Re: QUIC-LB update: Eliminate block ciphers?

Martin Thomson <> Wed, 06 October 2021 22:13 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 1EA113A097A for <>; Wed, 6 Oct 2021 15:13:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key) header.b=MCQIDsX8; dkim=pass (2048-bit key) header.b=ljUGwfoH
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id U92fARZrp3NV for <>; Wed, 6 Oct 2021 15:13:10 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 30BFB3A08ED for <>; Wed, 6 Oct 2021 15:13:09 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal []) by mailout.west.internal (Postfix) with ESMTP id 77A663201C81 for <>; Wed, 6 Oct 2021 18:13:06 -0400 (EDT)
Received: from imap41 ([]) by compute5.internal (MEProxy); Wed, 06 Oct 2021 18:13:06 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type; s=fm3; bh=1mx3X4nTjKh8lWRmAThUwXUZ7pf50Nl huXa+x0bvZ+A=; b=MCQIDsX8EYM/oN/41woUnNSJmjB/SRMRysi3Ht/jrfkHFnn dAUNaH7AMLFGKxg43T9qnMd1DS/sAPHTCI8LCprrZzkyEk1fs9TGVwz7ncmNvKGF rvAZFdnEvD/BwgIc4cW/ggIYlaXuSkmSKigJtBzIDBgrlyul5q5oR6lq/6VrhkUW drg/9IeOTg9ZiL4/65LWNfCmedmzZr44BbpsxFN3UR80xaLNNxnK01bA0uh78CQO QSxbWox4ZU2kB/uABTzbTtSC+jAbwy+GWWDC0Vwy9abVBwn3T74fLOCDKuvgNUbr qg8+jZcTwCuwSukwl5m/nJQvE9OU+nq2pnOCPvg==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=1mx3X4 nTjKh8lWRmAThUwXUZ7pf50NlhuXa+x0bvZ+A=; b=ljUGwfoHI7t9lC+MofEQnZ +xS9OrgbZgJ/gxIb9osSXjoRuohMjQ3vv33DdlnMiiGbvqAvRRmhPQ+pgYnqb/2b JSt68pFfJpTPiCQHSZly8/kKjFE8m3FtQg6yOGbmVD3DAhIxb+/7+RxbUJQeEt6X CFJnw9jdkbtYrs1o8xsp+jwkHEd7IHsNhpK3vwolk2/dVWievWL6+nab6QALwwtO rHOdc0C7H7K6gZJPAb06j9Z6HVERt1RK/JlrIoViOhZR3thN7RlSUiLYcnTalBch uy8+ysaHPVMeKhkm2qNfptkzsxlIsj1yV1wCrRG7EBZ9GzUaJu48XwFlG/n+j8HA ==
X-ME-Sender: <xms:cR9eYfndIw_c0FmQ0nUgHyG1b7qCJS7xDWFqV8bq6bUeJqppRBlUbQ> <xme:cR9eYS1VNYOuSrnZ_3L4vbybaOy8jEM97uCpKiB-b8eIG0A2Zv6yXwJafj5GHQ76n BSfjs1ti3-o9R9iKPY>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddrudeljedgtdefucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefofgggkfgjfhffhffvufgtsehttd ertderredtnecuhfhrohhmpedfofgrrhhtihhnucfvhhhomhhsohhnfdcuoehmtheslhho figvnhhtrhhophihrdhnvghtqeenucggtffrrghtthgvrhhnpeekteeuieektdekleefke evhfekffevvdevgfekgfeluefgvdejjeegffeigedtjeenucevlhhushhtvghrufhiiigv pedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehmtheslhhofigvnhhtrhhophihrdhnvg ht
X-ME-Proxy: <xmx:cR9eYVoKGEuGWKQXRMcv4iLyUGyC1lV6GNCBI3NHdMGCAlz7n6TNWw> <xmx:cR9eYXmwZG7eAB-PLvEn6x3tlAS93CozhoLd90LmPi2GJi4AaVE6EA> <xmx:cR9eYd2dO1Gr5tIoKhoLSzsn6v7EfyI5pLPYFU2b9e0fC3MYCFiV8w> <xmx:ch9eYeCuyoJnHSJr4zpHqdLI12PmnXjD9cDiPlnmOaMRvjB0CQCrJw>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id E63913C0246; Wed, 6 Oct 2021 18:13:05 -0400 (EDT)
X-Mailer: Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-1331-g5ae342296a-fm-20211005.001-g5ae34229
Mime-Version: 1.0
Message-Id: <>
In-Reply-To: <>
References: <> <> <> <> <> <>
Date: Thu, 07 Oct 2021 09:12:46 +1100
From: Martin Thomson <>
Subject: Re: QUIC-LB update: Eliminate block ciphers?
Content-Type: text/plain
Archived-At: <>
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 06 Oct 2021 22:13:15 -0000

On Thu, Oct 7, 2021, at 07:02, Christian Huitema wrote:
> Phil,
> What we have in the current LB spec is called a "stream cipher", but 
> that's a misnomer. What we have in the spec is actually a variable size 
> block cipher, derived from AES-ECB using a construct similar to FFX. 
> Your review of that algorithm would be appreciated.


I would call this a Feistel network, but avoid talking about FFX.  FFX has a bunch of guidance about the number of iterations of the network that this ignores; to call this FFX or even imply that it is FFX isn't really fair.  When you get right down to it, the real contribution in FFX is the analysis that produces guidance on the number of iterations and the inclusion of tweaks; if you use neither, then it's not really FFX.  As additional iterations are necessary to maintain a security level, we need to be careful about the claims we make in relation to security.