Dan:
So given the choice of "wraps keys of arbitrary length, binds associated data to wrapped keys, provably secure" or "wraps keys of arbitrary length" why would you not want to go with the former?
I have no objection to looking at other key wrap algorithms. This one is already FIPS-approved, and it is very unclear what the time schedule would be for another one to become FIPS-approved.
Russ