Re: [TLS] Data limit for GCM under a given key.

2015-11-07 Thread Yoav Nir
> On 7 Nov 2015, at 12:50 PM, Eric Rescorla wrote: > > > > On Fri, Nov 6, 2015 at 7:46 PM, Yoav Nir > wrote: > > > On 7 Nov 2015, at 11:39 AM, Dave Garrett > > wrote: > > > > On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wr

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Quynh Dang
Hi Eric and Watson, On Sat, Nov 7, 2015 at 12:50 PM, Eric Rescorla wrote: > > > On Fri, Nov 6, 2015 at 7:46 PM, Yoav Nir wrote: > >> >> > On 7 Nov 2015, at 11:39 AM, Dave Garrett >> wrote: >> > >> > On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wrote: >> >> Update: we discussed this e

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Dang, Quynh
. From: Tony Arcieri Sent: Friday, November 6, 2015 7:59 PM To: Watson Ladd Cc: Dang, Quynh; tls@ietf.org Subject: Re: [TLS] Data limit for GCM under a given key. On Friday, November 6, 2015, Watson Ladd mailto:watsonbl...@gmail.com>> wrote: On Wed, Nov 4, 2015 at 3:43 PM, Dang, Quynh wrote: &

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Dave Garrett
On Friday, November 06, 2015 10:54:02 pm Eric Rescorla wrote: > I don't believe time-based guidance is useful here, given that it's highly > situation specific rather than derived from reasoning about the properties > of the cipher. One reason to have a regular interval between rekeys is to ensure

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Eric Rescorla
On Fri, Nov 6, 2015 at 7:50 PM, Eric Rescorla wrote: > > > On Fri, Nov 6, 2015 at 7:46 PM, Yoav Nir wrote: > >> >> > On 7 Nov 2015, at 11:39 AM, Dave Garrett >> wrote: >> > >> > On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wrote: >> >> Update: we discussed this extensively in Yokohama

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Eric Rescorla
On Fri, Nov 6, 2015 at 6:39 PM, Dave Garrett wrote: > On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wrote: > > Update: we discussed this extensively in Yokohama and based on Watson's > > feedback and offline comments from David McGrew, the consensus was that > we > > needed to add some s

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Eric Rescorla
On Fri, Nov 6, 2015 at 7:46 PM, Yoav Nir wrote: > > > On 7 Nov 2015, at 11:39 AM, Dave Garrett wrote: > > > > On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wrote: > >> Update: we discussed this extensively in Yokohama and based on Watson's > >> feedback and offline comments from David M

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Yoav Nir
> On 7 Nov 2015, at 11:39 AM, Dave Garrett wrote: > > On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wrote: >> Update: we discussed this extensively in Yokohama and based on Watson's >> feedback and offline comments from David McGrew, the consensus was that we >> needed to add some sort

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Dave Garrett
On Friday, November 06, 2015 08:13:44 pm Eric Rescorla wrote: > Update: we discussed this extensively in Yokohama and based on Watson's > feedback and offline comments from David McGrew, the consensus was that we > needed to add some sort of rekeying mechanism to support long-lived flows. > Expect

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Eric Rescorla
Update: we discussed this extensively in Yokohama and based on Watson's feedback and offline comments from David McGrew, the consensus was that we needed to add some sort of rekeying mechanism to support long-lived flows. Expect a PR on this next week. Note: We'll still need guidance to implementa

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Tony Arcieri
On Friday, November 6, 2015, Watson Ladd wrote: > On Wed, Nov 4, 2015 at 3:43 PM, Dang, Quynh > wrote: > > I did not talk under indistinguishability framework. My discussion was > about confidentiality protection and authentication. > > What is the definition of "confidentiality protection" bei

Re: [TLS] Data limit for GCM under a given key.

2015-11-06 Thread Watson Ladd
here? > > Quynh. > > From: Watson Ladd > Sent: Wednesday, November 4, 2015 3:17:00 PM > To: Dang, Quynh > Cc: Eric Rescorla; tls@ietf.org > Subject: Re: [TLS] Data limit for GCM under a given key. > > On Wed, Nov 4, 2015 at 2:29 PM, Dang, Quynh wrote: >>

Re: [TLS] Data limit for GCM under a given key.

2015-11-04 Thread Dang, Quynh
: [TLS] Data limit for GCM under a given key. On Wed, Nov 4, 2015 at 2:29 PM, Dang, Quynh wrote: > Hi Eric and all, > > > The limit of 2^48 packets under a given key for GCM you mentioned today is > the limit for SRTP > (https://tools.ietf.org/html/draft-ietf-avtcore-srtp-ae

Re: [TLS] Data limit for GCM under a given key.

2015-11-04 Thread Watson Ladd
On Wed, Nov 4, 2015 at 2:29 PM, Dang, Quynh wrote: > Hi Eric and all, > > > The limit of 2^48 packets under a given key for GCM you mentioned today is > the limit for SRTP > (https://tools.ietf.org/html/draft-ietf-avtcore-srtp-aes-gcm-17#section-6). > The nonce space of the IV construction is only