Re: [Cfrg] Do we need a selection contest for AEAD?

"Blumenthal, Uri - 0553 - MITLL" <> Wed, 24 June 2020 17:14 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 5195D3A104A for <>; Wed, 24 Jun 2020 10:14:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.895
X-Spam-Status: No, score=-1.895 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_QP_LONG_LINE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id XOrWYLfthCUP for <>; Wed, 24 Jun 2020 10:14:27 -0700 (PDT)
Received: from (LLMX2.LL.MIT.EDU []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id A6DDE3A1049 for <>; Wed, 24 Jun 2020 10:14:27 -0700 (PDT)
Received: from ( by (unknown) with ESMTPS id 05OHEDVp004561; Wed, 24 Jun 2020 13:14:13 -0400
From: "Blumenthal, Uri - 0553 - MITLL" <>
To: Yevgeniy Dodis <>, Paul Grubbs <>
Thread-Topic: [Cfrg] Do we need a selection contest for AEAD?
Thread-Index: AQHWRl+/a1yZqWKXrUWtt9h91T1RYajoQPkAgAAJrQD//75bgA==
Date: Wed, 24 Jun 2020 17:14:12 +0000
Message-ID: <>
References: <> <> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
user-agent: Microsoft-MacOutlook/16.37.20051002
x-originating-ip: []
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha256; boundary="B_3675849251_1644659899"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.216, 18.0.687 definitions=2020-06-24_11:2020-06-24, 2020-06-24 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-2004280000 definitions=main-2006240118
Archived-At: <>
Subject: Re: [Cfrg] Do we need a selection contest for AEAD?
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 24 Jun 2020 17:14:29 -0000

I don't support that idea, because different use cases require different "optimizations". My use case doesn't care for nonce hiding, but cares very much for performance, and for the ability to have defined security bounds for truncated synthetic IV. 

There is no "one size fits all", or "one champion fits all". Even CAESAR results may not be granular enough (several categories, with a winner in each one).

Or are you planning to have a *separate* competition for *each* of those listed below: 

    they have a clear guide what to choose from. Whether this is
    committing, remotely-keyed, ZK-friendly, lightweight,
    side-channel-resistant, nonce-misuse resistant, nonce-hiding,
    beyond-birthday, etc.

On 6/24/20, 13:09, "Cfrg on behalf of Yevgeniy Dodis" < on behalf of> wrote:

    I support Paul's idea. I feel AEAD landscape is getting a bit out of
    hand, even despite the CEASAR competition.
    Would be good to bring back more structure and understanding, so when
    people in the industry need an AEAD scheme,
    they have a clear guide what to choose from. Whether this is
    committing, remotely-keyed, ZK-friendly, lightweight,
    side-channel-resistant, nonce-misuse resistant, nonce-hiding,
    beyond-birthday, etc.

    On Wed, Jun 24, 2020 at 12:34 PM Paul Grubbs <> wrote:
    > I think an AEAD competition is a great idea. Recently I've been studying the AEAD landscape, and there seem to be a lot of gaps between the needs of applications/protocols and the properties widely-used schemes provide. To address this and get a sense of which needs are most pressing, it might be good to have the first round be more of a "meta-competition" for discussing and prioritizing requirements and use cases. The result of this would be an (ideally small) list of well-defined design targets, for which people can propose schemes in subsequent rounds.
    > I'd also like to suggest another use case for AEAD: ZK-friendly AEAD modes. These modes would be compatible with efficient ZK proof systems and would make it easy to prove properties of plaintexts in zero knowledge.
    > On Fri, Jun 19, 2020 at 1:32 PM Stanislav V. Smyshlyaev <> wrote:
    >> Dear CFRG,
    >> The chairs would like to ask for opinions whether it seems reasonable to initiate an AEAD mode selection contest in CFRG, to review modern AEAD modes and recommend a mode (or several modes) for the IETF.
    >> We’ve recently had a CAESAR contest, and, of course, its results have to be taken into account very seriously. In addition to the properties that were primarily addressed during the CAESAR contest (like protection against side-channel attacks, authenticity/limited privacy damage in case of nonce misuse or release of unverified plaintexts, robustness in such scenarios as huge amounts of data), the following properties may be especially important for the usage of AEAD mechanisms in IETF protocols:
    >> 1) Leakage resistance.
    >> 2) Incremental AEAD.
    >> 3) Commitment AEAD (we've had a discussion in the list a while ago).
    >> 4) RUP-security (it was discussed in the CAESAR contest, but the finalists may have some issues with it, as far as I understand).
    >> 5) Ability to safely encrypt a larger maximum number of bytes per key (discussed in QUIC WG)..
    >> Does this look reasonable?
    >> Any thoughts about the possible aims of the contest?
    >> Any other requirements for the mode?
    >> Regards,
    >> Stanislav, Alexey, Nick
    >> _______________________________________________
    >> Cfrg mailing list
    > _______________________________________________
    > Cfrg mailing list

    Cfrg mailing list