Hi IPSECME, We've just published an updated version of our I-D specifying the use of AES-GCM-SIV in ESP and IKEv2. Version -01 updates the introduction and fixes some other typos from the -00.
Any feedback is welcome. We're additionally curious if there are thoughts on the following items, some of which are included as ednotes in draft: * Is it okay to rename the IKE IV field to Nonce (since GCM-SIV has a nonce instead of an IV)? * We'd prefer to recommend that nonces be entirely random. This is different from AES-GCM where the nonces are implicit. * We opt to set the GCM-SIV authentication tag as the ESP ICV field, as opposed included at the end of the ciphertext field. Best, Casey ________________________________ From: [email protected] <[email protected]> Sent: Wednesday, September 16, 2026 9:29 AM To: Casey Wynn (GOV) <[email protected]>; Nicholas Gajcowski (GOV) <[email protected]>; Rebecca Guthrie <[email protected]> Subject: New Version Notification for draft-guthrie-ipsecme-aes-gcm-siv-01.txt A new version of Internet-Draft draft-guthrie-ipsecme-aes-gcm-siv-01.txt has been successfully submitted by Casey Wynn and posted to the IETF repository. Name: draft-guthrie-ipsecme-aes-gcm-siv Revision: 01 Title: Using AES-GCM-SIV in the Internet Protocol Version 2 (IKEv2) and Encapsulating Security Payload (ESP) Protocols Date: 2026-09-16 Group: Individual Submission Pages: 9 URL: https://www.ietf.org/archive/id/draft-guthrie-ipsecme-aes-gcm-siv-01.txt Status: https://datatracker.ietf.org/doc/draft-guthrie-ipsecme-aes-gcm-siv HTML: https://www.ietf.org/archive/id/draft-guthrie-ipsecme-aes-gcm-siv-01.html HTMLized: https://datatracker.ietf.org/doc/html/draft-guthrie-ipsecme-aes-gcm-siv-01 Diff: https://author-tools.ietf.org/iddiff?url2=draft-guthrie-ipsecme-aes-gcm-siv-01 Abstract: This document specifies the use of AES-GCM-SIV in the Internet Key Exchange Protocol version 2 (IKEv2) and the Encapsulating Security Payload (ESP) protocols. This document also adds AES-GCM-SIV to the IANA IKEv2 registry for "Transform Type 1 - Encryption Algorithm Transform IDs." AES-GCM-SIV is a nonce misuse-resistant authenticated encryption with associated data (AEAD) algorithm based on AES-GCM. The IETF Secretariat
_______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
