Re: Threat Model
Shai Halevi wrote:
>On Tuesday 13 April 2004 08:19 pm, Nixon, Bob wrote:
>> [...]
>> The basic intention of the T10 protection information is that it is
>> generated by the application that writes the data, persisted by the
storage
>> until overwritten, and returned unmodified to the reading application
for
>> verification. It is allowed to be checked at points in transit, but the
>> storage is considered a point in transit, not an end point.
>
>This sounds like we cannot use it (since it belongs to the application),
>but then...
The T10 document proposes a particular CRC. Even though this is
'generated by the application', it seems that the allowance for
recalculation by the storage device means that it is not really
completely an 'application level' item.
The application isn't free to use any bitstring it wants; it must
select from the T10-mandated options (of which there seems to be
precisely one right now).
Best,
Do