Hi Sam,
Thanks for your comments!
ANonce and SNonce have two uses in 4-way handshake. The first use is to avoid generating identical PTKs by a given PMK. Your collision probability analysis is applicable here.
The second use is to serve as the input for a keyed challenge and response authentication protocol. I have been trying to find some quantitative analysis on the second use, but so far inconclusive. I also chatted with other experts. It seems people only feel
qualitatively the size of these nonces cannot be too small. That’s why I suggest these nonces to be 128 bits each, jointly making a 256-bit entropy as the input for the authentication purpose. However, the strength of 4-way handshake authentication (keyed
challenge and response) is mainly dependent of the key size and the MIC size. It seems CCMP-128’s 64-bit authentication tag could be the MIC in our case. So 256-bit input entropy might be a bit too much for a 64-bit MIC. Again, I have no quantitative reasoning
to support such feeling.
Best regards,
Hui
From: Sam Shi <Sam.Shi@xxxxxxxxxxxxxxxx>
Sent: Wednesday, September 2, 2026 3:35 AM
To: STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update
|
Caution: This
e-mail originated outside Infineon Technologies. Please be cautious when sharing information or opening attachments especially from unknown senders. Refer to our intranet
guide to help you identify Phishing email.
|
Hi Guy and Hui,
In one paper earlier this year, I made some analysis on the length of nonce. The analysis showed 64 bits would be sufficient for AMP case:
- Nonces provide freshness and uniqueness. They are transmitted in clear text. I do not see a reason to attack "Nonce".
- For uniqueness, my previous paper gave calculation that 64 bits already provide sufficient protection against Nonce collision.
- Also, given the (short) lifetime of AMP devices, there is no reason to use regular length of Nonce, i.e. 256bits.
- Recall that AMP is designed for low energy/energy harvesting scenario; every bit has cost. If we put Nonce to 32 Octets, then only Anonce + Snonce would be 64 Octets. This is too much for AMP
scenarios.
In my opinion, 64 bits would be enough and if we are really concerned, 128 bits would be definitely sufficient.
P.S. The numerical analysis shown in 11-26/0604:
|
|
~50% collision
|
Probability of one repeat after 1 million use
|
|
64-bit Nonce
|
after 2^32 (4.3 billion) uses
|
P≈2.71×10^(-8)
|
|
128-bit Nonce
|
after 2^64 uses
|
P≈1.47×10^(-27)
|
Thanks,
Sam
From: Guy-Armand Kamendje <guy-armand@xxxxxxxx>
Sent: Tuesday, September 1, 2026 6:57 AM
To: STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx <STDS-802-11-TGBP@xxxxxxxxxxxxxxxxx>
Subject: Re: [STDS-802-11-TGBP] PDT Security General Update
I am afraid that Sam's analysis does not consider offline dictionary attacks. I think 8 octets nonces might enable feasible offline dictionary attacks (more evidence is certainly needed to support this claim).
Sixteen or 32-octet nonces would put us on the safe side. My preference goes for 32 octets. Given that handshake is not expected to be a regular operation, the impact on the overal airtime might be limited.
G
On Tue, Sep 1, 2026 at 3:22 AM Rojan Chitrakar <00002005fb56ded7-dmarc-request@xxxxxxxxxxxxxxxxx> wrote:
Hi Hui,
“I have not found meaningful quantitative analysis about nonce size vs security performance, but there is good reason to worry about real-time attacks if the nonce size is too small, given that currently one piece SHA256 HW accelerator such as Antminer S21
series can compute hash value 2x10^14 times per second.”
Sam had contributed on the topic in the past:
https://mentor.ieee.org/802.11/dcn/26/11-26-0604-00-00bp-secure-amp-communication-with-reduced-length-anonce-and-snonce.pptx
Best Regards,
Rojan Chitrakar
Hi Rojan,
Thanks for the comments. Please see my responses to most of your comments in the attached document.
Best regards,
Hui
|
Caution:
This e-mail originated outside Infineon Technologies. Please be cautious when sharing information or opening attachments especially from unknown senders. Refer to our
intranet guide to help you identify Phishing email.
|
Hi Hui,
Thanks for the PDT. Added some comments on top of Amichai’s.
Best Regards,
Rojan Chitrakar
Thank you Hui,
Please see attached some comments
Best Regards
Amichai
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link:
https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1
To unsubscribe from the STDS-802-11-TGBP list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBP&A=1