[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: Two AES encryption modes?
On 29 Jul 2002, Andrew Krywaniuk wrote:
> A typical transform payload (including the header) for IKEv1 will run about
> 32 bytes for phase 1 and 24 bytes for phase 2. Eight bytes of that is the SA
> lifetime, which has been omitted from IKEv2. The real problem in terms of
> bandwidth consumption was permutation explosion, which has also been solved
> in IKEv2.
Unless I've missed something, the use of suites rather than individual
combinations of transforms -- which is precisely what we are debating --
is how that was solved. The problem with transforms is not that they are
individually bulky, but that they come in swarms, not one at a time.
> My claim is not so much that the cost is not important, but rather that it
> will be drowned out by other factors...
My claim is that you need to justify that more -- it's not a self-evident
truth.
Henry Spencer
henry@spsystems.net