3 ms·
For context, this is describing an updated AES-GCM-SIV construction following a number of attacks reported by NSA earlier this year: https://mailarchive.ietf.o
by bascule 10y ago
For context, this is describing an updated AES-GCM-SIV construction following a number of attacks reported by NSA earlier this year:
https://mailarchive.ietf.org/arch/attach/cfrg/pdfL0pM_N.pdf https://mailarchive.ietf.org/arch/attach/cfrg/pdfL0pM_N.pdf
Several cryptographers have been wary of this construction, both because of the history of attacks and also because it generally hasn't lived up to the goals of (nonce) "misuse resistant authenticated encryption" as described in the seminal Rogaway paper on the matter:
https://eprint.iacr.org/2006/221.pdf https://eprint.iacr.org/2006/221.pdf
It will be interesting to see more analysis on the latest version. For the intended use case (QUIC ticket encryption) it would be helpful.
- azet 10y agoFor the record: I'm not a cryptographer. :)