4 ms·
This is pretty cool. But IOT tends to fail hard on key agreement. And nothing here solves that. This seems to pretty much require a pre installed key, otherwise
by rocqua 1y ago
This is pretty cool. But IOT tends to fail hard on key agreement. And nothing here solves that. This seems to pretty much require a pre installed key, otherwise the overhead of securely installing a key would probably nullify the advantage of this encryption.
- tptacek 1y agoRight, it's a competition to standardize authenticated encryption constructions, not entire cryptosystems.
- LeGrosDadai 1y agoBy the same token AES is useless as well, because it doesn't address key exchange. This was not the goal of this standardization process.
- rocqua 1y agoMy point was that AES and SHA are not the reason IOT cryptography is so often broken or missing. Instead its getting the keys onto the system in a halfway secure manner that is the blocking issue. Hence I'd be a lot more enthusiastic about NIST guidance on these points.
- dvdkon 1y agoA pairing system as seen in e.g. Zigbee or BLE seems pretty good to me. Not everyone cares to implement it well and there's still no standard for web-based devices, but it's here and it works. I'd like to see more devices able to pair with NFC, but even that's standardised for Bluetooth, just underused.
- LeGrosDadai 1y agoAh, I see. That's indeed an interesting point. At any rate, IOT cryptography can use this standard as a building point, so it is a step in the right direction anyway.
- brohee 1y agoThe world that the algorithm targets is exactly where is this doable. MCUs typically have a protected OTP area that makes it a good place to inject keys right in the factory.