AES-GCM and AEAD Protected Data Packet (IETF draft)

Tankred Hase mail at
Thu Mar 24 01:44:31 CET 2016

Hi again,

> Am 23.03.2016 um 22:56 schrieb Werner Koch <wk at>:
> On Wed, 23 Mar 2016 03:20, mail at said:
>> wanted to get the GnuPG community's thoughts. Making GCM the new
>> standard mode for symmetric encryption would give us a modern and
>> performant alternative to OpenPGP's CFB mode. Especially with regards
> As I mentioned on the WG list, I would really like to see OCB used for
> OpenPGP.  OCB is far superior over any other AE modes.  There are no
> software patent issues even for closed source software with the
> exception for those whose business it is to kill people.

I've done some research concerning patents. It seems OCB is not unencumbered by patents [1][2] while GCM is patent free [3][4]. A least according to Wikipedia and Matthew Green’s blog...

"GCM. Galois Counter Mode has quietly become the most popular AE(AD) mode in the field today, despite the fact that everyone hates it. The popularity is due in part to the fact that GCM is extremely fast, but mostly it's because the mode is patent-free. GCM is 'on-line' and can be parallelized, and (best): recent versions of OpenSSL and Crypto++ provide good implementations, mostly because it's now supported as a TLS ciphersuite. As a side benefit, GCM will occasionally visit your house and fix broken appliances."

Would this change your perception of GCM in regards to GnuPG adoption?



More information about the Gnupg-users mailing list