QUIC WG, Yesterday we submitted a draft that proposes to use GCM-SST Cipher for (D)TLS and QUIC. The advantage of this cipher is that its authentication tag properties are much closer to ideal and do remove AES-GCM’s downside. AES-GCM has the property if an attacker ever succeeds with a forgery and can determine its success it gets a large number of bits out of the authentication key H, thus making subsequent forgeries much simpler.
This proposal also defines in addition to the 128-bit keyed AES-GCM-SST also defines the 256-bit keyed AES-256-GCM-SST (with 128 bit blocks) as well as RIJNDAEL_GCM_SST which is the same type of algorithm as AES-GCM-SST but with 256 bit keys and 256 bit blocks. For these we have defines ciphers with truncated authentication tags to 96 and 112 bits. However, I think this is one area where we should have some discussion. The 96-bit is chosen to be at least as strong as AES-GCM with 128-bit authentication tags and the 112 to be stronger. However, are these tags length the right choice? Cheers Magnus From: [email protected] <[email protected]> Date: Monday, 6 July 2026 at 15:35 To: John Mattsson <[email protected]>; John Mattsson <[email protected]>; Magnus Westerlund <[email protected]> Subject: New Version Notification for draft-westerlund-tls-gcm-sst-00.txt A new version of Internet-Draft draft-westerlund-tls-gcm-sst-00.txt has been successfully submitted by Magnus Westerlund and posted to the IETF repository. Name: draft-westerlund-tls-gcm-sst Revision: 00 Title: Use of Galois Counter Mode with Strong Secure Tags (GCM-SST) in TLS, DTLS and QUIC Date: 2026-07-06 Group: Individual Submission Pages: 10 URL: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-westerlund-tls-gcm-sst-00.txt&data=05%7C02%7Cmagnus.westerlund%40ericsson.com%7C448b7ef61cc74750815a08dedb637507%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639189417374133964%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=VaZQMmANOd1O9bU4xqvNviJSIXqo%2BcgTvJERix%2FiHGI%3D&reserved=0<https://www.ietf.org/archive/id/draft-westerlund-tls-gcm-sst-00.txt> Status: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-westerlund-tls-gcm-sst%2F&data=05%7C02%7Cmagnus.westerlund%40ericsson.com%7C448b7ef61cc74750815a08dedb637507%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639189417374162862%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=d9kavRI8O5ekjG7Y3roqengU6wYq5GE%2B7XoFt9DmZFA%3D&reserved=0<https://datatracker.ietf.org/doc/draft-westerlund-tls-gcm-sst/> HTMLized: https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-westerlund-tls-gcm-sst&data=05%7C02%7Cmagnus.westerlund%40ericsson.com%7C448b7ef61cc74750815a08dedb637507%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639189417374192463%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=I8WrDlENG3UR1gXeIZLZ%2BbcNOvi5B1SmT04qDTGx7iQ%3D&reserved=0<https://datatracker.ietf.org/doc/html/draft-westerlund-tls-gcm-sst> Abstract: This document defines cipher suites based on AES-GCM-SST and Rijndael-GCM-SST (Galois Counter Mode with Strong Secure Tags) for use in TLS 1.3, DTLS 1.3, and QUIC. GCM-SST provides authenticated encryption with near-ideal forgery probabilities for short authentication tags, making it suitable for bandwidth-constrained environments where reduced per-packet overhead is important. This document specifies cipher suites with 96-bit and 112-bit authentication tags. The IETF Secretariat
