Skip to content

Commit

Permalink
That was a little unclear on a re-read
Browse files Browse the repository at this point in the history
  • Loading branch information
martinthomson committed Jan 29, 2018
1 parent 509afe9 commit f94ef09
Showing 1 changed file with 5 additions and 4 deletions.
9 changes: 5 additions & 4 deletions draft-ietf-quic-tls.md
Original file line number Diff line number Diff line change
Expand Up @@ -1603,10 +1603,11 @@ effectively random.
All the AEAD functions used meet indistinguishability under (adaptive) chosen
plaintext attack (IND-CPA, IND-CPA2) goals and produce minimal expansion of the
plaintext, adding only an authentication tag. Therefore, this document assumes
that the sampled AEAD output is unpredictable and not subject to influence by an
attacker. Based on this assumption, the odds of producing identical input to a
packet protection algorithm approach the birthday bound on the size of the input
(that is, one divided by the square root of the number of possible values).
that each bit of sampled AEAD output contains one bit of entropy and that an
attacker is unable to reduce this without knowledge of the key. Based on this
assumption, the odds of producing identical input to a packet protection
algorithm approach the birthday bound on the size of the input (that is, one
divided by the square root of the number of possible values).

Note:

Expand Down

0 comments on commit f94ef09

Please sign in to comment.