Network Working Group P. Hoffman Request for Comments: 3664 VPN Consortium Category: Standards Track January 2004The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE)
1. Introduction
[AES-XCBC-MAC] describes a method to use the Advanced Encryption Standard (AES) as a message authentication code (MAC) whose output is 96 bits long. While 96 bits is considered appropriate for a MAC, it is too short to be useful as a long-lived pseudo-random (PRF) in either IKE version 1 or version 2. Both versions of IKE use the PRF to create keys in a fashion that is dependent on the length of the output of the PRF. Using a PRF that has 96 bits of output creates keys that are easier to attack with brute force than a PRF that uses 128 bits of output.
Hoffman Standards Track [Page 1]
RFC 3664 The AES-XCBC-PRF-128 Algorithm for IKE January 2004 2. The AES-XCBC-PRF-128 AlgorithmThe AES-XCBC-PRF-128 algorithm is identical to [AES-XCBC-MAC] except that the truncation step in section 4.3 of [AES-XCBC-MAC] is *not* performed. That is, there is no processing after section 4.2 of [AES-XCBC-MAC].
3. Security Considerations
The security provided by AES-XCBC-MAC-PRF is based upon the strength of AES. At the time of this writing, there are no known practical cryptographic attacks against AES or AES-XCBC-MAC-PRF.
4. Intellectual Property Statement
The IETF takes no position regarding the validity or scope of any intellectual property or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; neither does it represent that it has made any effort to identify any such rights. Information on the IETF's procedures with respect to rights in standards-track and standards-related documentation can be found in BCP-11. Copies of claims of rights made available for publication and any assurances of licenses to be made available, or the result of an attempt made to obtain a general license or permission for the use of such proprietary rights by implementors or users of this specification can be obtained from the IETF Secretariat.
Hoffman Standards Track [Page 2]
RFC 3664 The AES-XCBC-PRF-128 Algorithm for IKE January 2004 5. References 5.1. Normative References[AES-XCBC-MAC] Frankel, S. and H. Herbert, "The AES-XCBC-MAC-96
6. Author's Address
Paul Hoffman VPN Consortium 127 Segre Place Santa Cruz, CA 95060 USA
Hoffman Standards Track [Page 3]
RFC 3664 The AES-XCBC-PRF-128 Algorithm for IKE January 2004 7. Full Copyright StatementCopyright (C) The Internet Society (2004). All Rights Reserved.