@techreport{westerlund-tls-gcm-sst-00, number = {draft-westerlund-tls-gcm-sst-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-westerlund-tls-gcm-sst/00/}, author = {Magnus Westerlund and John Preuß Mattsson}, title = {{Use of Galois Counter Mode with Strong Secure Tags (GCM-SST) in TLS, DTLS and QUIC}}, pagetotal = 10, year = 2026, month = jul, day = 6, abstract = {This document defines cipher suites based on AES-GCM-SST and Rijndael-GCM-SST (Galois Counter Mode with Strong Secure Tags) for use in TLS 1.3, DTLS 1.3, and QUIC. GCM-SST provides authenticated encryption with near-ideal forgery probabilities for short authentication tags, making it suitable for bandwidth-constrained environments where reduced per-packet overhead is important. This document specifies cipher suites with 96-bit and 112-bit authentication tags.}, }