[CFRG] AES-CTR + HMAC-SHA-256 AEAD

John Mattsson <john.mattsson@ericsson.com> Fri, 12 March 2021 23:12 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DBB473A1914 for <cfrg@ietfa.amsl.com>; Fri, 12 Mar 2021 15:12:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.849
X-Spam-Level:
X-Spam-Status: No, score=-1.849 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.248, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, SUBJ_ALL_CAPS=0.5, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mbjLgvyuO9V5 for <cfrg@ietfa.amsl.com>; Fri, 12 Mar 2021 15:12:56 -0800 (PST)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2086.outbound.protection.outlook.com [40.107.20.86]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B3CAB3A1958 for <cfrg@ietf.org>; Fri, 12 Mar 2021 15:12:53 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=O6aWJaEroiTdKv2yxg3qK//h85F+xnQfL/N+SkQmL4qWhotxj1iSN8nElsUrgnU0i6dtqk+jrcWCqufIeJwrN8OWJhucDndJLcPnhXT+Ur9I+O5g9an2uWb/UeActbdI1UW7Jvk3fZVD3fiYnKLMLSCExJ/52cYXDOYBpC07JyVBJwRy+kh773mAKh8L+jREAlEg5CLvKREpiO9wwZFeRZLWo18n0jWNkxLkcBrgSFzebxL/Ir3OEOPv227jA/7q5yTKB3O+eY2BXrqIw+JRUh0mV9iHJhmO2hrpZFZPQ9Qkpyo0efN2bvutL0D3Ax5fVsOkGRk5n1Q6xolbCIGWJA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rbylStYhs95muJp+QfQztD1Sx9DpgwllQ8JZ34hIeHw=; b=YsiFeORn8IG2RtkDMdrpQM/kvIktmkfDomhdUy9croHCihMrs99K4cc0wUI09C+jiUha3Mjet2JZj56eY9dQhH598SaREfwUx08Bkl1aOgSUjVD3PIZDm+IR9Q8e4ZfiwNuFBKMqsqz1m7r9D+VZK9l9mUJN/4IMX2zrzFBwa3sDDF9RumLJJqhEav/2aRh9Xf3Q+6uAZ7taks98POmZU+fdPyfB5OT4zlgktlrazZhEtChOtsmskZ4S9d3QqSipv/ZzfD2axWzd1WbMlJTwNmrExY4saLp6guZ6xcdoqgd1UPtsPUctBBWCkgZEpfv1DmAniolQUmAzqbSDzVC0dg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rbylStYhs95muJp+QfQztD1Sx9DpgwllQ8JZ34hIeHw=; b=rPCYsvxHgQgqmjyv3/cEhpVThi1I9tehXbc5NIPJWm3h9tR0070WGJBtWw0fXx5zcZBKVf3Z1LPf9ZZkQ3SO4KDk0sgtC8ViTIo7bnAnLdy9tIR2R9rv4qY31ESNQCjMgsOF17lO+6ZgkPyLJpAlgaa0rcFZf0Q9rzXucLjuKjk=
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com (2603:10a6:3:4b::8) by HE1PR0701MB2395.eurprd07.prod.outlook.com (2603:10a6:3:6f::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3955.10; Fri, 12 Mar 2021 23:12:38 +0000
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::69ab:83ff:dd6e:3536]) by HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::69ab:83ff:dd6e:3536%4]) with mapi id 15.20.3955.011; Fri, 12 Mar 2021 23:12:38 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: "cfrg@ietf.org" <cfrg@ietf.org>
Thread-Topic: AES-CTR + HMAC-SHA-256 AEAD
Thread-Index: AQHXF5UxBGcr+yyvCk2agJK9w9DVqw==
Date: Fri, 12 Mar 2021 23:12:38 +0000
Message-ID: <5E976EFE-CF76-49CA-A02E-9189EB609988@ericsson.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.46.21021202
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [81.225.97.222]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 1750a30c-174e-458c-a9f6-08d8e5ac5474
x-ms-traffictypediagnostic: HE1PR0701MB2395:
x-microsoft-antispam-prvs: <HE1PR0701MB23956DE95215365CB0C38F34896F9@HE1PR0701MB2395.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 86uL4KRnOkk2gJEcrWLLNZ+xUHjvu3GTQVxIcCiRwE7CtH5Cw/gRd7vbrmCGrli2dnUMqDqhWXWRPRvbml/owAfGJUFYOm1DpfOlCnLQ7iwdcUFKVOClB/S9uam89enPVXJVOmpzSkw1H1jMOSgl77KyxxkI+ocPlHknTHyCXtFXPDE3vZUKiDlh5YZKYARCNZaCWSZx4I1Pplt5OTx8vLvE9T1J7K6z8+/f6A4TdPpkeC2f3xmEcV4n3mOy68sPDXcUC4DBaQ8dC3PHDWM1BUwBHADU7aK0Pu9HbMcXuYV0sbaTHtOzUfSQSbgRgUQ7UUTsc1Fk3bCrgo3qX2joSGLz3ia2dVtEeDrDWqTCe9TyDZHVeQAottO2S8BhLWXq4OETOj+kYvzF46bfzG76eUJKYwNsGCk6so0XL1yNID+jfdTbjkXK3E0IfB2dFzCuawn7VQy/i5l5xcZydYz3+aWirq+ZhndrL3aPjqvSOrk6a1etxsAuvyY9suJm/7XNR2Dk8cNt+Ktr4Yn4ioOQV3Fn29fMAYrPW9TlD6s6ztvuB1m2KudAg6ruVtWSQW0awGbgIoIR2BgGxiX3DnaYUPeUPPNdzzEwr17Ac4ig56SJdH7/A/CKD0t3NfPDxwL28BnGusX2JSPG0HQFIBjMxyoNaV3jp317vlMJVDhUHfYhNvbO2lKIP5YG5O0wuldL
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0701MB3050.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(366004)(346002)(376002)(136003)(39860400002)(66946007)(83380400001)(64756008)(966005)(76116006)(66476007)(66446008)(33656002)(186003)(6506007)(66556008)(8676002)(2616005)(44832011)(478600001)(5660300002)(316002)(6916009)(6486002)(4744005)(6512007)(71200400001)(36756003)(86362001)(8936002)(26005)(2906002)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: =?utf-8?B?c21UOCtlazFyUGYxelJNNlc2b1I0Kyt3WXZLSWh2OTB6TGk4Sms5Vm1MVUZy?= =?utf-8?B?NEtNK2pSQlhvSkZZcUJsdVlhTU9YVGxneWN2VTFWNVBCWkF5NU1DcTVBTnlV?= =?utf-8?B?Q1o4ZXV1SWh2TXRwU0poYVBYQjF5T0lXeUdrSmlNU0ROdi9sNjFYNzVSUWRm?= =?utf-8?B?ZlNGR1VOSGpxY1NCUnFKaWU1L2ovS2IzOWtwTDQ5bDhiN0ROWStFS1RSeHpn?= =?utf-8?B?QlNHYWZFeHF5aEZUUDhiNUxrK012bGlsQXFDQUpEY0FOakpVNUd0VmtJdDNn?= =?utf-8?B?OUN2ZXVLSDQyQWFBcFRmTWRaVk85ZDU1cDM1T1R4NEJUakh1bmdlOUl3QXEy?= =?utf-8?B?UUxOS1JaYi92a0pWZEI5SEcrRlZGekFkKzhURnhwM2RCRlhtSFNHNEpML252?= =?utf-8?B?SDdnQU5Pd091MTNmNVMxelkrdXRaRUFVaXlNeEJYbjZ2cmN6RGZmczE0SDZw?= =?utf-8?B?ZFJSTHA5M1YxelV0TjE1OVBPUWR0S056SlFnN1BYaXNvNWhMRUR5THdxblZt?= =?utf-8?B?blBGUWdRMEJ2ZlVlcCt2aDNvNVJ2R1QrQ25FWlRSMHRTMFFsNzEyRzRkMUJw?= =?utf-8?B?aXgrV09sYjJXL211UzlFY3RPUTZEVEU2WGlyaERweUFqeXhwc3pUOVlsNXVZ?= =?utf-8?B?MkxjM0VhZHJ0TUp2ZWo4bGRGRkdSZzJjQXV0ZnZ3ZnRZdDM5OXNLcVRQNFhI?= =?utf-8?B?MWQvUzUvY0NWdTI2OVVXalk0b01FU1Y3b29QUWNDTEVZK1AzajBtNDBNQXMv?= =?utf-8?B?ekk4ZkpaY0RiSFBUczFWVlp6S2VXKzVOTFoxdUlaTHBnbXdUTmNYTVVpdkx2?= =?utf-8?B?RDd6QUV1bDJ1ZUVua0FNWTh3ZHdVUlZkZFk4VDREUjlCdUVZWDQyZ0xSSVRV?= =?utf-8?B?MXprVThjdUZNbXFwcnNQdW1wdUJ0US9FdW1YcDJ3V090c25Fd3VWbDJkMjNk?= =?utf-8?B?d0g3WXpsbDZoMFNpRUVJeExHOVFoMjdwUFhIY05lcXFsRXdxK1djNXRhQUta?= =?utf-8?B?UW1tWVFKcTQzN0RjUkkrd2xnNUZ0ZlVrUld6VW5mc2JJZlBSZVFMWVpPVWp0?= =?utf-8?B?ZkZjUzZmRXlsSHROUTlZNzhyUWI4ZCtNNHVwZ3o5N3RzN2RIbzhDdWVEc1dT?= =?utf-8?B?K0t6dkdRTm9LSWlnQjZ1MGp5SmdmcjhpaEYreVFXeWlGSm5xQi9PTlVIY0dD?= =?utf-8?B?ZnordG9qcmYxVGtqZWp5czgwUWJnKy9WZEpuRTRJSm13eHowOXZrNGZrS1lY?= =?utf-8?B?QjRtQ3hybUFTSDJMMUVPdFFDNERBOUlxZHI0Y0VXQjVZT3BaNzY5ekFaMnEw?= =?utf-8?B?U1Q1VklWbGkwWXhxZ3FINGJZVTVsWjZzUHR0RG9pRm9FM0VraGZMeksxOEJG?= =?utf-8?B?RjhJR0czSjZnTks5UE1QaE9nSHNxemxrZ1VIZ0JxNEIzd2I2MnZCb05IaUZu?= =?utf-8?B?TStLMWtqRWlUZzU0WHFZaFY2MnlMd29Bb29JMEgwWTF4Y0puNVJ4T1AvUEx6?= =?utf-8?B?cnk1dDF1WjBxdkk1d3VIY3oyQVBqTk5uNzdZSkR4MVBmNjdSUm5veGpyZlVU?= =?utf-8?B?eU5wN1BNTmhyK0svcGNmK2p4VFJud09xcGl1SUMxSTZQRkM5SG1wUG8vdFNy?= =?utf-8?B?K0k2QW1scG5xQ3NUQXQraml2ZHEyV1NHZVZ5SmdyV1VLQ0svSEF3UzJLM09h?= =?utf-8?B?OFNnZWlQZXRJY0UvUlhXTDdWVi9UaHZOQ0V0b2JCY0FqNGUwT0ZFNG9ZMW5a?= =?utf-8?Q?Y+k/VwcyNkM2hq+RqdAQWgRWkUMBFsSK+GyG0LQ?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <90B3889294B3F645AD85A678C996CF32@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0701MB3050.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1750a30c-174e-458c-a9f6-08d8e5ac5474
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Mar 2021 23:12:38.5653 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: jCF7UFCgQMOg2fAauy62nnktD9l8UrqBQ28BnE2ZAXtbqPT3tVJqQj/RhjE359b4Xb81QuKG5X/7w9a7o7i07DMyeRwn8bvvKWAwGfvJytI=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2395
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/iaD_VkbLOq9wGqAXOBldkuyTSos>
Subject: [CFRG] AES-CTR + HMAC-SHA-256 AEAD
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Mar 2021 23:13:03 -0000

Hi,

In the CFRG chat today, Richard Barnes asked for reviews of https://tools.ietf.org/html/draft-omara-sframe-01#section-4.5.1

I think standardizing an AES-CTR + HMAC-SHA-256 AEAD seems very useful. The design in 4.5.1 looks very good. Some comments:

- I think the nonce length Nn ciphersuite 1 and 2 should be 16. I don't see any reason to not use 16 bytes radnomness/salt. 

- It looks like the frame counter CTR and the block counter collide, but maybe I miss something.

- I note that only the aad_len is authenticated, while GCM authenticated both aad_len and ct_len. I don't know what is correct.

Cheers,
John