%% You should probably cite draft-sullivan-mls-attachments-01 instead of this revision. @techreport{sullivan-mls-attachments-00, number = {draft-sullivan-mls-attachments-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sullivan-mls-attachments/00/}, author = {Nick Sullivan and Raphael Robert}, title = {{Encrypted Attachments for MLS}}, pagetotal = 15, year = , month = , day = , abstract = {This document defines random-access authenticated encryption of large write-once files for Messaging Layer Security (MLS) groups. A file is encrypted so that a receiver can decrypt and authenticate any byte range without processing the whole file. The encryption is SEAL- attachment, SEAL's named write-once attachment scheme (raAE), parameterized by the AEAD and key derivation function of the group's MLS cipher suite and keyed from the MLS exporter. The encrypted bytes are carried by any means, and a recipient needs only a small reference (the object's identifier and length, and an optional locator) to fetch, key, and verify the object. MLS application messages cannot carry large files, and existing attachment encryption produces an opaque, immutable blob with no partial access. This extension supplies the random-access layer those uses need.}, }