Re: [kitten] I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-05.txt

Benjamin Kaduk <kaduk@MIT.EDU> Tue, 03 February 2015 18:35 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 329AF1A1BF5 for <kitten@ietfa.amsl.com>; Tue, 3 Feb 2015 10:35:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SZ-x14UqOoFa for <kitten@ietfa.amsl.com>; Tue, 3 Feb 2015 10:35:48 -0800 (PST)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E33401A1ADF for <kitten@ietf.org>; Tue, 3 Feb 2015 10:35:47 -0800 (PST)
X-AuditID: 12074424-f791c6d000000d25-34-54d1150250fc
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 51.9E.03365.20511D45; Tue, 3 Feb 2015 13:35:46 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t13IZjQp023382; Tue, 3 Feb 2015 13:35:45 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t13IZgs2011430 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 3 Feb 2015 13:35:44 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t13IZg7M003520; Tue, 3 Feb 2015 13:35:42 -0500 (EST)
Date: Tue, 03 Feb 2015 13:35:41 -0500
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Michael Jenkins <m.jenkins.364706@gmail.com>
In-Reply-To: <CAC2=hncRCQoDMgAVunuqugDi1UozH+oWxZX-T5KgMFdXHmLXUA@mail.gmail.com>
Message-ID: <alpine.GSO.1.10.1502031328390.22079@multics.mit.edu>
References: <20140923122546.30735.53089.idtracker@ietfa.amsl.com> <20140930141040.271b6205@willson.usersys.redhat.com> <CAC2=hncRCQoDMgAVunuqugDi1UozH+oWxZX-T5KgMFdXHmLXUA@mail.gmail.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrLIsWRmVeSWpSXmKPExsUixCmqrMskejHE4OQyBYujm1exWCz7dpXN YuP7U4wWP+YuYnVg8dg56y67x5IlP5k83u+7yuaxtfkfYwBLFJdNSmpOZllqkb5dAlfGzrcn 2AqucVXcOdfH1MB4jKOLkYNDQsBE4tCh/C5GTiBTTOLCvfVsILaQwGImiY5Nhl2MXED2BkaJ 3WunskMkDjJJnF8EZddLNPxvYgeZwyKgJfHzdQRImE1ARWLmm41gc0QEDCQWTVoHZjML5Eo8 65vODFIuLOAn8eFvJkiYUyBQ4sPJqawgNq+Ao0THnutsEGt3M0ocW3yFBSQhKqAjsXr/FBaI IkGJkzOfsEDM1JJYPn0bywRGwVlIUrOQpBYwMq1ilE3JrdLNTczMKU5N1i1OTszLSy3SNdfL zSzRS00p3cQICmV2F5UdjM2HlA4xCnAwKvHwOihdCBFiTSwrrsw9xCjJwaQkypshfDFEiC8p P6UyI7E4I76oNCe1+BCjBAezkgjvnt9A5bwpiZVVqUX5MClpDhYlcd5NP/hChATSE0tSs1NT C1KLYLIyHBxKErxOIEMFi1LTUyvSMnNKENJMHJwgw3mAhj8CqeEtLkjMLc5Mh8ifYlSUEudd C5IQAElklObB9cJSzStGcaBXhHm1RYCqeIBpCq77FdBgJqDBshdBri4uSURISTUwhu74siVM 1qFq3/WvjvsuFyfOazpdUjcjcI0lg+8Gtm/mvtsVPs578GJdv3K577Zrvd3Xirl+77a+8fLu 4o7tJ6sT12/x0VM72Lh12tyOviaN1eqmlWwyizIuumWVXuL73Hv839zpy69Y71iUWvVM18Dc TOvm+vWn3kStiPqd4iL57M6EMuvFGkosxRmJhlrMRcWJAM059BkQAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/_nRnoInABtjCO8BQFRR6wYyBYs8>
Cc: kitten@ietf.org, "mjjenki@tycho.ncsc.mil" <mjjenki@tycho.ncsc.mil>, Simo Sorce <simo@redhat.com>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-05.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Feb 2015 18:35:50 -0000

On Mon, 2 Feb 2015, Michael Jenkins wrote:

> the document than say "because Suite B". I propose that the following
> paragraph be added to the Security Considerations section (8) to address
> the entire document, rather than to litter the document with in-place
> explanations:
>
> 8.2    Algorithm dimensions
>
> Although there is nothing in this document that constrains its application,

It's not entirely clear what "constraints its application" is intended to
mean here; I would prefer an alternate phrasing.

> it has been written to be consistent with common implementations of AES and
> SHA-2. The  encryption and hash algorithm sizes have been chosen to create
> a consistent level of protection, with consideration to implementation
> efficiencies. So, for instance, SHA-384, which would normally be matched to
> AES-192, is instead matched to AES-256 to leverage the fact that there are
> efficient hardware implementations of AES-256.

I wonder if there is a way to say that the combination of SHA-384 and
AES-256 as used in this document "only has 192 bits of security" (to the
extent that the concept of bits of security can even be defined).

> Would this suffice? If so, I'll generate an -06 version and upload it in
> time for Dallas.

That would be fine for me, but let's give Simo some time to reply as well.

-Ben