[要約] RFC 4615は、IKEv2プロトコル等で用いられるAES-CMACベースの疑似乱数関数(AES-CMAC-PRF-128)アルゴリズムを定義しています。可変長鍵をAES-CMACを用いて128ビット鍵に変換し、鍵生成素材の生成や認証に適用する手順を規定しています。HMAC以外の選択肢を提供し、特にハードウェア実装においてAES暗号リソースを効率的に再利用可能にすることを目的としています。

Network Working Group                                            J. Song
Request for Comments: 4615                                 R. Poovendran
Category: Standards Track                       University of Washington
                                                                  J. Lee
                                                     Samsung Electronics
                                                                T. Iwata
                                                       Nagoya University
                                                             August 2006
        

The Advanced Encryption Standard-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128) Algorithm for the Internet Key Exchange Protocol (IKE)

インターネット鍵交換プロトコル(IKE)のための高度暗号化標準暗号ベースのメッセージ認証コード擬似ランダム関数128(AES-CMAC-PRF-128)アルゴリズム

Status of This Memo

本文書の状態

This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the "Internet Official Protocol Standards" (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited.

この文書は、インターネットコミュニティ向けのインターネット標準トラックプロトコルを規定し、改善のための議論と提案を募集するものです。このプロトコルの標準化状態およびステータスについては、最新の「インターネット公式プロトコル標準」(STD 1)を参照してください。このメモの配布は無制限です。

Copyright Notice

著作権表示

Copyright (C) The Internet Society (2006).

Copyright (C) The Internet Society (2006).

Abstract

概要

Some implementations of IP Security (IPsec) may want to use a pseudo-random function (PRF) based on the Advanced Encryption Standard (AES). This memo describes such an algorithm, called AES-CMAC-PRF-128. It supports fixed and variable key sizes.

IPセキュリティ(IPsec)の一部の実装では、高度暗号化標準(AES)に基づく疑似乱数関数(PRF)を使用したい場合があります。このメモでは、AES-CMAC-PRF-128と呼ばれるそのようなアルゴリズムについて説明します。これは固定および可変の鍵サイズをサポートします。

Table of Contents

目次

   1. Introduction ....................................................2
   2. Basic Definitions ...............................................2
   3. The AES-CMAC-PRF-128 Algorithm ..................................2
   4. Test Vectors ....................................................4
   5. Security Considerations .........................................4
   6. IANA Considerations .............................................5
   7. Acknowledgements ................................................5
   8. References ......................................................5
      8.1. Normative References .......................................5
      8.2. Informative References .....................................5
        
1. Introduction
1. はじめに

[RFC4493] describes a method to use the Advanced Encryption Standard (AES) as a Message Authentication Code (MAC) that has a 128-bit output length. The 128-bit output is useful as a long-lived pseudo-random function (PRF). This document specifies a PRF that supports fixed and variable key sizes for IKEv2 [RFC4306] Key Derivation Function (KDF) and authentication.

[RFC4493] は、128ビットの出力長を持つメッセージ認証コード(MAC)として高度暗号化標準(AES)を使用する方法を説明しています。この128ビット出力は、長期的な疑似乱数関数(PRF)として有用です。本書では、IKEv2 [RFC4306] の鍵導出関数(KDF)および認証において、固定および可変の鍵サイズをサポートするPRFを規定します。

2. Basic Definitions
2. 基本的な定義

VK Variable-length key for AES-CMAC-PRF-128, denoted by VK.

VK VKで表される、AES-CMAC-PRF-128の可変長鍵です。

0^128 The string that consists of 128 zero-bits, which is equivalent to 0x00000000000000000000000000000000 in hexadecimal notation.

0^128 128個のゼロビットからなる文字列であり、16進表記の0x00000000000000000000000000000000に相当します。

AES-CMAC The AES-CMAC algorithm with a 128-bit long key described in section 2.4 of [RFC4493].

AES-CMAC [RFC4493] のセクション2.4で説明されている、128ビット長の鍵を使用するAES-CMACアルゴリズムです。

3. The AES-CMAC-PRF-128 Algorithm
3. AES-CMAC-PRF-128アルゴリズム

The AES-CMAC-PRF-128 algorithm is identical to AES-CMAC defined in [RFC4493] except that the 128-bit key length restriction is removed.

AES-CMAC-PRF-128アルゴリズムは、128ビットの鍵長制限が削除されている点を除き、[RFC4493] で定義されているAES-CMACと同一です。

IKEv2 [RFC4306] uses PRFs for multiple purposes, most notably for generating keying material and authentication of the IKE_SA. The IKEv2 specification differentiates between PRFs with fixed key sizes and those with variable key sizes.

IKEv2 [RFC4306] は、主に鍵生成素材の生成や IKE_SA の認証など、複数の目的で PRF を使用します。IKEv2 仕様では、固定鍵サイズの PRF と可変鍵サイズの PRF を区別しています。

When using AES-CMAC-PRF-128 as the PRF described in IKEv2, AES-CMAC-PRF-128 is considered to take fixed size (16 octets) keys for generating keying material but it takes variable key sizes for authentication.

IKEv2で説明されているPRFとしてAES-CMAC-PRF-128を使用する場合、AES-CMAC-PRF-128は鍵生成素材の生成には固定サイズ(16オクテット)の鍵を使用するとみなされますが、認証には可変サイズの鍵を使用します。

That is, when generating keying material, "half the bits must come from Ni and half from Nr, taking the first bits of each" as described in IKEv2, section 2.14; but for authenticating with shared secrets (IKEv2, section 2.16), the shared secret does not have to be 16 octets and the length may vary.

すなわち、鍵生成素材を生成する際、IKEv2のセクション2.14に記載されているように、「ビットの半分はNiから、残り半分はNrから、それぞれの最初のビットを取得しなければならない」とされていますが、共有秘密鍵(IKEv2のセクション2.16)による認証の場合、共有秘密鍵は16オクテットである必要はなく、長さが異なる場合があります。

   +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
   +                        AES-CMAC-PRF-128                           +
   +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
   +                                                                   +
   + Input  : VK (Variable-length key)                                 +
   +        : M (Message, i.e., the input data of the PRF)             +
   +        : VKlen (length of VK in octets)                           +
   +        : len (length of M in octets)                              +
   + Output : PRV (128-bit Pseudo-Random Variable)                     +
   +                                                                   +
   +-------------------------------------------------------------------+
   + Variable: K (128-bit key for AES-CMAC)                            +
   +                                                                   +
   + Step 1.   If VKlen is equal to 16                                 +
   + Step 1a.  then                                                    +
   +               K := VK;                                            +
   + Step 1b.  else                                                    +
   +               K := AES-CMAC(0^128, VK, VKlen);                    +
   + Step 2.   PRV := AES-CMAC(K, M, len);                             +
   +           return PRV;                                             +
   +                                                                   +
   +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
        

Figure 1. The AES-CMAC-PRF-128 Algorithm

図1. AES-CMAC-PRF-128アルゴリズム

In step 1, the 128-bit key, K, for AES-CMAC is derived as follows:

ステップ1では、AES-CMAC用の128ビット鍵 K が以下のように導出されます。

o If the key, VK, is exactly 128 bits, then we use it as-is.

o 鍵 VK が正確に128ビットである場合、それをそのまま使用します。

o If it is longer or shorter than 128 bits, then we derive the key, K, by applying the AES-CMAC algorithm using the 128-bit all-zero string as the key and VK as the input message. This step is described in step 1b.

o 128ビットより長いか短い場合、128ビットの全ゼロ文字列を鍵とし、VKを入力メッセージとしてAES-CMACアルゴリズムを適用することにより、鍵 K を導出します。このステップはステップ1bで説明されています。

In step 2, we apply the AES-CMAC algorithm using K as the key and M as the input message. The output of this algorithm is returned.

ステップ2では、Kを鍵、Mを入力メッセージとしてAES-CMACアルゴリズムを適用します。このアルゴリズムの出力が返されます。

4. Test Vectors
4. テストベクトル
   ------------------------------------------------------------

   Test Case AES-CMAC-PRF-128 with 20-octet input
   Key        : 00010203 04050607 08090a0b 0c0d0e0f edcb
   Key Length : 18
   Message    : 00010203 04050607 08090a0b 0c0d0e0f 10111213
   PRF Output : 84a348a4 a45d235b abfffc0d 2b4da09a

   Test Case AES-CMAC-PRF-128 with 20-octet input
   Key        : 00010203 04050607 08090a0b 0c0d0e0f
   Key Length : 16
   Message    : 00010203 04050607 08090a0b 0c0d0e0f 10111213
   PRF Output : 980ae87b 5f4c9c52 14f5b6a8 455e4c2d

   Test Case AES-CMAC-PRF-128 with 20-octet input
   Key        : 00010203 04050607 0809
   Key Length : 10
   Message    : 00010203 04050607 08090a0b 0c0d0e0f 10111213
   PRF Output : 290d9e11 2edb09ee 141fcf64 c0b72f3d

   ------------------------------------------------------------
        
5. Security Considerations
5. セキュリティに関する考慮事項

The security provided by AES-CMAC-PRF-128 is based upon the strength of AES and AES-CMAC. At the time of this writing, there are no known practical cryptographic attacks against AES or AES-CMAC. However, as is true with any cryptographic algorithm, part of its strength lies in the secret key, VK, and the correctness of the implementation in all of the participating systems. The key, VK, needs to be chosen independently and randomly based on RFC 4086 [RFC4086], and both keys, VK and K, should be kept safe and periodically refreshed. Section 4 presents test vectors that assist in verifying the correctness of the AES-CMAC-PRF-128 code.

AES-CMAC-PRF-128が提供するセキュリティは、AESおよびAES-CMACの強度に基づいています。本書の執筆時点では、AESまたはAES-CMACに対する実用的な暗号攻撃は知られていません。しかし、他のいかなる暗号アルゴリズムにも当てはまるように、その強さの一部は秘密鍵 VK と、すべての参加システムにおける実装の正確性にあります。鍵 VK は RFC 4086 [RFC4086] に基づいて独立かつランダムに選択される必要があり、VK と K の両方の鍵は安全に保管され、定期的に更新されるべきです。セクション4では、AES-CMAC-PRF-128コードの正確性の検証に役立つテストベクトルを提示しています。

If VK is longer than 128 bits and it is shortened to meet the AES-128 key size, then some entropy might be lost. However, as long as VK is longer than 128 bits, then the new key, K, preserves sufficient entropy, i.e., the entropy of K is about 128 bits.

VKが128ビットより長く、AES-128の鍵サイズに合わせるために短縮される場合、一部のエントロピーが失われる可能性があります。しかし、VKが128ビットより長い限り、新しい鍵 K は十分なエントロピーを維持します。すなわち、K のエントロピーは約128ビットです。

Therefore, we recommend the use of VK that is longer than or equal to 128 bits, and we discourage the use of VK that is shorter than or equal to 64 bits, because of the small entropy.

したがって、128ビット以上の VK の使用を推奨し、エントロピーが小さいため、64ビット以下の VK の使用は推奨しません。

6. IANA Considerations
6. IANAの考慮事項

IANA has allocated a value of 8 for IKEv2 Transform Type 2 (Pseudo-Random Function) to the PRF_AES128_CMAC algorithm.

IANAは、IKEv2のTransform Type 2(疑似乱数関数)において、PRF_AES128_CMACアルゴリズムに対して値8を割り当てました。

7. Acknowledgements
7. 謝辞

Portions of this text were borrowed from [RFC3664] and [RFC4434]. Many thanks to Russ Housley and Paul Hoffman for suggestions and guidance. We also thank Alfred Hoenes for many useful comments.

本書の一部分は [RFC3664] および [RFC4434] から借用されました。提案とガイダンスをいただいた Russ Housley 氏と Paul Hoffman 氏に深く感謝いたします。また、多くの有益なコメントをいただいた Alfred Hoenes 氏にも感謝いたします。

We acknowledge support from the following grants: Collaborative Technology Alliance (CTA) from US Army Research Laboratory, DAAD19-01-2-0011; Presidential Award from Army Research Office,- W911NF-05-1-0491; ONR YIP N00014-04-1-0479. Results do not reflect any position of the funding agencies.

私たちは、以下の助成金からの支援に感謝します:米国陸軍研究所からのCollaborative Technology Alliance (CTA)、DAAD19-01-2-0011、陸軍研究室からの大統領賞(W911NF-05-1-0491)、ONR YIP(N00014-04-1-0479)。なお、本成果は資金提供機関のいかなる立場も反映するものではありません。

8. References
8. 参考文献
8.1. Normative References
8.1. 引用文献

[RFC4493] Song, JH., Poovendran, R., Lee, J., and T. Iwata, "The AES-CMAC Algorithm", RFC 4493, June 2006.

[RFC4493] Song, J.H., Poovendran, R., Lee, J., and T. Iwata, "The AES-CMAC Algorithm", RFC 4493, June 2006. https://datatracker.ietf.org/doc/html/rfc4493

[RFC4306] Kaufman, C., "Internet Key Exchange (IKEv2) Protocol", RFC 4306, December 2005.

[RFC4306] Kaufman, C., "Internet Key Exchange (IKEv2) Protocol", RFC 4306, December 2005. https://datatracker.ietf.org/doc/html/rfc4306

[RFC4086] Eastlake, D., 3rd, Schiller, J., and S. Crocker, "Randomness Requirements for Security", BCP 106, RFC 4086, June 2005.

[RFC4086] Eastlake, D., 3rd, Schiller, J., and S. Crocker, "Randomness Requirements for Security", BCP 106, RFC 4086, June 2005. https://datatracker.ietf.org/doc/html/rfc4086

8.2. Informative References
8.2. 参考引用

[RFC3664] Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE)", RFC 3664, January 2004.

[RFC3664] Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE)", RFC 3664, January 2004. https://datatracker.ietf.org/doc/html/rfc3664

[RFC4434] Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE)", RFC 4434, February 2006.

[RFC4434] Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE)", RFC 4434, February 2006. https://datatracker.ietf.org/doc/html/rfc4434

Authors' Addresses

著者の連絡先

JunHyuk Song Samsung Electronics University of Washington Phone: (206) 853-5843

JunHyuk Song, Samsung Electronics, University of Washington, 電話: (206) 853-5843

   EMail: junhyuk.song@samsung.com, junhyuk.song@gmail.com
        

Radha Poovendran Network Security Lab University of Washington Phone: (206) 221-6512

Radha Poovendran, Network Security Lab, University of Washington, 電話: (206) 221-6512

   EMail: radha@ee.washington.edu
        

Jicheol Lee Samsung Electronics Phone: +82-31-279-3605

Jicheol Lee, Samsung Electronics, 電話: +82-31-279-3605

   EMail: jicheol.lee@samsung.com
        

Tetsu Iwata Nagoya University

岩田哲 名古屋大学

   EMail: iwata@cse.nagoya-u.ac.jp
        

Full Copyright Statement

完全な著作権表示

Copyright (C) The Internet Society (2006).

Copyright (C) The Internet Society (2006).

This document is subject to the rights, licenses and restrictions contained in BCP 78, and except as set forth therein, the authors retain all their rights.

この文書は BCP 78 に含まれる権利、ライセンス、および制限の対象となり、そこに規定されている場合を除き、著者はすべての権利を保持します。

This document and the information contained herein are provided on an "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

この文書およびここに含まれる情報は「現状のまま」提供され、貢献者、その代表またはスポンサーである組織(存在する場合)、インターネット協会、およびインターネットエンジニアリングタスクフォースは、明示的または黙示的を問わず、ここにある情報の使用がいかなる権利も侵害しないという保証、または商品性や特定の目的への適合性に関する黙示的な保証を含め、あらゆる保証を否認します。

Intellectual Property

知的財産

The IETF takes no position regarding the validity or scope of any Intellectual Property Rights or other rights that might be claimed to pertain to the implementation or use of the technology described in this document or the extent to which any license under such rights might or might not be available; nor does it represent that it has made any independent effort to identify any such rights. Information on the procedures with respect to rights in RFC documents can be found in BCP 78 and BCP 79.

IETFは、この文書に記載された技術の実装または使用に関連すると主張される可能性のある知的財産権またはその他の権利の有効性もしくは範囲、あるいはそれらの権利に基づくライセンスが利用可能であるか否かの範囲に関して、いかなる立場もとりません。また、そのような権利を特定するための独自の調査を行ったことも表明しません。RFC文書における権利に関する手続きの情報は、BCP 78およびBCP 79に記載されています。

Copies of IPR disclosures made to the IETF Secretariat and any assurances of licenses to be made available, or the result of an attempt made to obtain a general license or permission for the use of such proprietary rights by implementers or users of this specification can be obtained from the IETF on-line IPR repository at http://www.ietf.org/ipr.

IETF事務局に対して行われた知的財産権(IPR)開示のコピー、および利用可能となるライセンスの保証、または本仕様の実装者もしくは利用者による当該所有権の使用に対する一般的なライセンスもしくは許可を得ようとした試みの結果は、http://www.ietf.org/ipr にあるIETFオンラインIPRリポジトリから取得できます。

The IETF invites any interested party to bring to its attention any copyrights, patents or patent applications, or other proprietary rights that may cover technology that may be required to implement this standard. Please address the information to the IETF at ietf-ipr@ietf.org.

IETFは、本標準の実装に必要な技術に関わる可能性のある著作権、特許、特許出願、またはその他の所有権について、関係者が情報を寄せることを歓迎します。情報は ietf-ipr@ietf.org のIETF宛てにお送りください。

Acknowledgement

謝辞

Funding for the RFC Editor function is provided by the IETF Administrative Support Activity (IASA).

RFCエディタ機能の資金は、IETF Administrative Support Activity(IASA)によって提供されています。