Re: [Cbor] [Secdispatch] Ciphertext format draft

Yaron Sheffer <> Fri, 15 January 2021 15:09 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 4A8E83A0AC4; Fri, 15 Jan 2021 07:09:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -0.527
X-Spam-Status: No, score=-0.527 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MALFORMED_FREEMAIL=1.569, MIME_QP_LONG_LINE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 0rW1-bD2Cgyh; Fri, 15 Jan 2021 07:09:50 -0800 (PST)
Received: from ( [IPv6:2a00:1450:4864:20::42b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 505133A0ABE; Fri, 15 Jan 2021 07:09:50 -0800 (PST)
Received: by with SMTP id c5so9608162wrp.6; Fri, 15 Jan 2021 07:09:50 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=user-agent:date:subject:from:to:cc:message-id:thread-topic :references:in-reply-to:mime-version; bh=D96ZdDSHN1bJyemhvRtHR+dsqteYHktRD3V5FSEMnro=; b=WXCvoi9r6ogHjIymNkeOguZ/R7hf+X3EFKQwWCtdPPDNxKyKLOn5AG6vWBDBUtIO+K No2XHt4g0Eu4SOAJv4bEY2MWmvltXhF+lFc1e5hUiRSQOr9S1La2DLpqE1VhhUIEafDe DyLiFPlnJrxbO5fixWc2ofBS2P2xu6zJoSPYiwmd+eQX0otXODtm8EjdGUtudCpDBi8/ mf/s664ZwSPuJlHx2uA88drKG9CXC0opX5IUx0APTS2UWdnQcJCT0ApfHAgkobiJBmgX 5iJ3yDFDOOgHTHr/6PoH0otGJCe9zSwTVWKY7oXs7y/7eJkBjV22B0jmgjZdZeaQFyLn +oOg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:user-agent:date:subject:from:to:cc:message-id :thread-topic:references:in-reply-to:mime-version; bh=D96ZdDSHN1bJyemhvRtHR+dsqteYHktRD3V5FSEMnro=; b=l2ecLTYuW7G3F/xO8vmuF6b/dDwd6k8gLWj1JXAMJCyRAEKFQcSgTs6LnyMnvbwc5L pn/7Ki3xtnrf/RfltH6AeL3llReDk8M7uC8JFGKVlnLyEO2IR37tDpLAxlwUe5W396oo cEv2ck25G6dwZ11yW9BAKObq89E6AZv82aNQe59PNXtYbzvb/WZMwdSSEAM9QRaFrU8X 5Ora3vQGbF6yh/KuLgqivGa5qDqnO3n11ASSTJX5JseYRHKaRf9BugwgrDXqbppMz0Dt qpvsaMIlZ2Cx2GYSo0vYq3o5ulET8mHboC73quSRzSnGR60xJNHOLtNm3a1osbXTZGS1 EMmA==
X-Gm-Message-State: AOAM533WSi7KzdmydvJP9hq++JlCTzXHeCyV1qGclBD+UlnMTHwo9wir pgm3VzzFHm4YmDkaefoGTqA=
X-Google-Smtp-Source: ABdhPJy2hXN2SRT0BDSxTS/zvxHl/TBlMlWybb05VEXbbbjGAxiO5uD8c/hZRb4cLDekeYcJkdUDMQ==
X-Received: by 2002:adf:e74a:: with SMTP id c10mr13844767wrn.122.1610723388846; Fri, 15 Jan 2021 07:09:48 -0800 (PST)
Received: from [] ( []) by with ESMTPSA id r13sm14945610wrt.10.2021. (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 15 Jan 2021 07:09:48 -0800 (PST)
User-Agent: Microsoft-MacOutlook/16.45.21011103
Date: Fri, 15 Jan 2021 17:09:46 +0200
From: Yaron Sheffer <>
To: Francesca Palombini <>, "" <>, Cose Wg <>
CC: "Keselman, Gleb" <>, Yoav Nir <>, "" <>
Message-ID: <>
Thread-Topic: [Secdispatch] Ciphertext format draft
References: <>
In-Reply-To: <>
Mime-version: 1.0
Content-type: multipart/alternative; boundary="B_3693575388_459445110"
Archived-At: <>
Subject: Re: [Cbor] [Secdispatch] Ciphertext format draft
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Concise Binary Object Representation \(CBOR\)" <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 15 Jan 2021 15:09:52 -0000

We would love feedback from the CBOR community, but to clarify: we are merely using CBOR in the simplest way possible, we are not proposing any changes to it.




From: Francesca Palombini <>
Date: Friday, January 15, 2021 at 17:06
To: "" <>, Cose Wg <>
Cc: "Keselman, Gleb" <>, Yoav Nir <>, Yaron Sheffer <>, "" <>
Subject: Re: [Secdispatch] Ciphertext format draft




This has been posted to Secdispatch, and I thought CBOR and COSE might want to take a look. (Feel free to reply to the original thread in Secdispatch, to keep the conversation in one place).




From: Secdispatch <> on behalf of Yaron Sheffer <>
Date: Friday, 15 January 2021 at 15:54
To: "" <>
Cc: "Keselman, Gleb" <>, Yoav Nir <>
Subject: [Secdispatch] Ciphertext format draft


Hi, we just submitted draft-sheffer-ietf-ciphertext-format-01 [1]. This is a CBOR-based set of headers for encrypted data, with the goal of enabling automation of large datasets that contain encrypted data, typically interspersed with plain data. Specifically we want to facilitate discovery of encrypted data (e.g., this database column contains ciphertext) and attributing this data back to the service that created the data and the key that was used to encrypt it.


We received good feedback on the SAAG list to change from generic TLV to CBOR, which we implemented in -01.


The authors would appreciate this list’s feedback regarding next steps.