RE: Security Use Requirements

Michael Krause <krause@cup.hp.com> Thu, 08 February 2001 16:23 UTC

Received: from ece.cmu.edu (ECE.CMU.EDU [128.2.236.200]) by ietf.org (8.9.1a/8.9.1a) with SMTP id LAA12144 for <ips-archive@odin.ietf.org>; Thu, 8 Feb 2001 11:23:47 -0500 (EST)
Received: (from majordom@localhost) by ece.cmu.edu (8.11.0/8.10.2) id f18EHeK08103 for ips-outgoing; Thu, 8 Feb 2001 09:17:40 -0500 (EST)
X-Authentication-Warning: ece.cmu.edu: majordom set sender to owner-ips@ece.cmu.edu using -f
Received: from palrel3.hp.com (palrel3.hp.com [156.153.255.226]) by ece.cmu.edu (8.11.0/8.10.2) with ESMTP id f18EGkH08067 for <ips@ece.cmu.edu>; Thu, 8 Feb 2001 09:16:46 -0500 (EST)
Received: from hpindlm.cup.hp.com (hpindlm.cup.hp.com [15.13.95.89]) by palrel3.hp.com (Postfix) with ESMTP id A1D3F448; Thu, 8 Feb 2001 06:16:45 -0800 (PST)
Received: from mk731913.cup.hp.com (mk731912.cup.hp.com [15.8.80.111]) by hpindlm.cup.hp.com (8.9.3 (PHNE_18979)/8.9.3 SMKit7.02) with ESMTP id GAA24887; Thu, 8 Feb 2001 06:19:31 -0800 (PST)
Message-Id: <5.0.2.1.2.20010208061424.00a8a428@hpindlm.cup.hp.com>
X-Sender: krause@hpindlm.cup.hp.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 08 Feb 2001 06:16:27 -0800
To: Michael Eisler <mre@zambeel.com>
From: Michael Krause <krause@cup.hp.com>
Subject: RE: Security Use Requirements
Cc: ips@ece.cmu.edu
In-Reply-To: <Roam.SIMC.2.0.6.981593759.11529.mre@zambeel.com>
References: <"Your message with ID" <5.0.0.25.2.20010207155733.00a63d00@10.30.15.2>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ips@ece.cmu.edu
Precedence: bulk

At 04:55 PM 2/7/2001 -0800, Michael Eisler wrote:
>Why use DES, which is slow for software implementations, when AES
>is there, is fast, and has little dispute about its safety?
>
>draft-ietf-ipsec-ciph-aes-cbc-01.txt proposes a means
>for using AES in IPsec.
>
>draft-ietf-tls-ciphersuite-03.txt proposes a means for
>using AES in TLS.
>
>3DES is really, really slow for software to the point of being impractical.
>While one can always mandate it for implementation, in practice I doubt any
>customer using a software 3DES over ips will want to use it.

How fast is AES in hardware?  3DES is link-rate in hardware today and in 
wide use by many products.  While software implementations are interesting 
/ value to some, most high-speed implementations, e.g. 1 / 10 GbE, will 
require hardware acceleration and thus the preference is to focus on 
hardware friendly solutions wherever possible.

Mike