3 ms·
Reasonable question! (1) OCB has long had a patent grant for GPLed software (https://github.com/mobile-shell/mosh/blob/master/ocb-license.html https://github.c
by keithwinstein 8y ago
Reasonable question!
(1) OCB has long had a patent grant for GPLed software (https://github.com/mobile-shell/mosh/blob/master/ocb-license.html https://github.com/mobile-shell/mosh/blob/master/ocb-license...), so the Rogaway patents were a non-issue even in 2011. (Of course there are other patents on authenticated encryption, e.g. IBM's Jutla patents. I understand why OCB gets singled out because of the Rogaway patents, but my understanding is that all AE modes, and perhaps most computer programs in general, likely implicate some patent.)
(2) The crypto experts told us that OCB was the best AEAD mode and that if we are going to put all our eggs in one basket, we should pick OCB. I am pretty happy with the choice and with the lack of traditional cipher negotiation in Mosh.
(3) Implementation quality strongly favored OCB. At the time, OpenSSL had no AE modes at all, so we probably would have had to vendor and ship an implementation of something not-OCB, or use a non-AE construction. I understand OpenSSL had a lot of pain implementing GCM in a robust way over the subsequent years -- if we had depended on OpenSSL or tried to use its AE modes, we would have inherited that pain.
Given our position of wanting to pick one mode and lock it in (which seems to have paid off), I don't think we could have made a better choice in 2011 than AES-OCB. I might make the same choice today, but would look harder at the other available AE modes in OpenSSL.
- loeg 8y agoThanks! The details really help me understand the options available and why the choice was made. I appreciate your taking the time to answer the question thoroughly.