AEAD Usage Limits — interactive explorer

Explore the confidentiality, integrity and authenticated-encryption usage limits from draft-irtf-cfrg-aead-limits. Pick an algorithm and parameters; the limits, per-algorithm comparison and the advantage curve update live. All math is done in the log2 domain so limits like 264.5 stay exact.

Parameters

Setting
Nonce construction
Security target & usage
Upper bound on attacker success probability (CA, IA or AEA).
Largest message (plaintext + AAD), in bytes. Converted to L for bounds that depend on message length; the cited AEGIS claims do not.
Attacker's precomputation, in cipher operations.
Presets
Recommendation

Confidentiality limit — max q
protected messages
Integrity limit — max v
forgery attempts
Offline-work floor (o/2^k)
advantage regardless of usage

Advantage vs. usage

All algorithm groups at these parameters

AEAD / equivalent-limit groupmax qmax vbinding
Formulas & assumptions for ()