Re: [TLS] STRAW POLL: Size of the Minimum FF DHE group

Andrey Jivsov <crypto@brainhub.org> Tue, 04 November 2014 19:51 UTC

Return-Path: <crypto@brainhub.org>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4D7241A7029 for <tls@ietfa.amsl.com>; Tue, 4 Nov 2014 11:51:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2g0n9l2jF7UX for <tls@ietfa.amsl.com>; Tue, 4 Nov 2014 11:51:14 -0800 (PST)
Received: from resqmta-po-03v.sys.comcast.net (resqmta-po-03v.sys.comcast.net [IPv6:2001:558:fe16:19:96:114:154:162]) (using TLSv1 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2D6501A6FEB for <tls@ietf.org>; Tue, 4 Nov 2014 11:51:13 -0800 (PST)
Received: from resomta-po-06v.sys.comcast.net ([96.114.154.230]) by resqmta-po-03v.sys.comcast.net with comcast id BXqv1p0064yXVJQ01XrDUJ; Tue, 04 Nov 2014 19:51:13 +0000
Received: from [IPv6:::1] ([71.202.164.227]) by resomta-po-06v.sys.comcast.net with comcast id BXrC1p00N4uhcbK01XrCwD; Tue, 04 Nov 2014 19:51:13 +0000
Message-ID: <54592E30.2000208@brainhub.org>
Date: Tue, 04 Nov 2014 11:51:12 -0800
From: Andrey Jivsov <crypto@brainhub.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.1.1
MIME-Version: 1.0
To: tls@ietf.org
References: <8E6B8F53-9E8C-46B2-A721-85E918576F3A@ieca.com>
In-Reply-To: <8E6B8F53-9E8C-46B2-A721-85E918576F3A@ieca.com>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 8bit
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcast.net; s=q20140121; t=1415130673; bh=4eW1HAyEevJ1w/ReejydiximhUlVp6MQizfMwCKFU4g=; h=Received:Received:Message-ID:Date:From:MIME-Version:To:Subject: Content-Type; b=N9AX+tPMj19Mt/5gy/Zfww2aPTh1IxuRicqCPZo75wr2cBntTxvmLutqvVk49u4tl Lh7n3joAR/QNRXIxmCS3l/gTIIuXGemFUXHBwqTWLFYSgSxCsCcn1ctWrAf9rOegtJ FubXS9IFyTl5i/yxjoa7XFkf56YnB7J3RuIbhkYqwSmNw1PBUsn1k8hpfFRzpkDFuk 0wZ0ehC2OxYklPWg6Psr6MdJnYoiZY7Nls0bjSqFq03JEvgyV2WknrUA9up6KMRoCX xi9K17n7j+V4wGa77BSbQAxlUW0hkMU5f6S80IldZG22knQapgPEJvaN6/RkdP37pB 9AZhwq7saXCoA==
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/v-LqfAujoiK1iVJFDC9nvWoO4OU
Subject: Re: [TLS] STRAW POLL: Size of the Minimum FF DHE group
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 04 Nov 2014 19:51:16 -0000

On 11/04/2014 09:49 AM, Sean Turner wrote:
> 2) There is some disagreement about the work factor for the DLOG keys - e.g., NIST says 112-bit work factor correlates to 2048-bit DLOG keys but ECRYPT-II says 112-bit work factor correlates to 2432-bit DLOG keys (see references in draft).
>
> 3) The other point made about 2048-bit DLOG is that it’s a power of 2 and there’s parity with the public key sizes.

An interesting question is if 2432 is optimal to accommodate wide words 
/ vector arithmetic.

2^9 * 5 = 2560  (5 512-bit units, or 10 128-bit units)
2^7 * 19 = 2432 (128 bit units)

Besides, there is a benefit to pick a round number. For example, RSA 
2048 is much faster than 2432 in openssl master today on x86.

So, while I am OK with a stronger size, 2432 looks like sub-optimal, so 
of these two I would select RSA 2048.