Re: [TLS] Salsa20 stream cipher in TLS

Wan-Teh Chang <wtc@google.com> Mon, 18 March 2013 19:49 UTC

Return-Path: <wtc@google.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B860E21F904B for <tls@ietfa.amsl.com>; Mon, 18 Mar 2013 12:49:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.978
X-Spam-Level:
X-Spam-Status: No, score=-101.978 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id isVjVdicPj1a for <tls@ietfa.amsl.com>; Mon, 18 Mar 2013 12:49:05 -0700 (PDT)
Received: from mail-ie0-x233.google.com (mail-ie0-x233.google.com [IPv6:2607:f8b0:4001:c03::233]) by ietfa.amsl.com (Postfix) with ESMTP id C7A3221F8FAC for <tls@ietf.org>; Mon, 18 Mar 2013 12:48:51 -0700 (PDT)
Received: by mail-ie0-f179.google.com with SMTP id k11so7442274iea.38 for <tls@ietf.org>; Mon, 18 Mar 2013 12:48:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=ptXySJh+gW1crGcIb+mifuN/1RadHY9lXYZg31IxYpo=; b=hZdsJ/UBS+kKMG/Rz7oVxGnlkp9mI2+nlSn74jDNq7nEHVgurYtnpsHbD+W/GE24W3 dSJz6wKakT1iN1mWkt82zHG2OCGqUAbeVSaTU2mZeJENrg9ESbx6oKaYaBB8TTp+uKXr 5LR1riMjgS3jK2IKbVUWLl8MadCurXnrrCSAdEwmyKVaUWtN1vRq3CBZcqR+OJsYVf9K ufUZa6lMnCDlbcPbWL9XB22FQBPiFt8O3xdN9H0NI62weXptEc2G/FBy02fAV6JnnBmv eM8ukZp7SvSxohyleQ+Qn/b+HW8cc1B9BBN8cVhSLDc0GQ3MPmUKjpV20KX6exWDgiX1 kPKg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type:x-gm-message-state; bh=ptXySJh+gW1crGcIb+mifuN/1RadHY9lXYZg31IxYpo=; b=Uqk0dixlC9nzjv+kVEQ7FZZjPSI/AasMJpfL647CyFpBZXm/T5cxf0/IChlfbtUEI2 l3kR9kEQgd6RvfpiLrej/+wHlHDzzrXg+/1ItJXQM+asIGI//NA90nQWZV61Ou9Ga6xy R6xFyNu3oWcPUqwsNKGnRKfIW7xmfY30eXW37Vpc6Lc9izNWKmhr1UiLj7P/s2zoy3Qb ERfzsXJnegYXlao2gJ7hT8KU8a16huDYeJNo9dgpIOPV5BavYyAMor9MSK5A/URU8T9o pu1wLH9t+4ply3zVOUsdaqhlcNhWs73BU1/XAmS4DN3AR3SkvWxpUTmOC6rO7DkUuD5Z jWjQ==
MIME-Version: 1.0
X-Received: by 10.50.152.229 with SMTP id vb5mr125374igb.56.1363636131204; Mon, 18 Mar 2013 12:48:51 -0700 (PDT)
Received: by 10.231.112.2 with HTTP; Mon, 18 Mar 2013 12:48:51 -0700 (PDT)
In-Reply-To: <747787E65E3FBD4E93F0EB2F14DB556B183EB8AD@xmb-rcd-x04.cisco.com>
References: <87ppyxhc6y.fsf@latte.josefsson.org> <747787E65E3FBD4E93F0EB2F14DB556B183EB8AD@xmb-rcd-x04.cisco.com>
Date: Mon, 18 Mar 2013 12:48:51 -0700
Message-ID: <CALTJjxG7H+TTLeDW279SK5fWi13c2HPpkFKt3gLhv7VD__p0Cg@mail.gmail.com>
From: Wan-Teh Chang <wtc@google.com>
To: "David McGrew (mcgrew)" <mcgrew@cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"
X-Gm-Message-State: ALoCoQnHVS/ffbVpMxgAAUD6fGyWHO4b4jJ7R0Jvux4NOZC7yv4UpHZ78FB/TD7Tfr434UFlrCvWxPD0u2syQKmvm3X1HCdOogAy0WkBwfuokbgx6jj6wwmnJXYQc00BdsZYNag3wx3uLuBY39dYJWxxnXLmaFh37Ver9fV4FyesdDL/F9enL6ZZXJrwwkb5zGxafxAsj4Vb
Cc: Simon Josefsson <simon@josefsson.org>, "cfrg@irtf.org" <cfrg@irtf.org>, "joachim@secworks.se" <joachim@secworks.se>, "tls@ietf.org" <tls@ietf.org>
Subject: Re: [TLS] Salsa20 stream cipher in TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Mar 2013 19:49:13 -0000

On Sun, Mar 17, 2013 at 3:51 PM, Simon Josefsson <simon@josefsson.org> wrote:
> All,
>
> FYI, we have published -00 of a draft that describes how the Salsa20
> stream cipher can be added to TLS and DTLS, see:
>
> http://tools.ietf.org/html/draft-josefsson-salsa20-tls

Hi Simon,

I am interested in this work. I am especially interested in your plan
to allow the salsa20 cipher suites to be used in TLS 1.0 and TLS
1.1, which you stated in the first paragraph of the Introduction
section.

Since all of the new cipher suite names end in _SHA256, I
infer the MAC algorithm is hmac_sha256. (The fact is
not explicitly stated in the -00 draft.) It is important to
clarify how hmac_sha256 can be used in TLS 1.0 and
TLS 1.1, because a naive implementor would see the old
definition of MACAlgorithm in TLS 1.0 and 1.1:

    enum { null, md5, sha } MACAlgorithm;

and conclude that hmac_sha256 can't be used in TLS
1.0 and 1.1.

I'm also interested in figuring out if these cipher suites
can be used in SSL 3.0. The only difficulty I see is
extending the SSL 3.0 MAC algorithm to hash=sha256
(see the definition of the SSL 3.0 MAC in Section 5.2.3.1
of RFC 6101) -- it is not clear what should be the size of
pad_1 and pad_2 for hash=sha256.

The reason I'm interested in SSL 3.0 is that web browsers,
when talking to Google servers, which implement TLS/SSL
version negotiation correctly, are still downgraded to SSL 3.0
by network errors injected by certain network devices.

Wan-Teh