QUIC WG,

Yesterday we submitted a draft that proposes to use GCM-SST Cipher for (D)TLS 
and QUIC. The advantage of this cipher is that its authentication tag 
properties are much closer to ideal and do remove AES-GCM’s downside. AES-GCM 
has the property if an attacker ever succeeds with a forgery and can determine 
its success it gets a large number of bits out of the authentication key H, 
thus making subsequent forgeries much simpler.

This proposal also defines in addition to the 128-bit keyed AES-GCM-SST also 
defines the 256-bit keyed AES-256-GCM-SST (with 128 bit blocks) as well as 
RIJNDAEL_GCM_SST which is the same type of algorithm as AES-GCM-SST but with 
256 bit keys and 256 bit blocks.

For these we have defines ciphers with truncated authentication tags to 96 and 
112 bits. However, I think this is one area where we should have some 
discussion. The 96-bit is chosen to be at least as strong as AES-GCM with 
128-bit authentication tags and the 112 to be stronger. However, are these tags 
length the right choice?

Cheers

Magnus

From: [email protected] <[email protected]>
Date: Monday, 6 July 2026 at 15:35
To: John Mattsson <[email protected]>; John Mattsson 
<[email protected]>; Magnus Westerlund <[email protected]>
Subject: New Version Notification for draft-westerlund-tls-gcm-sst-00.txt

A new version of Internet-Draft draft-westerlund-tls-gcm-sst-00.txt has been
successfully submitted by Magnus Westerlund and posted to the
IETF repository.

Name:     draft-westerlund-tls-gcm-sst
Revision: 00
Title:    Use of Galois Counter Mode with Strong Secure Tags (GCM-SST) in TLS, 
DTLS and QUIC
Date:     2026-07-06
Group:    Individual Submission
Pages:    10
URL:      
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-westerlund-tls-gcm-sst-00.txt&data=05%7C02%7Cmagnus.westerlund%40ericsson.com%7C448b7ef61cc74750815a08dedb637507%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639189417374133964%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=VaZQMmANOd1O9bU4xqvNviJSIXqo%2BcgTvJERix%2FiHGI%3D&reserved=0<https://www.ietf.org/archive/id/draft-westerlund-tls-gcm-sst-00.txt>
Status:   
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-westerlund-tls-gcm-sst%2F&data=05%7C02%7Cmagnus.westerlund%40ericsson.com%7C448b7ef61cc74750815a08dedb637507%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639189417374162862%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=d9kavRI8O5ekjG7Y3roqengU6wYq5GE%2B7XoFt9DmZFA%3D&reserved=0<https://datatracker.ietf.org/doc/draft-westerlund-tls-gcm-sst/>
HTMLized: 
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-westerlund-tls-gcm-sst&data=05%7C02%7Cmagnus.westerlund%40ericsson.com%7C448b7ef61cc74750815a08dedb637507%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639189417374192463%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=I8WrDlENG3UR1gXeIZLZ%2BbcNOvi5B1SmT04qDTGx7iQ%3D&reserved=0<https://datatracker.ietf.org/doc/html/draft-westerlund-tls-gcm-sst>


Abstract:

   This document defines cipher suites based on AES-GCM-SST and
   Rijndael-GCM-SST (Galois Counter Mode with Strong Secure Tags) for
   use in TLS 1.3, DTLS 1.3, and QUIC.  GCM-SST provides authenticated
   encryption with near-ideal forgery probabilities for short
   authentication tags, making it suitable for bandwidth-constrained
   environments where reduced per-packet overhead is important.  This
   document specifies cipher suites with 96-bit and 112-bit
   authentication tags.



The IETF Secretariat


Reply via email to