasing > slightly): a performant keyed (family of) PRF suitable for use as > a MAC, > with the security goal for a MAC being considered to be that an > attacker, > even after seeing tags for many messages (perhaps selected by the > attacker), is unable to guess tags for any other messages. > > In short: is SipHash fit for this purpose? > > There does seem to be a decent amount of literature analyzing > SipHash, but > I have not attempted to review it to any significant degree. > > Thanks, > > Ben > > _______________________________________________ > CFRG mailing list > CFRG@irtf.org <mailto:CFRG@irtf.org> > https://www.irtf.org/mailman/listinfo/cfrg > <https://www.irtf.org/mailman/listinfo/cfrg> > > > _______________________________________________ > CFRG mailing list > CFRG@irtf.org > https://www.irtf.org/mailman/listinfo/cfrg -- email: rstruik.ext@gmail.com | Skype: rstruik cell: +1 (647) 867-5658 | US: +1 (415) 287-3867
- [CFRG] SipHash recommendation? Benjamin Kaduk
- Re: [CFRG] SipHash recommendation? Jean-Philippe Aumasson
- Re: [CFRG] SipHash recommendation? Rene Struik
- Re: [CFRG] SipHash recommendation? Jean-Philippe Aumasson
- Re: [CFRG] SipHash recommendation? Rene Struik
- Re: [CFRG] SipHash recommendation? Jean-Philippe Aumasson
- Re: [CFRG] SipHash recommendation? Rene Struik
- Re: [CFRG] SipHash recommendation? Jean-Philippe Aumasson