Hi IPSECME,

We've just published an updated version of our I-D specifying the use of 
AES-GCM-SIV in ESP and IKEv2.  Version -01 updates the introduction and fixes 
some other typos from the -00.

Any feedback is welcome.  We're additionally curious if there are thoughts on 
the following items, some of which are included as ednotes in draft:

  *
Is it okay to rename the IKE IV field to Nonce (since GCM-SIV has a nonce 
instead of an IV)?
  *
We'd prefer to recommend that nonces be entirely random.  This is different 
from AES-GCM where the nonces are implicit.
  *
We opt to set the GCM-SIV authentication tag as the ESP ICV field, as opposed 
included at the end of the ciphertext field.


Best,
Casey


________________________________
From: [email protected] <[email protected]>
Sent: Wednesday, September 16, 2026 9:29 AM
To: Casey Wynn (GOV) <[email protected]>; Nicholas Gajcowski (GOV) 
<[email protected]>; Rebecca Guthrie <[email protected]>
Subject: New Version Notification for draft-guthrie-ipsecme-aes-gcm-siv-01.txt

A new version of Internet-Draft draft-guthrie-ipsecme-aes-gcm-siv-01.txt has
been successfully submitted by Casey Wynn and posted to the
IETF repository.

Name:     draft-guthrie-ipsecme-aes-gcm-siv
Revision: 01
Title:    Using AES-GCM-SIV in the Internet Protocol Version 2 (IKEv2) and 
Encapsulating Security Payload (ESP) Protocols
Date:     2026-09-16
Group:    Individual Submission
Pages:    9
URL:     
https://www.ietf.org/archive/id/draft-guthrie-ipsecme-aes-gcm-siv-01.txt
Status:  https://datatracker.ietf.org/doc/draft-guthrie-ipsecme-aes-gcm-siv
HTML:  https://www.ietf.org/archive/id/draft-guthrie-ipsecme-aes-gcm-siv-01.html
HTMLized: 
https://datatracker.ietf.org/doc/html/draft-guthrie-ipsecme-aes-gcm-siv-01
Diff:      
https://author-tools.ietf.org/iddiff?url2=draft-guthrie-ipsecme-aes-gcm-siv-01
Abstract:


   This document specifies the use of AES-GCM-SIV in the Internet Key
   Exchange Protocol version 2 (IKEv2) and the Encapsulating Security
   Payload (ESP) protocols.  This document also adds AES-GCM-SIV to the
   IANA IKEv2 registry for "Transform Type 1 - Encryption Algorithm
   Transform IDs."  AES-GCM-SIV is a nonce misuse-resistant
   authenticated encryption with associated data (AEAD) algorithm based
   on AES-GCM.



The IETF Secretariat


_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to