[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Cfrg] draft-housley-ccm-mode-00.txt



daw@mozart.cs.berkeley.edu (David Wagner) writes:
>Peter Gutmann wrote:
>>If it's truly unencumbered, I'd like to see this as standards-track.
>
>Can you elaborate?  What advantages do you see for CCM over the standard
>encrypt-then-authenticate generic composition of AES-CBC encryption and AES-
>CBC-MAC (suitably modified to be secure for variable-length messages)?  The
>latter is unencumbered and has the same performance characteristics as CCM.

I was thinking more of OCB and its assorted ancestors and relatives (with
accompanying extended family of patents).  I'd be happy with any unencumbered,
reasonably clean encrypt+MAC combo (note that's encrypt+MAC, not encrypt-then-
MAC), Russ just happened to get there first with his CCM draft.

Peter.


_______________________________________________
Cfrg mailing list
Cfrg@ietf.org
https://www1.ietf.org/mailman/listinfo/cfrg