Re: [Cfrg] I-D Action: draft-irtf-cfrg-gcmsiv-04.txt

"Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk> Fri, 24 February 2017 00:07 UTC

Return-Path: <Kenny.Paterson@rhul.ac.uk>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C0A881293E4 for <cfrg@ietfa.amsl.com>; Thu, 23 Feb 2017 16:07:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.92
X-Spam-Level:
X-Spam-Status: No, score=-1.92 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=rhul.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ipDfE034ft3O for <cfrg@ietfa.amsl.com>; Thu, 23 Feb 2017 16:07:05 -0800 (PST)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0040.outbound.protection.outlook.com [104.47.2.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 102E91293E1 for <cfrg@ietf.org>; Thu, 23 Feb 2017 16:07:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rhul.onmicrosoft.com; s=selector1-rhul-ac-uk; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=ySXGpx671osuMLs5y7fdW0E5l069fhfPnVYSrNyVX4o=; b=SHhvz//7P32q2nnjbezO0IvdduruqFY+w8fvdPhmz04GUet/I5DNjz3HQhUZlNdZphTnKT0+n4UeHSKGfaknp6eOlz+Xv/ImusqN2NNqWI+74XQI9N9h+4hSDm/xOjotOFdex4tzDyV+TPv8dsxtw0hGpf9iz9PVBFjtP68DmDg=
Received: from AM4PR0301MB1906.eurprd03.prod.outlook.com (10.168.2.156) by AM4PR0301MB1905.eurprd03.prod.outlook.com (10.168.2.155) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.919.13; Fri, 24 Feb 2017 00:07:00 +0000
Received: from AM4PR0301MB1906.eurprd03.prod.outlook.com ([10.168.2.156]) by AM4PR0301MB1906.eurprd03.prod.outlook.com ([10.168.2.156]) with mapi id 15.01.0919.018; Fri, 24 Feb 2017 00:06:59 +0000
From: "Paterson, Kenny" <Kenny.Paterson@rhul.ac.uk>
To: Adam Langley <agl@imperialviolet.org>, "cfrg@ietf.org" <cfrg@ietf.org>
Thread-Topic: [Cfrg] I-D Action: draft-irtf-cfrg-gcmsiv-04.txt
Thread-Index: AQHSjfILPJEKyD2c8U+2aZYUqmbh9aF2yOAAgAB/nAA=
Date: Fri, 24 Feb 2017 00:06:59 +0000
Message-ID: <D4D52910.8A146%kenny.paterson@rhul.ac.uk>
References: <148786730667.20244.7762484121330383342.idtracker@ietfa.amsl.com> <CAMfhd9VumcZ76MJjx3Kr8gw6mbUJc7x_pPcSDR2V0Jiuz+sm-w@mail.gmail.com>
In-Reply-To: <CAMfhd9VumcZ76MJjx3Kr8gw6mbUJc7x_pPcSDR2V0Jiuz+sm-w@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.7.1.161129
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Kenny.Paterson@rhul.ac.uk;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [183.77.227.125]
x-microsoft-exchange-diagnostics: 1; AM4PR0301MB1905; 7:4xrXIyaHcqiKHnZHzuGTDZegQZ9S+pu9jdTV6vD/2b8x+Td2qmKMfEvIi+kNguI8NyJtSHnJCax/5kV6Y/Aw3eIZByYKco+Y+dgUP4oixz0onjyUEnnoyXjN35C0+MymRBEewDWrepMrw3EKJ5T+YjOB5yI7cgQQ0l38U4bHxfYpfU/veKOI2fFaSeHmQOH9KpZX/v4oJ6XCLgQ5hlF+jUy4EuSglwSQwDeBKn2JRawdhJb4M286gZTOsMmHqFkGwSMhKDAn2brELj8iCqPaihOgkDzn/sQSZs63Xp4zJT1ZEYkRoZjPl+3hJLiNWJjEPoPjIubRKZ3MpdrfKDDudA==
x-forefront-antispam-report: SFV:SKI; SCL:-1SFV:NSPM; SFS:(10009020)(6009001)(7916002)(39450400003)(377454003)(24454002)(189002)(199003)(377424004)(2900100001)(74482002)(106356001)(92566002)(5660300001)(53546006)(3280700002)(50986999)(229853002)(81156014)(97736004)(54356999)(81166006)(3660700001)(2906002)(36756003)(76176999)(8676002)(101416001)(25786008)(106116001)(105586002)(4001350100001)(102836003)(68736007)(6436002)(6486002)(66066001)(230783001)(99286003)(189998001)(77096006)(2950100002)(6506006)(6116002)(83506001)(2501003)(8936002)(38730400002)(7736002)(305945005)(42882006)(86362001)(122556002)(6306002)(3846002)(6246003)(6512007)(53936002); DIR:OUT; SFP:1101; SCL:1; SRVR:AM4PR0301MB1905; H:AM4PR0301MB1906.eurprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
x-ms-office365-filtering-correlation-id: 75fe67d4-b8e4-4259-cc32-08d45c490d8b
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001); SRVR:AM4PR0301MB1905;
x-microsoft-antispam-prvs: <AM4PR0301MB19057CE5FB4C18E182796053BC520@AM4PR0301MB1905.eurprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6041248)(20161123555025)(20161123562025)(20161123560025)(20161123564025)(20161123558025)(6072148); SRVR:AM4PR0301MB1905; BCL:0; PCL:0; RULEID:; SRVR:AM4PR0301MB1905;
x-forefront-prvs: 0228DDDDD7
received-spf: None (protection.outlook.com: rhul.ac.uk does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <A18A190B877BC343A1C7380849C4386A@eurprd03.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: rhul.ac.uk
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Feb 2017 00:06:59.5175 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2efd699a-1922-4e69-b601-108008d28a2e
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR0301MB1905
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/sWfgR_P_To75BxAdhRBU6LCDr6M>
Subject: Re: [Cfrg] I-D Action: draft-irtf-cfrg-gcmsiv-04.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Feb 2017 00:07:08 -0000

Dear Adam, 

Thank you to you, Shay and Yehuda for putting this paper together and for
updating the draft.

I think Section 7 of the paper is particularly helpful, and I would like
to direct people there for a good discussion of nonce misuse resistance
and an explanation of what this scheme achieves.

Regards,

Kenny 

On 23/02/2017 16:32, "Cfrg on behalf of Adam Langley"
<cfrg-bounces@irtf.org on behalf of agl@imperialviolet.org> wrote:

>On Thu, Feb 23, 2017 at 8:28 AM,  <internet-drafts@ietf.org> wrote:
>> A New Internet-Draft is available from the on-line Internet-Drafts
>>directories.
>> This draft is a work item of the Crypto Forum of the IETF.
>>
>>         Title           : AES-GCM-SIV: Nonce Misuse-Resistant
>>Authenticated Encryption
>>         Authors         : Shay Gueron
>>                           Adam Langley
>>                           Yehuda Lindell
>>         Filename        : draft-irtf-cfrg-gcmsiv-04.txt
>>         Pages           : 46
>>         Date            : 2017-02-23
>
>Dear all,
>
>Revision 04 of the AES-GCM-SIV draft
>(https://tools.ietf.org/html/draft-irtf-cfrg-gcmsiv-04) has just been
>published. This contains only tidy-ups from revision 03—no substantive
>changes have been made.
>
>Most importantly, it now references a paper
>(https://eprint.iacr.org/2017/168) by Shay and Yehuda in which they
>give precise security bounds for AES-GCM-SIV. Specifically I'd like to
>highlight to the group theorem six (which gives those bounds) and
>section 5.3 (which gives concrete values of those bounds at a number
>of locations in the configuration space).
>
>In light of previous discussions in the working group, section seven
>includes some remarks about the meaning of nonce-misuse resistance.
>
>(Comments about the paper, including sightings of typos, are welcome
>to be sent to us directly; no need to clutter this list with them.)
>
>
>Cheers
>
>AGL
>
>_______________________________________________
>Cfrg mailing list
>Cfrg@irtf.org
>https://www.irtf.org/mailman/listinfo/cfrg