[CFRG] Re: ASN.1 in draft-connolly-cfrg-xwing-kem
Bas Westerbaan <bas@cloudflare.com> Sat, 02 November 2024 22:15 UTC
Return-Path: <bas@cloudflare.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C58C2C14F5FC for <cfrg@ietfa.amsl.com>; Sat, 2 Nov 2024 15:15:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cloudflare.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2fPgvxq0YXI2 for <cfrg@ietfa.amsl.com>; Sat, 2 Nov 2024 15:15:21 -0700 (PDT)
Received: from mail-yw1-x112d.google.com (mail-yw1-x112d.google.com [IPv6:2607:f8b0:4864:20::112d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 105ACC14F5E4 for <cfrg@irtf.org>; Sat, 2 Nov 2024 15:15:21 -0700 (PDT)
Received: by mail-yw1-x112d.google.com with SMTP id 00721157ae682-6e34339d41bso26830667b3.0 for <cfrg@irtf.org>; Sat, 02 Nov 2024 15:15:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1730585720; x=1731190520; darn=irtf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=cRu3LZGlMCYETphQe2TkPd9ZywoWuMq6yBR+2iY7k2c=; b=SshDwkICOf1QwKVIY0TDERemHHuuQXix/IVIEAQjsVwZ3H3zuJ+q/fs8k+nOtpkHXK 5cVc9U9EfxDHFCw1Z4zpPwgM7RhgET1eul/Ycz7/4rKZ1LI8Ut+qyXFyW3CfbCEM0+LB cJQ4y/yfL4R/SbPRojt19n0rTguS1+8jIK9f5ji3/707FmjPoi9dmS7EmsnieWRh1cuA 6ykxNY7uqDv/wTAXUj71DkhIWTMSwD0GrPITeGAmgIhE8czxBb6C3+k/TympVp9dvqtr 7JexZjt/uuMnL2wh5KEXb19yheHtKZzY7aKZX2ak+db4UqoUJxZKRNK8YOi3Ik4xNEfO brkA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1730585720; x=1731190520; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=cRu3LZGlMCYETphQe2TkPd9ZywoWuMq6yBR+2iY7k2c=; b=C0P5E3eA/3nYgBEOOKUHPictTp0dkJ1I/pGzZL9NQPLqCLYHz5JQomAkAkdC5gidy8 meyGDh/vXiQpd7QEZlyN83IRA9HLSmcssKRD6Q8rW+xoQ9ZMU+7b2L2HwsurwXTk2Gr9 oVlXh/t+qBKpy/nGfXUnpqBuwOkEcFEacg370RHF0co8Id08wiSWx1czi9a64I04lAt9 6mLRRn8zcd5JWjyZc26VVkn/1yzZN17m3bi54PMUZNplodcQsSm3l2UCjkFhvNI9s/OX NE6dveqHdKM34+VXjeU4Q55CgMjbzTS+CRc46tt0c10D63NLCRUFShc06twiC8VP1mYE 2tyQ==
X-Forwarded-Encrypted: i=1; AJvYcCV/YGvnk1KfY/B8Gl+CMvgK6E5guo3xhPFSbLwvgtKQIMoygbZQ7jOlIfOtpDYQuFEE+J+J@irtf.org
X-Gm-Message-State: AOJu0YzBonTj8hBDnoMFj59/at/kNAK5f5QF/LaXCIqUK6G6v0YxrtiW RYeoxD4Ns+HX3TrOCQCaTiqqIxZ5yqwaT59oyWRAy3/u4i6LfHcd82OLsBFt5tZtJ7E36DVoOel X2X81n7cteI1V26ftR8imJvLbKqxPsCVusUHnvQ==
X-Google-Smtp-Source: AGHT+IHNvUOFWoMtRoKZjJdPmwajsLahXRXYNzgzMl3UOOuwLAkbrgHHLYQiqoXvO2i6gxfz2aIMpqeReuB5kvUw7dY=
X-Received: by 2002:a05:690c:6c0e:b0:6e7:fb87:7097 with SMTP id 00721157ae682-6e9d88ee7afmr299779587b3.8.1730585720138; Sat, 02 Nov 2024 15:15:20 -0700 (PDT)
MIME-Version: 1.0
References: <FDEAFB57-D5F8-490D-BD2A-486A58C24FFF@vigilsec.com>
In-Reply-To: <FDEAFB57-D5F8-490D-BD2A-486A58C24FFF@vigilsec.com>
From: Bas Westerbaan <bas@cloudflare.com>
Date: Sat, 02 Nov 2024 23:15:09 +0100
Message-ID: <CAMjbhoWqyKMFftCCNQys6SELzt+HZrM8sc6jm5AZsiQZ2r0JsQ@mail.gmail.com>
To: Russ Housley <housley@vigilsec.com>
Content-Type: multipart/alternative; boundary="0000000000001abb610625f5635b"
Message-ID-Hash: SCIP63LAJKCVNQCCS4MT5G65U7PI535C
X-Message-ID-Hash: SCIP63LAJKCVNQCCS4MT5G65U7PI535C
X-MailFrom: bas@cloudflare.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-connolly-cfrg-xwing-kem@ietf.org, IRTF CFRG <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: ASN.1 in draft-connolly-cfrg-xwing-kem
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/2OPbGIpL9munZLL9Jq-eFuUBVR4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
Hi Russ,
Thanks for this — I'll carve out some time tomorrow to include this. Are
you around tomorrow at the hackathon in case I have some dumb questions?
Best,
Bas
On Sat, Nov 2, 2024 at 2:52 PM Russ Housley <housley@vigilsec.com> wrote:
> Dear Authors:
>
> Please consider including an ASN.1 module in an appendix. We have seen
> this reduces implementation mistakes, especially by making it clear whether
> IMPLICIT or EXPLICIT TAGS are being employed. I have provided a suggestion
> for one below.
>
> In addition, I suspect that you do not want the public key wrapped in an
> OCTET STRING when it appears in a certificate. Hackathon experience with
> Kyber and ML-KEM suggest that it is not needed. That said, there are times
> that the public key might be used in other contexts. Sext something like
> this might be appropriate:
>
> ~~~
> No additional encoding of the XWing public key is applied in the
> SubjectPublicKeyInfo field of an X.509 certificate [RFC5280].
>
> No additional encoding of the XWing private key is applied in the
> PrivateKeyInfo field of the privateKey field of the OneAsymmetricKey
> type of an Asymmetric Key Package [RFC5958].
>
> When XWing public key appears outside of aa SubjectPublicKeyInfo type
> in an environment that uses ASN.1 encoding, the XWing public key
> can be encoded as an OCTET STRING by using the XWingPublicKey type.
>
> When the XWing private key appears outside of an Asymmetric Key Package
> in an environment that uses ASN.1 encoding, the XWing private key
> can be encoded as an OCTET STRING by using the XWingPrivateKey type.
> ~~~
>
> If you agree, then yo also need to add:
>
> XWingPrivateKey ::= OCTET STRING to the module below.
>
> Russ
>
>
> = = = = = = = =
>
>
> XWing-KEM-2024
> { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1)
> pkcs-9(9) smime(16) modules(0) id-mod-XWing-kem-2024(TBD) }
>
> DEFINITIONS IMPLICIT TAGS ::= BEGIN
>
> -- EXPORTS ALL
>
> IMPORTS
>
> KEM-ALGORITHM
> FROM KEMAlgorithmInformation-2023 -- [I-D.housley-lamps-cms-kemri]
> { iso(1) identified-organization(3) dod(6) internet(1)
> security(5) mechanisms(5) pkix(7) id-mod(0)
> id-mod-kemAlgorithmInformation-2023(109) }
>
> AlgorithmIdentifier{}, PUBLIC-KEY, SMIME-CAPS
> FROM AlgorithmInformation-2009 -- [RFC5912]
> { iso(1) identified-organization(3) dod(6) internet(1)
> security(5) mechanisms(5) pkix(7) id-mod(0)
> id-mod-algorithmInformation-02(58) } ;
>
>
> -- XWing KEM Algorithm
>
> id-XWing OBJECT IDENTIFIER ::= { iso(1) identified-organization(3)
> dod(6) internet(1) private(4) enterprise(1) 62253 25722 }
>
> XWingPublicKey ::= OCTET STRING
>
> kema-XWing KEM-ALGORITHM ::= {
> IDENTIFIER id-XWing
> PARAMS ARE absent
> PUBLIC-KEYS { pk-XWing }
> UKM ARE optional
> SMIME-CAPS { IDENTIFIED BY id-XWing } }
>
> pk-XWing PUBLIC-KEY ::= {
> IDENTIFIER id-XWing
> -- KEY no ASN.1 wrapping --
> PARAMS ARE absent
> -- PRIVATE-KEY no ASN.1 wrapping --
> CERT-KEY-USAGE {keyEncipherment} }
>
>
> -- Updates for the KEM-ALGORITHM Set from rfc5990bis
>
> KeyEncapsulationMechanism ::=
> AlgorithmIdentifier { KEM-ALGORITHM, {KEMAlgorithms} }
>
> KEMAlgorithms KEM-ALGORITHM ::= { kema-XWing, ... }
>
>
> -- Updates for the SMIME-CAPS Set from RFC 5911
>
> SMimeCapsSet SMIME-CAPS ::= {kema-XWing.&smimeCaps, ... }
>
> END
>
>
>
- [CFRG] ASN.1 in draft-connolly-cfrg-xwing-kem Russ Housley
- [CFRG] Re: ASN.1 in draft-connolly-cfrg-xwing-kem Bas Westerbaan
- [CFRG] Re: ASN.1 in draft-connolly-cfrg-xwing-kem Bas Westerbaan
- [CFRG] Re: ASN.1 in draft-connolly-cfrg-xwing-kem Russ Housley