Skip to content

SIV properly handle zero AD components#777

Open
karel-m wants to merge 1 commit into
developfrom
pr/siv-zero-ad
Open

SIV properly handle zero AD components#777
karel-m wants to merge 1 commit into
developfrom
pr/siv-zero-ad

Conversation

@karel-m

@karel-m karel-m commented Jul 18, 2026

Copy link
Copy Markdown
Member

This PR fixes an SIV corner case that occurs when zero AD components are used.

Checklist

  • tests are added or updated

@karel-m
karel-m requested a review from sjaeckel July 18, 2026 21:18

@sjaeckel sjaeckel left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This has been discussed on the IETF ML [0] and FMU it was unconclusive.

Now I'm not sure if merging this would make our implementation worse, since we already allow a zero-length nonce...

[0] https://mailarchive.ietf.org/arch/msg/cfrg/Gu5cyorHPLrQ_CGYe775Xc6SV1c/

@karel-m

karel-m commented Jul 21, 2026

Copy link
Copy Markdown
Member Author

I did not look into it that deeply. I mainly wanted to be compatible with OpenSSL SIV implementation.

You are right, it may need more investigation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants