[CFRG] Re: Random-access authenticated encryption (raAE) draft
John Mattsson <john.mattsson@ericsson.com> Tue, 14 July 2026 08:25 UTC
Return-Path: <john.mattsson@ericsson.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C9F2E1165C70F for <cfrg@mail2.ietf.org>; Tue, 14 Jul 2026 01:25:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784017547; bh=tnL73Ph/Ki6JKJ6qaFv0lA9ggpU1Ol6Gqf0LD/81VWE=; h=From:To:Subject:Date:References:In-Reply-To; b=tCBh6024l8GJdcAHnrXkw2vb4Luvh00iVdFnaJ4N9NM778mZPM39vB1WyMjCf/OJr 3NSYdftvXO96ynE1fS6jwFzuq2fmLeRZrXAkIU6PH2rIyU/AtKYd83cxq3YTWtYLtr L4bvwjbvPai3HfzUH4G3D5LsPuBVLN3y/wgVV4bw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c84tdI3UCv6O for <cfrg@mail2.ietf.org>; Tue, 14 Jul 2026 01:25:46 -0700 (PDT)
Received: from GVXPR05CU001.outbound.protection.outlook.com (mail-swedencentralazlp170130007.outbound.protection.outlook.com [IPv6:2a01:111:f403:c202::7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BD6611165C694 for <cfrg@irtf.org>; Tue, 14 Jul 2026 01:25:13 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Xvp5BCM28qyIr44kfaeFAKAkbLvKMwQ9MQQ0ieAXBgnT9FtTqrp0KLsdI4+4Fnen7U+JnFo9JxzU3R33S5aRb8Bv79+4H7aFDkngcO+vyj4xTmt9qWRYejA4vcon31jUhRfdOGOT5B5R5bOJTdO460XCSjGDjjiCTMHHhxcCEveLiNtOelvdgS8wOHD14Q8an0JK+IoM7oemASYYyWuOC7mH9HJBIxiMcF/isav7uUhJsYctoF07cni0dPQnq82HOdldusFh5EIeipZbr+B2iot3Q8tLu0sJ1OZ+PrbdbF4nt/fk6AvBZXaZwaFguiUjlNM2j4tVWPrVEXK6oIKoKQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=uzy5BtQ7/NsDE2ZOUdt3gfPxthBdT3OOT8Ukb+pWtL4=; b=LozT+twJI9gFu7RNRXtJd4egrEvlHAI9KoEU6x3b+hq6wlSrmhPdt0fzoeFDlkmG7bY0EUgNDqhKh7el+PZe2BumAQy9ycULngBaH4d9AmeyZ2e5E0qV2Xwh1432cz8yO1bzWQvmGf0swTGJVi0OB8eiKx5Vxv0dccWkFuoD4WxACllnRPY4LlE0sRAU7QP7Cf0KeOKKCkKhUO1J18vRRwKEOOTVcREOQzo0Wv7hgck+2HO7PFnO2vlZSQKla2YyzRYudm2D60IsQcLtpSz+aAF1ONSNSrl7Z4k0aMsuWlVZFziuWGSF3zH5I5W3+cpulEHa64one4j8O2mw/eIlJw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uzy5BtQ7/NsDE2ZOUdt3gfPxthBdT3OOT8Ukb+pWtL4=; b=j1muuCTrQQTRSp9pzG06IBIFrAkckkAV1VfcER3m68DonFXE/S/8I7ALwjTq6esccl3mMhOe/bn3+gqA1sRkVgXz36VTAKTDlYYubYdZ3SIqQk5+9Od0fOaU0x3jbhM1GbV1hkSyEr88z0RJMLn4HUfWl/p/WPSkie6TND4EZniC86+LwQ/GBB2noi8dUZPdLisYDx9qIywsX35z2yTnZ4+doeoZJkGblaT0kDxsBG1TtmIve4BNBifSKOJjZPw1h8hxyvJVlC62P7AvHIPgXZIa1M9Qomtv4U68LcPTgtsWvVsmCSZMp495lLZCbigDl3ekz09fr43c6NycrG5rKQ==
Received: from AS4PR07MB8825.eurprd07.prod.outlook.com (2603:10a6:20b:4f3::15) by GV2PR07MB11602.eurprd07.prod.outlook.com (2603:10a6:150:2f5::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.202.16; Tue, 14 Jul 2026 08:25:05 +0000
Received: from AS4PR07MB8825.eurprd07.prod.outlook.com ([fe80::11a4:5f37:fa92:f174]) by AS4PR07MB8825.eurprd07.prod.outlook.com ([fe80::11a4:5f37:fa92:f174%6]) with mapi id 15.21.0223.007; Tue, 14 Jul 2026 08:25:05 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Martin Thomson <mt@lowentropy.net>, "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: [CFRG] Re: Random-access authenticated encryption (raAE) draft
Thread-Index: AQHdE2cIE14J7LgbF0GeLcmgAbIrXLZsqpxb
Date: Tue, 14 Jul 2026 08:25:05 +0000
Message-ID: <AS4PR07MB8825389E838C161453B02DA989F92@AS4PR07MB8825.eurprd07.prod.outlook.com>
References: <CAOjisRximY8dNJVFkYyHogh6UyH6HOUK==yt8+b-Muy9VntX9Q@mail.gmail.com> <ef6adb6e-cc5e-4021-96c7-4691404c9b1b@app.fastmail.com>
In-Reply-To: <ef6adb6e-cc5e-4021-96c7-4691404c9b1b@app.fastmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: AS4PR07MB8825:EE_|GV2PR07MB11602:EE_
x-ms-office365-filtering-correlation-id: 978fa784-e92b-4a63-4734-08dee1816896
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|4022899009|376014|23010399003|18002099003|22082099003|3023799007|11063799006|4143699003|4133799003|8096899003|13003099007|38070700021|6133799003|56012099006;
x-microsoft-antispam-message-info: M9aoFSe2RTtx8L98YnM9YnZVXxJmone8o/QQSTaEe8COFyCZKzHmUwF8Y26Jikegw+lBJpLkubbC1r3fI7pJSl2iuKr3Y9VyK/Hl5gyaNgq8xbdS4b1pQbNWsai4CgIFS3Z4vp+Pr7Uv9Su9RYOrzwDYu4RiRhoi8+rndJvNBEQN7eUAMDwLYMUJyp32x2sl014QzA2V8/6UfzEmkXZ4HRWVEER9XUJRSh77KN6aSkTjRWxfwyGdREtXVZ172E37kAJHaU8FLy7kkbGsX+NquIT32A8Pe/77LElLsixTT/yfUPHyjywdW0qdgK3elqanMBB4zaVt/ToDxGH4yp0xmv22iGNdg4ZK/hzQGjCmDA9TzICLoNqZGvrTb8WBMdqTIxWO08SR3iR5Fb9XL6r+ZxDnY2UVDuJ4ezttIDERTyCI3D4B33a3mAEOr5hvoT8l0UCT6RmxEe+OCiH1v3MP5AIhb5wpDzOTid2jjfKBreDH16r6hTjfTs/cvsx8u/aLRqt4tT5tGZraz/2DCzEG8lBYDrToATXIHELp3scK03px6LgMsNoFAo8+ZZAvIyxqQh5asvFi4AqsnXm1RXxM9wzPxsbNhjxE78zlmKH01ZGuSVuG6zWbXf1RV4CsHMADKR583K4Tmbvaayq9cGBQpQolFqbygU152t9bBxhHRVMW1KMK1eZ2L18p+jHW4uq9tkVEGKWyg/LuzfGZJQkN5mSCQc7Jtgv7e9PYTznS7A4=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS4PR07MB8825.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(4022899009)(376014)(23010399003)(18002099003)(22082099003)(3023799007)(11063799006)(4143699003)(4133799003)(8096899003)(13003099007)(38070700021)(6133799003)(56012099006);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: qhHPf67BHuGee8ErNsidgL59VZ26CLCTIzzP+LI1IYxLAOGM8MeVllvVMixPBYmtfFKhz3YQbOYZFMeXIMgf3nlLVaqklwx5shWFajWqFRj8D3Y79lwJX4897u2j3vrOSZ1+ho6BBZQqPhm7vnUnwSce4Hkw+1JRH2uCw9PBbaWRCXBt2MnZmqTgPkB70Tt3XNVMM3lzIrH9vSIiIa+WuwjsfVOmFukv1oOFPbtT8ND7DvnSOo21yKM/k/gx0ZCMg1x4CSbBGREk8LZCq0i9AMAxto6CstRnumXa9WjJcu1dGSvB2jSK9Yo1aI/LJCb6aWzd7CuhajnzF6S+4zPWpseQsMJk2wURFaIL1RwQwpO17OZkCraykGASruVQmsgDqdRFBg81x/tZCMw9ZYIDGXc0lZalo4vU8cxvx7YD7g8eZWIOXwuWgAT8Xh6UNBYte3GX+eC++Arj/7l2CJYzb37MV7Xl09qD1PZ6NaN0DiTxIGnc97iGD4hmFpdNMbEURACAfyjQSCRBfbqqt4F23GOXJEH+tFor4hw06Rnbt7ptJ6HPr+KOuZ7acEkieBWkuMKKCpq0bXp0KS6T1oZjXcCuVbiTcZaXpLNCX4T0hOYGvoHUcS/ysjrTeaehxCqYVi3EUpYiGXToUe95O3EWRewPBCTI5fb2rhOn0nYHi/1/sNJbcIbhKGIJGsP1yuWct5RYbIcNZoOxI4PSkblUako33pNDo5uJCqon9uS/Huu3Ai0VtM4sLBXbvkOiXBXB1BLUFL70lY/st8QlAqs/NS0vn2vQ+78wquY5LmMZiRG05bF6nZs09ZADGkPCDqbkX44FfYdl2uOpiuaLaeBVygBH/VkkykGWh+8rvOUYJhW4vTfc6S9Ml1MVVRKZKKCSaJycliPolNOnWDPgHyEVOX9hUxqYkNZiCo44aTdbbh3UbhU0P933F5Nbdbpbr9B7R8YxW2FxIII/SlokF4QlPYHBCvy2QxfrgdQ7QI5y3fyDhyRWt9Vp77FyjdsAONtOddwfQmXw5O5kMyj8i1RyuMVwpMliZR+QQef8wNvO9eRvurfqucbOtgH1tmfG1UbwrxHoYp6qkyVlSfgokBbFKUt0viHifgQIxMRdXCUC8jP0G6Maoo/RjNAtBcBn5zqh507yw729l8Cxt4f+pKhhmWxSH2KdZ/zfFdvJbXDx+sQibvlPGw+dJg70/cTW+4b01Y86wdmFHwUP7F0lEXiJIxXc0a1vsfZ0w/AjmZe2IE60t5gjx3qkr3ASzPqjbRybcdezCdWOtZWPVQbX0yBlharnQuaiW8uDWjrv20rceJ0n3Kyd9r7SLugqf2H+1odLThGZjCNC42GAVMJyT3Vf3v07IJA0HMp4LizOnqvvfx3En9Y1TfHZoBVY5+o0hmj3zuMEpq3Xf9pWNjftRDUiOEZwQhQ1CY/JMmQSZhdIa9JoAjqlUuRxK7etDfMUAVy2dn85TA495+5XKFN8uUvq92FNUB7Q+iDe2sTrG6Xak9cQwnVHgqPxiUK8wmzSSZVTUpGw6lOElooHX3UMlF8YOPnoA1xP7XrNirzpLsRtiHN8WlvYfblT45Nv+q0DoHr4oleynPS3BZuSUBCe2c6TkRYtaLCzsyS8V0RXyKl8jZsAJcsfabeTvoa3ovp7U9Nr9ky+xkL1+yDfWPecWe8CymQNpSOmv8Q+fTzC2nhrHV9TvfQC5snR9yRRtUCpaSXZ52xMfvdk7s9AWUeLyfLtS8uXYFCBaTUg9km6dmhDqyM=
Content-Type: multipart/alternative; boundary="_000_AS4PR07MB8825389E838C161453B02DA989F92AS4PR07MB8825eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AS4PR07MB8825.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 978fa784-e92b-4a63-4734-08dee1816896
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Jul 2026 08:25:05.4058 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: JpKDZfH8QI5zuVdJaEuSoojMidux8l8FrIAYpZkz6Wy0xD20wETg6dfE9342JZToCH7HcFyPpQ78iDEJU49zMLyB8OEK0RpsKdRyafnFYU0=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV2PR07MB11602
Message-ID-Hash: CI65GAB5N7H7DZGY6JMY6ZHTSQ34WMNC
X-Message-ID-Hash: CI65GAB5N7H7DZGY6JMY6ZHTSQ34WMNC
X-MailFrom: john.mattsson@ericsson.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Random-access authenticated encryption (raAE) draft
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/sJ1dwHdx7QX3liOREFPScSLpeIA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
Hi Nick, Thanks for driving this! I think this has a lot of value and something the IETF should work on. I think even standardizing file encryption even without random-access would have value. My experience is that very weak file options like openssl-enc, gpg, and deriving a keys from low entropy passwords are still commonly used in practice. openssl-cms - CMS and age are modern secure options but lack random access. https://github.com/filosottile/age Disk encryption standards have random access but lack integrity. Agree with Martin that this can/should be done in IETF. Cheers, John Preuß Mattsson From: Martin Thomson <mt@lowentropy.net> Date: Tuesday, 14 July 2026 at 10:01 To: cfrg@irtf.org <cfrg@irtf.org> Subject: [CFRG] Re: Random-access authenticated encryption (raAE) draft Hi Nick, I'm going to suggest a DISPATCH outcome for this, which does not involve CFRG. I think that this is pure engineering and the IETF should be the place to take it up. The usual requirements apply, of course: we need to see the receipts on customers for the mechanism, etc... On Tue, Jul 14, 2026, at 00:54, Nick Sullivan wrote: > Hi all, > > Writing as an author, not a chair. I've been working on a draft I want > to share with the group. This is not a call for adoption, just sharing > the early draft in case there's interest. Comments and reviews welcome. > > *The **problem*. Applications dealing with large encrypted objects > (encrypted backups, encrypted archives, object stores) need to read any > part of the object without decrypting the whole thing. They also need > to verify that each part read belongs to the current object at its > claimed position, without processing the entire object. Mutable > objects, like encrypted file formats, encrypted disk images, and object > stores that accept partial updates, also need in-place modification of > any part without re-encrypting the whole. The positional and inclusion > proofs should also remain valid after each modification. Take an > encrypted database file or an encrypted disk image: any block is read > or written by index, and a reader wants to know that the block it reads > really belongs at the offset it came from in the current image, without > re-hashing every block on every write. No proven security notion in the > literature covers all of this under one primitive. As such, each > application ends up rolling its own segmented AE layer, mostly without > security proofs for the rewrite and whole-object cases. > > Prior work covers pieces of the problem. CHAIN (Hoang, Reyhanitabar, > Rogaway, Vizár 2015) is sequential. STREAM (same paper) supports > random-access decryption of individual segments and encodes a > final-segment bit for truncation detection, but has no whole-object > snapshot and no in-place rewrite. Its deployed relatives (Tink > Streaming AEAD, OpenPGP v2 SEIPD) are write-once streaming formats and > don't expose rewrite at all. The v2 SEIPD design is itself the outcome > of Efail (Poddebniak et al., USENIX 2018), where v1's whole-message > integrity failed and applications acted on unauthenticated plaintext. > FLOE (Fábrega, Len, Ristenpart, Rubin; ePrint 2025/2275) formalizes > random-access AEAD security cleanly and gives a proven construction. > This work builds on that formal foundation. > > I've posted draft-sullivan-cfrg-raae-02, "Random-Access Authenticated > Encryption." It covers the primitive, the security notions, the prior > constructions in the space, and a concrete family of instantiations > with test vectors called SEAL (Segmented Encryption and Authentication > Layer), as well as a security analysis (companion paper forthcoming) > and write/rewrite budgets. > > The draft has two layers. raAE is the abstract primitive: the base > interface and security notions come from Fábrega et al., which this > document extends. SEAL is one concrete construction of raAE, > parameterized by an AEAD, a KDF, and an epoch length. It has two > profiles (immutable and mutable) and an optional snapshot authenticator > that binds the whole segment set and updates cheaply on rewrite. A > protocol that would previously have signed the whole encrypted object > can sign the snapshot authenticator instead and get the same > authentication scope without touching the segments. The snapshot > authenticator is also not a single construction, different > authenticators fit different consuming-protocol contexts. For example, > settings that supply only a single CEKs and owner per object versus > settings with a shared CEK (as in MLS) necessitate different > authenticators. > > Freshness against whole-object rollback, storage transactions, and key > management are explicitly out of scope. Those belong in a consuming > protocol. > > The shortest path to a concrete, testable thing is to read > SEAL-simple(AES-256-GCM, HKDF-SHA-256) in Appendix E > <https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-sullivan-cfrg-raae-02.html%23name-seal-simple-implementation-&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C2b5d3a29f3b34311dba908dee17e2832%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196129131599926%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=RB6Qzta8cW2zXvpt2fuW8kUrZ%2FJLvch0g5kH9wBa6G0%3D&reserved=0<https://www.ietf.org/archive/id/draft-sullivan-cfrg-raae-02.html#name-seal-simple-implementation->>, > which is the degenerate case for SEAL with no rewrites or snapshot > authentication and fixed legacy AEAD/KDF. > > Reviews and comments on the framing, the security notions, the > construction, or the scope are all useful. > > Draft: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-sullivan-cfrg-raae-02.html&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C2b5d3a29f3b34311dba908dee17e2832%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196129131636376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=PEqj1VekOr39dDt1di4%2FQNvdrsuR%2BP23JEK635HWbWk%3D&reserved=0<https://www.ietf.org/archive/id/draft-sullivan-cfrg-raae-02.html> > > Best, > Nick > _______________________________________________ > CFRG mailing list -- cfrg@irtf.org > To unsubscribe send an email to cfrg-leave@irtf.org _______________________________________________ CFRG mailing list -- cfrg@irtf.org To unsubscribe send an email to cfrg-leave@irtf.org
- [CFRG] Random-access authenticated encryption (ra… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Martin Thomson
- [CFRG] Re: Random-access authenticated encryption… John Mattsson
- [CFRG] Re: Random-access authenticated encryption… Ilari Liusvaara
- [CFRG] Re: Random-access authenticated encryption… Jack Grigg
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… John Mattsson
- [CFRG] Re: Random-access authenticated encryption… Nico Williams
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… John Mattsson
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Martin Thomson
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Dmitry Belyavsky
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Tushar Patel
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Wang Guilin
- [CFRG] Re: Random-access authenticated encryption… Nick Sullivan
- [CFRG] Re: Random-access authenticated encryption… Wang Guilin
- [CFRG] Re: Random-access authenticated encryption… Nico Williams
- [CFRG] Re: Random-access authenticated encryption… Mark Xue