Re: [CFRG] HPKE and Key Wrapping

John Mattsson <john.mattsson@ericsson.com> Wed, 30 March 2022 09:15 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5E2B23A0DCF for <cfrg@ietfa.amsl.com>; Wed, 30 Mar 2022 02:15:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.11
X-Spam-Level:
X-Spam-Status: No, score=-2.11 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hou8spsLsMoZ for <cfrg@ietfa.amsl.com>; Wed, 30 Mar 2022 02:15:25 -0700 (PDT)
Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-ve1eur03on060b.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe09::60b]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 898D53A17CB for <cfrg@irtf.org>; Wed, 30 Mar 2022 02:15:25 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=nYLIRHHrYlQ87Vl/i2btXKBoXZ7dK5MG0fNM4YTMlfAvgCEnXkH9nqmqq5UMUSHgW3dZkfVtnmreDKl5H+Wi5jw0arStvpGavxH2MSzo8v8nSryCRqWYtpq+MNAtbDACZBDeZe9o9TIVL0g41mnMjp5IPaocIZekIOVeiVwNwLOOjbfoeSS7cuCXoZpWQd73spf4ZU3ntcCWHXUMcS5MmQw/RHJi2MJL1HvTtcJuyJGx8qNuFW8vCTSVfpOtENhgl5+MfGmt1M0sPj7KblE1uamdyL8YI1+dF2nzH11ix9GYDvNvu+F5JZxAm1xX0OFRgL8XuE8dhn+hvvhePZrsPg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=JTb9w4slIyVFOGaIJBDoE2dzYKpPv3e5hAso7oiKwn0=; b=dAhcUCPsvKdTzfR2q5pq6+yzuuoAIuqpv4MAZJiU6P6Kwc8bEwLFTP5NQtkZREN1NVtNkvgq7ReBMeZWf6JgkFTl6wLrPueqmaYWpAaiMcToaVB3pI7biJNuCHNpFBXZnCxHxiXjky9I3fOTJ7aKIyiAZ0367USz1wGixg5HKgEL5lW1yd/UYrqJ+/FKxht29P36CUZIMG7PAHuhsOi8+8O16vLTtv7TfVuZTRV6UsCGO4rvtJMe2I/3JZN7vmxFH0WJzVhHWLi1B59RzcWt+7s3hg68knKSJIsXTE+R7CJ2s4hoghQUMaww8w5Soe//QfxbteN8shxvInDesNVFzg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=JTb9w4slIyVFOGaIJBDoE2dzYKpPv3e5hAso7oiKwn0=; b=rStRPROoDIItaHS8hwd3mdw0zuNSFQkc9CnKNJ/ojkzOJiw1dH+R8nSF7mdM34gEi9hnuple+SZATYa9NuQhIAqwznNcOUDBJyUUUROIEP2wur2W3xo8HuCY6PHHDeZtA2F6/RxiK2zCIO+byckg3xcjt4vr3h+5CroDxiuWiTA=
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com (2603:10a6:3:4b::8) by AM0PR07MB5508.eurprd07.prod.outlook.com (2603:10a6:208:102::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5123.19; Wed, 30 Mar 2022 09:15:19 +0000
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::b462:480e:b937:c62c]) by HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::b462:480e:b937:c62c%7]) with mapi id 15.20.5123.019; Wed, 30 Mar 2022 09:15:18 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Martin Thomson <mt@lowentropy.net>, "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: [CFRG] HPKE and Key Wrapping
Thread-Index: AQHYQ0u7KP9IsmRXD0Kbvf1+Gh7oQ6zXFHKAgACQ5q8=
Date: Wed, 30 Mar 2022 09:15:18 +0000
Message-ID: <HE1PR0701MB305054EA87D9754596E754AF891F9@HE1PR0701MB3050.eurprd07.prod.outlook.com>
References: <HE1PR0701MB3050AFD941AABAB80D7EC31E891E9@HE1PR0701MB3050.eurprd07.prod.outlook.com> <7c67e7a0-ddaa-4f2e-9a1e-91af4956c0f1@beta.fastmail.com>
In-Reply-To: <7c67e7a0-ddaa-4f2e-9a1e-91af4956c0f1@beta.fastmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 9745b169-528e-41f4-011e-08da122dcf6a
x-ms-traffictypediagnostic: AM0PR07MB5508:EE_
x-microsoft-antispam-prvs: <AM0PR07MB55089059672728EFC96738DA891F9@AM0PR07MB5508.eurprd07.prod.outlook.com>
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: MiDW7ZDSNHifxvh9NxOuVkboBUWgJToZKyJcdDsBTailrgW7d708uu4SrIlPcY9F5YaOfgF2yZzEB3lFEFORejzzF268xkVPgBQ2OYcwBXTqiP6kkOaAqlio01ifkYkzRWw6ktXbeUnvFFW/TckNc192ZhxdbMzZT/MyuhiBROWfbjAy4M29XdWec7gtfFRvcP9CI78+ljy+yPIc4P7biuqcLi3ptVbrA2l2PqiD65eDUrWTFlMIjABMEetAVtDT8R7834RztgrYDUlEGLo35RRnLssOl97f18xvt+QsDxoXTyjxJGh29TtJLKNCpmBZE0W/VbyqZKXvIpiePWsSI8gPMOXio9eaAlWghSKpbddSouf9hNnmrK/R0yDFT41ssmHfj+aKtvUD/NRjUHimCo+5VczOtRmdcQhkqXT0X9PqRsf57lHfbDvyOzRzmAPdrzIvi8xyz2sF3NsunxpSa7xDIsnOCtZN+5k6ZtHAfrLvphObOU0KsKAGXoh36ozrmsbFA736Az7EXP4Lv+z5/JmFkj4CYJF3KPVXa4lMglSs1t2fGUS1XI92oxlYlZVg7bgd7ZtAUy9nPxBsTl/bBaaoIMhM6UP8S0gZHHrPUFObg8LgRItnMW3wp5xGfGwGqyTJWmNCnUZ3LvrUn8ke1/cfU56ISJTh+6/bN6UTIHEazbeVGp9OpWf4Kgjkt4J6SBvnPeYg8cSxwKohRRZsZw8BCl/oOrM9qgc3ABnqJ2bL0ELwjLECypVOpz114TlwVWFBmL/qqW5SC1TQse4pvWwbky98RM786yPqoYli1oA=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0701MB3050.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(4636009)(366004)(44832011)(166002)(83380400001)(186003)(26005)(38070700005)(82960400001)(8676002)(55016003)(86362001)(2906002)(66946007)(66476007)(8936002)(110136005)(91956017)(122000001)(966005)(71200400001)(52536014)(508600001)(66556008)(76116006)(66446008)(64756008)(6506007)(33656002)(316002)(9686003)(5660300002)(7696005)(38100700002)(53546011); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: P868jkB+o+YITmhKPN9NSp4kQVeVnddUaMNE66MibLEkC7nhDEDac9ZzTU0KLNh4K9pU56atTA9zL6oSQP4xGvuETxXyUEZGjcqlEvXCdp8DndyQeVflW3ng4XFZnhYzx6kx0Wd+8Vf+rqGD4w9aXJ+q1Hpeb4FwaXqqLKr3xZtYAvHa6i+NKlnsjDTqLUoFMCRmcBNAjwKZ+It+tuZl2IxdvB+cgaxgnCM0U541ftGC/l46+EVW4Xu4EAYX79axgY2bbCQv70JTu12vl9RLg9rWf7nR6OSONve6/bINzIp435jdHDI7qooNXWRopqYUyOGVDJGdWb6Wowfl4+/zTTJ0+jM1lpzgkJupVVnMb5/Eddf1nyW5Ilv2lzJ7uKnkmXDNeemzTVHWk7wFPPeuG8Wxj1ymkkjEa2VH6z0JHleSc4YFs0gRb5m+5asfSBEzRYcvdEGO7xQ/wR8JTeu8/P97WePKocCOtnhvrLxd6zr6q4MnUkaZOAsMvo+1x7O5m0+9IuimXM2nmiQIeEe4EpFTnHDZdJTFqZNSInrlioLHHlFKXuvJTFpl0VyT/HlClxokzEeyBXJto83UvLlKUSbrZ/lMTJiPzxzZCL1xjdJ7hq/ACVZJZwlDJSkczIWf5Z/LzGWcE0Z3I/Qae8kG+UEH3onyW9oKRo5wbADtvgUvzMJB4tr0ij+gCJNawCkKTQDGdWtFxE7hY7V98k1DLIB6thrI80dTiPNDpBYTLl9DigHFSRzFapSTrWRIzPiOi1rxFnoDNLYiKvVpxpP3vgXMYYgbeOD6037BCFjVewRamq3gQlqvAUoBlizRZjG+aWTqHlQx9C477+Q8cOEZFW30NXHzGoSBfPXK6s+IHcRw3Vf5y5p4pVmbPzzVFbM5hqFpK67PzgNPqn6P4zBq9jjO+zNqrhqRyaWOr0Kcf8N/NrawyqP6b1Ldxc9JT7/rXw6Wn/EZFhuboImsf59W1maHSKpXAhzZjpne3K+sqrFpytxAUTL6Xm4HRsDYx7CoakqwRClMtk2MgW4bbtM2s6fdbMev3j8weYNFPPbcGe7RfHeVeHGcwnSyXCx1W2OBbyRMFzEHmuWZ+wBa4D3xBXvcFti0l0Tukc708WyzEoBF9qk/YhtQhakA3nBSmEIBWWmThsnvOB6WucCAvrut3VFum51PEECMDiiSok6QrCr2/XmbpHxkKvl7IQqUxuznt9A+8Vw+DnveRnO1SGjpf9FH3Xd+GvaelDxMOn7W/1DMqUWVoCNPjMKHi/EKjiDJOjDXEQPX0SBNybWvjPinGqyfE+9hzOUZ0yC/tcuTgIUS/1Z3VD8eC+DaceI8ncyRBO+W2GOf7TPaC6z6l25PQV9QI4n+kWQdIIANhe3AJ3I5o2MWJGlrBYjrRlzwHa3XnKcKeKc2MW/12WGvQ7+q6jJn1uuMnT1kVSxC2LfxoDTsJeAW8Kgij9cwVrVKnzej0RJ/UI2Z5pNNINtV3VdMLKG5PUzzN1urvgSnOrrP9h3+vpDpoCA4wmwJEK69Bxfe++bf3tZFwWIuh+ymyD4PGQSUivF6MqgklmULOOBEFUIkLYlnlpPv3AdXuhH3kZTcGUiZBwlMRgDDp63eH+jB5vxhuh0xs1NXZO7yDTWS0uMUSdd1h3Xz5MSSh5ERAp8RPMjmz6m9mu2jeihVruX7XrfbCo7giyELHbIHkBNvzuIBAs780J3UVicbhzh/oEvp0uV/x3x71wHerIoV8NcEdyf2acMaS8zngdCtMlxUXN3L+YG6aeuyF3sjz/U2HfaF
Content-Type: multipart/alternative; boundary="_000_HE1PR0701MB305054EA87D9754596E754AF891F9HE1PR0701MB3050_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0701MB3050.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9745b169-528e-41f4-011e-08da122dcf6a
X-MS-Exchange-CrossTenant-originalarrivaltime: 30 Mar 2022 09:15:18.7286 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Il6mmJYKRgQCwYe+VAE4v+50DeB8EOC3wbc6N4nNOeawJlcW4NR3PmAzlW+pThgr75wuz0IVuh2q/VWZkS/JU81r+PXt36GYjSKjujPHRJM=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR07MB5508
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/2_S6NSB0qN_UjhujpnJPU7J1EpI>
Subject: Re: [CFRG] HPKE and Key Wrapping
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Mar 2022 09:15:32 -0000

Hi Martin,

>What is wrong with the existing HPKE cipher suites for protecting keying materials?  That >is, aside from not carrying a NIST approval stamp.

See my mail to Dan
https://mailarchive.ietf.org/arch/msg/cfrg/ID0JuUDIg7np4CxMZLq-7Zuaj40/

Key wrapping mechanisms has in the past tried to provide security even in the case of compromised RNG and state. To keep that attack model, I think HPKE would need to be augmented with something like AES-KWP, AES-SIV, or AES-GCM-SIV.

I would personally chose the algorithm with the best properties over NIST approval stamp (HPKE is not NIST approved either). I think it makes sense for CFRG to add AES-SIV and/or AES-GCM-SIV to HPKE.

Cheers,
John

From: CFRG <cfrg-bounces@irtf.org> on behalf of Martin Thomson <mt@lowentropy.net>
Date: Wednesday, 30 March 2022 at 02:32
To: cfrg@irtf.org <cfrg@irtf.org>
Subject: Re: [CFRG] HPKE and Key Wrapping
On Tue, Mar 29, 2022, at 20:05, John Mattsson wrote:
> Would it make sense to standardize AES-KWP for HPKE or do CFRG believe
> that AES-SIV is the future of key wrapping? Irrespectively I think the
> CFRF should produce a good recommendation on how to use HPKE for key
> wrapping.

What is wrong with the existing HPKE cipher suites for protecting keying materials?  That is, aside from not carrying a NIST approval stamp.

_______________________________________________
CFRG mailing list
CFRG@irtf.org
https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-40f7d10cf9eb7c69&q=1&e=c95f3aec-4703-4832-9b62-2c7a79363887&u=https%3A%2F%2Fwww.irtf.org%2Fmailman%2Flistinfo%2Fcfrg