There is a newer paper that has a better analysis (tighter, more comprehensive) here: https://eprint.iacr.org/2018/993
You can also find other references in https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-aead-limits to analyses of ChaCha20-Poly1305 and AES-CCM as well as better formulae for limits. On Thu, Nov 23, 2023, at 01:55, Antoine FRESSANCOURT wrote: > Hello, > > Thanks to both of you for your answers ! > > Best regards, > > Antoine > > -----Original Message----- > From: QUIC <[email protected]> On Behalf Of Sauli Kiviranta > Sent: mercredi 22 novembre 2023 15:49 > To: Max Franke <[email protected]> > Cc: [email protected] > Subject: Re: Looking for paper in informative reference of RFC 9001 > > Hi Antoine & Max, > > You can also use Internet Archive: > > https://web.archive.org/web/20211215094639/https://www.isg.rhul.ac.uk/~kp/TLS-AEbounds.pdf > > Best regards, > Sauli > > On 11/22/23, Max Franke <[email protected]> wrote: >> Hi, >> >> looks like the server that hosted it at rhul is having some issues, >> but you can find a htmlised version here: >> https://scholar.googleusercontent.com/scholar?q=cache:IUmsjyFbOU8J:sch >> olar.google.com/ >> >> Best, >> >> Max >> >> On 22.11.23 10:24, Antoine FRESSANCOURT wrote: >>> >>> Hello, >>> >>> While trying to answer a question about key lifetime in AES, I looked >>> at RFC 9001 (Using TLS to Secure QUIC) and I realized that the first >>> informative reference ([AEBounds] Luykx, A. and K. Paterson, "Limits >>> on Authenticated Encryption Use in TLS", 28 August 2017, >>> <https://www.isg.rhul.ac.uk/~kp/TLS-AEbounds.pdf>.) is not accessible >>> online (or at least I couldn’t find it even if I tried for 30 minutes). >>> >>> Does anybody have a copy of the PDF the RFC refers to ? Would you >>> mind sharing it with me ? Do you have an idea how to retrieve this paper ? >>> >>> Thanks in advance, >>> >>> >>> Antoine >>>
