[CFRG] Re: Progressing NTRUPrime/Classic McEliece drafts

John Mattsson <john.mattsson@ericsson.com> Sun, 02 February 2025 09:02 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D0500C1D8D43 for <cfrg@ietfa.amsl.com>; Sun, 2 Feb 2025 01:02:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.255
X-Spam-Level:
X-Spam-Status: No, score=-2.255 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eK3cqSJTBj7e for <cfrg@ietfa.amsl.com>; Sun, 2 Feb 2025 01:02:04 -0800 (PST)
Received: from EUR02-VI1-obe.outbound.protection.outlook.com (mail-vi1eur02on20630.outbound.protection.outlook.com [IPv6:2a01:111:f403:2607::630]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3EB41C1D8D42 for <cfrg@irtf.org>; Sun, 2 Feb 2025 01:02:03 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Y+JNnQhW49/TW8ENzasYtfiaiSub3hReK9tha/7Vh1rmd7wIVNRKtPMzrxmiIw67FSN5Sze5IyX8EjM+/3jt5g63Wu2w9xpGYINZNZ5NuJi2PwDUBcbsTkcXEmnzHUSMWSXIig9g88LT+1eoLJXIbZwpc0zok+Of9knhbeg5zQnJWCbz0e2Ttz8uTVoMITFOZssheI2p/f44aNj7xZmzN9t4GhxGTd1wyaf3XEcLpHzr4+lMobMCadetjyV4GzWykIHkiLHWAs0QioqWjaNaB7a9EiQ1CNb2SLlzeU5vbShwtjzd3XDlFnCL36VHkK6f6GUzodcgDrtv0TzIXsRY9Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=koGiKVe7yT5on/TLRQEncXq5MJUUnYq+ttQ5jnei3sE=; b=XjSfbO3T0ltjxz8Bk2qiIR8Bg79qE7dfx0LXZQCKqaqVYZ/ralJJzHsKuE10p4rwjG1DX2OkplDXjhKktaNrceJypic7tZNxqejEMi0gF3lNGPx6gtzAnuESCjYAISR4r3WO2V7Pfk4vbWolatOsy3PQVlYsCdwQ7JR7dPS5dJixLmaTEPNZEBRokPJuxUit3a8y2HKgrLZQp7WderJSvMoBqEVeGOn+99PrrhgphER3VZptU5EY13DgNnyjc+Uv+M5Q3dQRHs7SyKbFcouO3S7cqRK5qhOpC7rjWjX/C8mDHmelz84YwH9pYPnMFNQwHIzmAg/yTHkbU2DlMfYXwg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=koGiKVe7yT5on/TLRQEncXq5MJUUnYq+ttQ5jnei3sE=; b=Ig45trOOiiwh7wY2r44t+AFpYw+R4thXKbfVvRXcDe1Wx7nt9WLpzBmpCnnA4VeiEMCMQAka1mvnUxxSVXvIJW8Tag1FlTSDb67uIbZKlINVmGs3/X81RIv23doFWbGcmaollXUkyX0G6dJevcZLwu70pRAhdT31IcsoWQrcJtUVPdngo77TNLC3X6B+r+Ba+6wZ1omYutdzoLiA1PrHOfrwwPT2hBMK3iJbllkMx8r7Mi1/8DC/t+2jtavS0E8qCwkTzdWsOJ2G9rkAc2+lRoB6mC4FGwBBljg288p4VcqEUA9rZFRA25+5ZUdXJTDZpq1ZxBRAa0Fa/H9v0Rydeg==
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by VI2PR07MB10154.eurprd07.prod.outlook.com (2603:10a6:800:27b::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8398.20; Sun, 2 Feb 2025 09:01:59 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::bcf3:3f45:888e:a4b8%6]) with mapi id 15.20.8398.021; Sun, 2 Feb 2025 09:01:56 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Deirdre Connolly <durumcrustulum@gmail.com>, Quynh Dang <quynh97@gmail.com>
Thread-Topic: [CFRG] Re: Progressing NTRUPrime/Classic McEliece drafts
Thread-Index: AQHbbuZWhln5+gIMukqFBa0r7RDnT7MqVq4AgAEvGgCAAG5In4ABGCEAgACYWwCAAAN/I4AAEs2AgAX8foCAAAp+qg==
Date: Sun, 02 Feb 2025 09:01:56 +0000
Message-ID: <GVXPR07MB967888E4E98205134DF10BA089EA2@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <CACsn0cnJ7TgnCp1GsSnRfJCY1rt+t2BBSadm0YkDM8tuL-pE+A@mail.gmail.com> <CAOp4FwR_E4hky7RehU4c1rsy1tFxDgUTfKRRuj3NxWBThC3sow@mail.gmail.com> <CABzBS7kLoP7U=EpQmotCQntASFGcrLXpnSuTQ3i18W-W8Hf5QA@mail.gmail.com> <b7af8867-7386-4f03-b28a-cd5a32297ec4@betaapp.fastmail.com> <87y0yvs2ct.fsf@josefsson.org> <CABcZeBPhr4gENxWkoKKwqdu_dW3=7GRyKjpG0sf10CSHOXGwhg@mail.gmail.com> <4c7e3fae-b6d3-484b-91e0-52a948bffa3d@amongbytes.com> <AS5PR07MB9675B69CC59D88AECA2F9C3D89EE2@AS5PR07MB9675.eurprd07.prod.outlook.com> <CAE3-qLSoXJYHaxepMhnr7to0QBhSCcB9=jXVVNWyNgOLFxxEew@mail.gmail.com> <CAFR824xTKpsMPU5g_KrAdssd_DLw41Dnkk9t0eXiwUVVX=e8QQ@mail.gmail.com>
In-Reply-To: <CAFR824xTKpsMPU5g_KrAdssd_DLw41Dnkk9t0eXiwUVVX=e8QQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|VI2PR07MB10154:EE_
x-ms-office365-filtering-correlation-id: 15f17940-7051-4f42-54fa-08dd43683ed8
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|4022899009|366016|1800799024|13003099007|8096899003|38070700018|7053199007;
x-microsoft-antispam-message-info: uJt5Dv35BAViwDmJRNs5wkw11dFpZPG7nT2Q0umr5ymHzcpvHh1hZM4cRYlYE6BFrqvvHo69fXoa8hhj9Vs2ebL5TsCm/2qO5F1KuYYV11AXP65XaChTFLvajXIVAo6p9RlayJ/taM7+5UEwHtkZQ5iu4PtqMzEVoL7UeYOx/K+v1Mi9PTjUkIkBVXytOdf+uLrgxGRGZAXUdp9OL27izobcWNItRMGQKj9CPibkloB5QfoVBa8AltBh/smu4nMZzS4cE/0jmYhDoR3TmT8RFQ7g7IJgJxRa2AWhpPBI9YUZ+8ssgIpgbPX+rgjQwd6k12VQ97oQ2Ird3+AmYP/mTO/ufTLGZOQbtc9UT+vxS71rgoRuEIiNI2FkCzdiAnNeBOaefJ42e7SoEo9clBtlPgwbG7MH0ikiMzIBZ5zLuTr+u4pDBFVswDLAsUayh/eVfpb8a+3bLDPo+0+sY5QXtFJOUjtljTvh5cXmykonOafbfr1mqQeRp6yAHAr30auZdvYm3V3RUi/tnmjcNSbm5QqPemx33rXN0SKiztXXiSkaspX056jNCFa+7BJ4o9gJUEykv8dzQNbaWwj1bU1MTjCtS3JWCt90G71iDaqPXjGbfLfEGLGqFw/wgqazubA7ltbjVJja/IVX7fdbdn0Tnbe9N42EvT+aqSifB9av9Gh3yur1pCrfU8aufUrtQpuNWFaN77QbNhwuNZM4NwMv9rKVfKlc8qZzx/XcvBoW2yNUMncThJyXVpmCl7dv0j+Lm1VgxrxYhFjmnoGXjZKpI6P9goI34qTbqawdvuMHU4Z4oY9UkxL0PLESmKP10m5g+7XVlOzNtsh7e/5bF/aWIkHxU7JeT415tFbqNcJ/b1YaTZ/WhrQvOPMLV3a8ug/uNt5QFMTWuCnpqS3yWYWFfUsn8myVrYok20l1u1rxw/mlrflw+sVuTzkLNqzQST13Z1GGPvBJOdmr9J0/WG8e2lnNSk/MvcZhXflr/GVI3GX9DaRUieG253vaiN0jGQD7vFHceAqxr0ijn2MqTvY0vH/JbfT+7rUjD7B3q34VO0ZiQx729Q3W2pVBMgZKBykcncABhZLP4a3g9HQrhvF1/3OXsiQIeh3Sq6fEBviO88C+obtq4qLlL3So2s79wEc/fBWVP0IQYMMGe6e9YvEsbvRG+I5CWdzeIwCdqogO+EYcAvjn88cCgSEv+lmsbzNPqJAmbf1LkqvHiCUrL2JXooH0fWAahAR8Wf62h+Mour1p1lXTXDiEzXnfCg/tOI/8/GHyJjqUx3JkPgQJNn4OzNJ90ppLzZDiem/m7SFGD85m5OJ8uBodJLfdtEAeTz/2XO5nI4vvo0V11/c4fEoxzRBT+E6GMepDcwnwhP8ELU01l8XLhJcb8nMZkHygqX6z
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GVXPR07MB9678.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(4022899009)(366016)(1800799024)(13003099007)(8096899003)(38070700018)(7053199007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: lpcmU+WMVhm69Tkk38IgP9Oq2FtRSXZiITS+yfRFg4v3egYx7xogikSsOGicGsnNQ6FVYH1Vq2XD1BIyz5cFLOw4RRreVzmEfRuMCuZKyh9cIFKLIx/BEQMmzpd4vPa3C7xK0ygUXDGIstNUFMTSvkQbA3PXzWzGshKbp/MRb+wWcBiruZEtcxDiwh2JPhmANf8vGkDC97svi8mE3Eime71G+46KE43gb03hnLmRUpUkPCaWzeAu0geKIL2jHoYhebDTBNGGh5Q3TtDQ8gMAnFdK0EFaCNJoADbFF9w828ekqMs2h7iIpmJg5s8GUjUJsNHudXshrFMqkq8hbiSLcg+qEwPIF/zJaFIZ1ReXlBBQeJKjEHzNOjnadQfxMpJvZYLbfDZk6b4eo6ZpVSb60STLI6w8moAUBHbS+aLqcCE1TJIDegCOV6AqFQPDZHdhJ8hJ65Z5A5ylSZcVMRpYqIWOXIDkLA+YNsmZgnrFgPY7CYvcsTq+zV7GlnKJIXjgwR/gdAdfECzzrqefDOLuNKkpkPRe+2DC91mzwaws9v0Vydre7PYVhTu1t4IE7rDPvTCUN8pwuDQSQ2Spq6XcaFbZXGSuPW95Q9AHWRc4qJtl7EqEfG12rPaqFjOGiQvkyHPC3YJ06ev8IrhZr6JygtXaQEmABhKWyj+avDNHj4YXzmGD6mfMs53V9NYBTzMpROfpDDYpup/HUyrejQQVOxdqEzBlYd4YO7LSARemV688QcN+hlC+IOPC3CqwM40C4BQhTkfQ0zJDp1pMrm5gjiejST2pxj+1HVwXQI5lECz8TPdduRLU2vYB3be0yv0IZSW9KIe2gfLW135FMriOViMYaiQ1qRsA4nIQ8Sn37bORmL/uUk5sQutes0t2xop3DXGeMLUacXLz55CvwiEfbjh7ICEQGgljEC0W2Oi3MPXM6V0jeZNwv14GMozrFhRh1J1sZiJsQkN3ccc4wIbh/GVTYiLgfd9zWqgaZYc3AJU/aaurkst8jIGpWST1PJg3N1h9CEV5tuyg+FnHbba9Z3w96ziqFfR9bMCzVMtUc1EJhdWTwkO7cN8Ui8VOQMKbehD3QprDj26G7ktBY7E/I67B55aAjel5G+ggN8t5RkFsXPJK2xpBINCwJXfC90Lb4aTF+wcgSIDXv6IFU6sevjBBFhINmoT8Gn7oZjaVElI7osoTqvfeKbTBcsGHmS2Nlcbg0CP3Oo8q4yBtXzNeBmZQM5BV2/Eq7IoOd5xCg4lwEP01hPKOWWH0Dd+K3lBKRr0vgfZcL+RNbidNNqqqk5lwYEmnBDBHllm3BW9S2gFGO+SZJNnqif5PSkyBtlOUzNY6XVxk/+Pdk0oVXuHnfLcTWgN3/CzDgVvKWv8rBKGwcgy0mWPa/XOQy5MH9OpnUyonPfkkAtPuJDi2tH/ATHYzw/QFzQnYSIdp6OfFA4GzzlKYH7sDqtivJQCCViUl6XtDQFTGpMhXoqmnCX2AbHOJnQ1zdkYNas1ISotqbB2otqLTgHCVpmtShrSRiMDZBjCbz9j5VBiiBSzuEPnLr7yNAjWBDcbBb7VOKZuq+oU6EG1KOAmu4A43PE9+OeR9VuwgifCbLxp+jvrdyEF6lRYqLDSKtDl/ByJQK6O50XY=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB967888E4E98205134DF10BA089EA2GVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 15f17940-7051-4f42-54fa-08dd43683ed8
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Feb 2025 09:01:56.6092 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: shmsluYw+sKHhpFfhQ90kIsF3MNLXrQwdl3cOnEiIP6YCRhyIGR8MImnRbeK0N5tvwcijcMDC6umHAjW8QeVjAx7uhEF0lEsiD18i0vIa1A=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI2PR07MB10154
Message-ID-Hash: 2ESYXBQ3V24WE4VQJ4VRNAIWMWRL25EP
X-Message-ID-Hash: 2ESYXBQ3V24WE4VQJ4VRNAIWMWRL25EP
X-MailFrom: john.mattsson@ericsson.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IRTF CFRG <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Progressing NTRUPrime/Classic McEliece drafts
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/2iYAHAgjNf39azLBlBAMUFrtIpw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

CFRG has run elliptic curve and PAKE selection processes. I would assume Quynh means something like that.

I don't see any additional lattice based KEMs or NIKE worth standardizing at the moment. The next couple of years I think IEFT/IRTF should focus on integrating ML-KEM, Classic McEliece, and BIKE/HQC, ML-DSA, FN-DSA

Sent from Outlook for iOS<https://aka.ms/o0ukef>
________________________________
From: Deirdre Connolly <durumcrustulum@gmail.com>
Sent: Sunday, February 2, 2025 9:17 AM
To: Quynh Dang <quynh97@gmail.com>
Cc: IRTF CFRG <cfrg@irtf.org>
Subject: [CFRG] Re: Progressing NTRUPrime/Classic McEliece drafts

> I think the CFRG needs to run a competition process

Has CFRG ever done anything like this?

On Wed, Jan 29, 2025, 12:52 PM Quynh Dang <quynh97@gmail.com<mailto:quynh97@gmail.com>> wrote:
Hi all,

Below is my personal view which does not imply any view from NIST or anybody else.

I think the CFRG needs to run a competition process to select a lattice-based KEM to provide a good option for the users who don’t want to use ML-KEM or NIST’s standardized cryptographic methods generally.

At least there are 2 candidates we all know right now which are NTRU ( see here https://www.ntru.org/) and Streamlined NTRU Prime (see here https://ntruprime.cr.yp.to/) . There are important differences between them; they are not “about” the same. Something is true with NTRU does not mean it is automatically true with Streamlined NTRU Prime (security, performance or IPR etc.).

Here are the reports of the second and third rounds of NIST's KEM selection process which had both candidates: https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8309.pdf  and https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8413-upd1.pdf .

It would be very useful to have performance data of  (many) different implementations of the options of NTRU and Streamlined NTRU Prime on (many) different platforms including constrained ones beside the data we received during the first 3 rounds.

Regards,
Quynh.
PS: I don’t plan to spend my time replying to potential messages asking me all sorts of things. My apologies in advance if I don't reply to your messages.

On Wed, Jan 29, 2025 at 6:48 AM John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org<mailto:40ericsson.com@dmarc.ietf.org>> wrote:

I agree that CFRG should prioritize things that are likely to be adopted by IETF, but I think it is important that CFRG is not limited to things that have a current customer in the IETF. This would be too limiting for an RG. CFRG must be able to work on things that are likely to be useful by the IETF long-term.
John

From: Kris Kwiatkowski <kris@amongbytes.com<mailto:kris@amongbytes.com>>
Date: Wednesday, 29 January 2025 at 12:30
To: cfrg@irtf.org<mailto:cfrg@irtf.org> <cfrg@irtf.org<mailto:cfrg@irtf.org>>
Subject: [CFRG] Re: Progressing NTRUPrime/Classic McEliece drafts
i haven't seen anyone suggest that CFRG should not publish its own
specifications regardless of what NIST does. That's certainly not
my position. That would be an odd position to take as CFRG has
already done this a number of times.

For primitives like LMS, XMSS, and HKDF, it was IETF that originally developed the specifications, with NIST later incorporating them into its standards.

+1 for CFRG focuses on defining primitives that are likely to be adopted by IETF, ensuring they are well-vetted before becoming part of widely used protocols.



_______________________________________________
CFRG mailing list -- cfrg@irtf.org<mailto:cfrg@irtf.org>
To unsubscribe send an email to cfrg-leave@irtf.org<mailto:cfrg-leave@irtf.org>
_______________________________________________
CFRG mailing list -- cfrg@irtf.org<mailto:cfrg@irtf.org>
To unsubscribe send an email to cfrg-leave@irtf.org<mailto:cfrg-leave@irtf.org>