Re: [Cfrg] Fwd: I-D Action: draft-nir-cfrg-chacha20-poly1305-00.txt

Yoav Nir <ynir@checkpoint.com> Tue, 28 January 2014 07:10 UTC

Return-Path: <ynir@checkpoint.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 119F81A025B for <cfrg@ietfa.amsl.com>; Mon, 27 Jan 2014 23:10:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.436
X-Spam-Level:
X-Spam-Status: No, score=-7.436 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.535, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jgOd1-DuBZEO for <cfrg@ietfa.amsl.com>; Mon, 27 Jan 2014 23:10:46 -0800 (PST)
Received: from smtp.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by ietfa.amsl.com (Postfix) with ESMTP id 7ADA11A0258 for <cfrg@irtf.org>; Mon, 27 Jan 2014 23:10:45 -0800 (PST)
Received: from IL-EX10.ad.checkpoint.com ([194.29.34.147]) by smtp.checkpoint.com (8.13.8/8.13.8) with ESMTP id s0S7ATuW022054; Tue, 28 Jan 2014 09:10:30 +0200
X-CheckPoint: {52E75180-C-1B221DC2-1FFFF}
Received: from DAG-EX10.ad.checkpoint.com ([169.254.3.110]) by IL-EX10.ad.checkpoint.com ([169.254.2.228]) with mapi id 14.03.0123.003; Tue, 28 Jan 2014 09:10:29 +0200
From: Yoav Nir <ynir@checkpoint.com>
To: Ilari Liusvaara <ilari.liusvaara@elisanet.fi>
Thread-Topic: [Cfrg] Fwd: I-D Action: draft-nir-cfrg-chacha20-poly1305-00.txt
Thread-Index: AQHPG1VayupJctYi2UaBYTEolzC7J5qZGJEAgAB/R4A=
Date: Tue, 28 Jan 2014 07:10:29 +0000
Message-ID: <1617B1E4-A5D2-4AD3-8DA5-168E5308EE03@checkpoint.com>
References: <20140127114546.8921.73181.idtracker@ietfa.amsl.com> <2DD6FE86-A5C6-4144-8778-2DFFCA8AD5F8@checkpoint.com> <20140127233453.GA32488@LK-Perkele-VII>
In-Reply-To: <20140127233453.GA32488@LK-Perkele-VII>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.31.20.253]
x-kse-antivirus-interceptor-info: protection disabled
Content-Type: text/plain; charset="us-ascii"
Content-ID: <6FA0FDF1FA329440A078BC5506873227@ad.checkpoint.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "cfrg@irtf.org" <cfrg@irtf.org>
Subject: Re: [Cfrg] Fwd: I-D Action: draft-nir-cfrg-chacha20-poly1305-00.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jan 2014 07:10:48 -0000

On Jan 28, 2014, at 1:34 AM, Ilari Liusvaara <ilari.liusvaara@elisanet.fi>
 wrote:

> On Mon, Jan 27, 2014 at 10:15:26PM +0000, Yoav Nir wrote:
> 
>> Filename        : draft-nir-cfrg-chacha20-poly1305-00.txt
> 
> 
> 
>>  Rounds 1-4 are part of the "column" round, while 5-8 are part of the
>>  "diagonal" round:
> 
> Should the first "Rounds" be "Quaterrounds" or something?

1, 2, 3, and 4 are quarter-rounds. Together they make up a round. In this case, a column round.

> 
>>  AEAD Construction for Poly1305:
>>  000  50 51 52 53 0c 00 00 00 00 00 00 00 0c 00 00 00|PQRS............
>>  016  00 00 00 00 d3 1a 8d 34 64 8e 60 db 7b 86 af bc|.......4d.`.{...
>>  032  53 ef 7e c2 a4 ad ed 51 29 6e 08 fe a9 e2 b5 a7|S.~....Q)n......
>>  048  36 ee 62 d6 3d be a4 5e 8c a9 67 12 82 fa fb 69|6.b.=..^..g....i
>>  064  da 92 72 8b 1a 71 de 0a 9e 06 0b 29 05 d6 a5 b6|..r..q.....)....
>>  080  7e cd 3b 36 92 dd bd 7f 2d 77 8b 8c 98 03 ae e3|~.;6...-w......
>>  096  28 09 1b 58 fa b3 24 e4 fa d6 75 94 55 85 80 8b|(..X..$...u.U...
>>  112  48 31 d7 bc 3f f4 de f0 8e 4b 7a 9d e5 76 d2 65|H1..?....Kz..v.e
>>  128  86 ce c6 4b 61 16 72 00 00 00 00 00 00 00      |...Ka.r.......
> 
> What are that stuff at the begnning (the first 20 bytes)? The
> 12 byte additional data + its length?

It is. The AAD is "50:51:52:53:0c:00:00:00:00:00:00:00". Now that you mention it, I see that I omitted to include the AAD in my example. Will fix in the next revision (coming soon)

Thanks

Yoav