|
Hi Guy and Hui,
In one paper earlier this year, I made some analysis on the length of nonce. The analysis showed 64 bits would be sufficient for AMP case:
-
Nonces provide freshness and uniqueness. They are transmitted in clear text. I do not see a reason to attack "Nonce".
-
For uniqueness, my previous paper gave calculation that 64 bits already provide sufficient protection against Nonce collision.
-
Also, given the (short) lifetime of AMP devices, there is no reason to use regular length of Nonce, i.e. 256bits.
-
Recall that AMP is designed for low energy/energy harvesting scenario; every bit has cost. If we put Nonce to 32 Octets, then only Anonce + Snonce would be 64 Octets. This is too much for AMP scenarios.
In my opinion, 64 bits would be enough and if we are really concerned, 128 bits would be definitely sufficient.
P.S. The numerical analysis shown in 11-26/0604:
|
|
~50% collision
|
Probability of one repeat after 1 million use
|
|
64-bit Nonce
|
after 2^32 (4.3 billion) uses
|
P≈2.71×10^(-8)
|
|
128-bit Nonce
|
after 2^64 uses
|
P≈1.47×10^(-27)
|
Thanks,
Sam
From: Guy-Armand Kamendje <guy-armand@xxxxxxxx>
Sent: Tuesday, September 1, 2026 6:57 AM
To: STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx <STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx>
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update
I am afraid that Sam's analysis does not consider offline dictionary attacks. I think 8 octets nonces might enable feasible offline dictionary attacks (more evidence is certainly needed to support this claim).
Sixteen or 32-octet nonces would put us on the safe side. My preference goes for 32 octets. Given that handshake is not expected to be a regular operation, the impact on the overal airtime might be limited.
G
Hi Hui,
“I have not found meaningful quantitative analysis about nonce size vs security performance, but there is good reason to worry about real-time attacks if the nonce size is too small, given that currently one
piece SHA256 HW accelerator such as Antminer S21 series can compute hash value 2x10^14 times per second.”
Sam had contributed on the topic in the past:
https://mentor.ieee.org/802.11/dcn/26/11-26-0604-00-00bp-secure-amp-communication-with-reduced-length-anonce-and-snonce.pptx
Best Regards,
Rojan Chitrakar
Hi Rojan,
Thanks for the comments. Please see my responses to most of your comments in the attached document.
Best regards,
Hui
|
Caution:
This e-mail originated outside Infineon Technologies. Please be cautious when sharing information or opening attachments especially from unknown senders. Refer to our
intranet guide to help you identify Phishing email.
|
Hi Hui,
Thanks for the PDT. Added some comments on top of Amichai’s.
Best Regards,
Rojan Chitrakar
Thank you Hui,
Please see attached some comments
Best Regards
Amichai
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
|