[CFRG] Re: ML-KEM for HPKE: just use seeds

Deirdre Connolly <durumcrustulum@gmail.com> Mon, 14 October 2024 20:59 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7BDE0C1D52F1 for <cfrg@ietfa.amsl.com>; Mon, 14 Oct 2024 13:59:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.854
X-Spam-Level:
X-Spam-Status: No, score=-1.854 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QB_1xeL6ZooB for <cfrg@ietfa.amsl.com>; Mon, 14 Oct 2024 13:59:35 -0700 (PDT)
Received: from mail-ed1-x52c.google.com (mail-ed1-x52c.google.com [IPv6:2a00:1450:4864:20::52c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A07CEC14F6BF for <cfrg@irtf.org>; Mon, 14 Oct 2024 13:59:35 -0700 (PDT)
Received: by mail-ed1-x52c.google.com with SMTP id 4fb4d7f45d1cf-5c9428152c0so5906190a12.1 for <cfrg@irtf.org>; Mon, 14 Oct 2024 13:59:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1728939574; x=1729544374; darn=irtf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=WuMZpi1gIE/DGRwci4n7qnakJ+VNIuTq40eSvQV9jN0=; b=BfJXE3dot9zExAhCCN+N+PGbAXAXKXcxP2P5Dcc4qmudq2M7CTFkDA7JW/Q+PmZfx6 kJIjoTVMpeit+3bbJMkR3SAHuMp7T9631kjKvkfYmg+sXI/+Wbtpf6AQPPt23OjarfMh qIVsNEvTnViGfuM+kHEpmQec0zytky7/BZCH1rvqsU/MgvYEYgjUy55RDJevcAnZJHJ6 d6DE3ak+F91MwrE2OQJxvFQTZMfOyKkf8OqMYbkT5l1Y9Z9cWpygNm95OhnATYA5V99A 0xFcBuTk14bZERB8a987Rd8bEfSQ6epxF2GZZoghwUmNZFqEVnzFlRIqnzdZmtto6UQC 6RVA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1728939574; x=1729544374; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=WuMZpi1gIE/DGRwci4n7qnakJ+VNIuTq40eSvQV9jN0=; b=aMhIs9kE+AGi+vFWrDTKaruoBNqNScKA9N5H+ME0/fQfSxCAK2fiTsUznEnZhqzDtu iv+dQdI8B35kFy15uGa94+KrhO3GRMrA9ejRcylSX1mBc9gkmp9Zbz9dfz7Z9BdSqEtf HrqiPOx/TMnki5izhgQSxH0yl5g5ydbUGbWTTV/qbUDoVXqF1f8xMseqNv+izP6lRzQC f5h5SiE/rFRTfv3HV8zEmODzUWpGl6gZJgh5Y44lyIv76sAa8MhEzhFB7GmSNSIW7by9 3/ixxo/QJeNrLNIIeM9c068x7m/BkGMb1LGwC9yTQLd1COP1Vf0w99ZL8O3fSVP2765v 7zMw==
X-Gm-Message-State: AOJu0YzybLixpMSBDK1ng/j5u9n/k3EHYCCOftdpEk8p9DxS6Gkfsloh bU4BL54zYDAx+1156HvMqdK//+y4hwfMvZms5BlJuHcPvd4Q94Ja/nH7UO4NJYIjbvCgjpOso+6 3+mofdIsU6lbPKsIVYZmtCTd8r5SDzg==
X-Google-Smtp-Source: AGHT+IG81XYheTUkh1gDl42nHZQvZfV7qeXb0owjlW5nJKGZ90U8TPWglPV5qPMj7ouQCNmHI0nGQy/VREvdRp4MwdY=
X-Received: by 2002:a05:6402:4414:b0:5c9:48e0:66d1 with SMTP id 4fb4d7f45d1cf-5c948e06798mr10676042a12.35.1728939573227; Mon, 14 Oct 2024 13:59:33 -0700 (PDT)
MIME-Version: 1.0
References: <CAFR824xpwetkdZZL29TZoa2pEE6Ke537eNuritKbBJZ0wiCKYQ@mail.gmail.com> <CAKoiRuaocTHe0YJr=cdF57v0mcFOYi8K39jr_s0tqOX9OG4xXA@mail.gmail.com> <CAKoiRuZRH4QkMi8DXc-PrBZYsVcbXiqgzR+ZX6q9GTZB9ymBJA@mail.gmail.com> <CAFR824wfQRw0sYPn9se0gHzCQd=7U1RFn0wFs3rNyJ-yrnsqNg@mail.gmail.com>
In-Reply-To: <CAFR824wfQRw0sYPn9se0gHzCQd=7U1RFn0wFs3rNyJ-yrnsqNg@mail.gmail.com>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Mon, 14 Oct 2024 16:58:56 -0400
Message-ID: <CAFR824yYRsDu3sn5kVCS1SmdSPmEeHbskNSbky7G6kJKO==t-g@mail.gmail.com>
To: Rohan Mahy <rohan.mahy@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000019bcf10624761d19"
Message-ID-Hash: LWGZK4Y6XIGZAPI37UXPDIVSDXF7XDSH
X-Message-ID-Hash: LWGZK4Y6XIGZAPI37UXPDIVSDXF7XDSH
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: CFRG <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: ML-KEM for HPKE: just use seeds
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Ep-xY-qfoSBKKw_rcj_j2MDaDVk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

With help from Rohan, we have pushed version -03, which removes the
confusing language about KDFs and AEADs and chooses different codepoints in
the HPKE KEMs Registry (now 0x0040, 0x0041, and 0x0042):

https://datatracker.ietf.org/doc/draft-connolly-cfrg-hpke-mlkem/03/

There are some todo's to complete on making the explicit mapping between
FIPS 203 and RFC 9180 functions concrete and some references that should be
done by the 121 deadline.


On Sun, Oct 13, 2024 at 11:47 AM Deirdre Connolly <durumcrustulum@gmail.com>
wrote:

> Yes you are correct - I was thinking I was registering a whole 'HPKE'
> ciphersuite which is incorrect, this is just for the KEM, which is fully
> described by FIPS 203 and doesn't need the extra KDF and AEAD definitions,
> I'll be removing that text.
>
> On Sat, Oct 12, 2024, 5:56 AM Rohan Mahy <rohan.mahy@gmail.com> wrote:
>
>> Apologies for my hasty response on too little sleep.
>>
>> After skimming FIPS203 again, it looks like the hash function is fully
>> specified, so just deleting the paragraph about KDFs and AEAD seems best to
>> me.
>>
>> And NSecret is indeed always 32. It might be worth a note so readers less
>> familiar with ML-KEM don't think it is a typo.
>>
>> Thanks,
>> -rohan
>>
>> On Sat, Oct 12, 2024, 02:23 Rohan Mahy <rohan.mahy@gmail.com> wrote:
>>
>>> Hi Dierdre,
>>> Thanks very much for getting this out. My main technical concern is this
>>> paragraph, which does not provide a clear mapping of ML-KEM size to its
>>> KDF, and muddles cipher suite definition with KEM definition:
>>>
>>> We use HKDF-SHA256 and HKDF-SHA512 as the HPKE KDFs and AES-128-GCM and
>>> AES-256-GCM as the AEADs for ML-KEM-512, ML-KEM-768, and ML-KEM-1024.
>>>
>>> Please define the specific KDF to use clearly in text or in a table. (I
>>> think we can leave AEAD out of this.) I heard much talk of using ML-KEM-768
>>> for the 128-bit and 192-bit security levels. Should we have 3 or 4
>>> definitions for HPKE KEM?
>>> ML-KEM-512 (SHA256) for ??
>>> ML-KEM-768 (SHA256) for 128?
>>> ML-KEM-768 (SHA384) for 192
>>> ML-KEM-1024 (SHA512) for 256
>>>
>>> Regarding the IANA registration section, it requests 0x0512, 0x0768, and
>>> 0x1024. Please don't. 0x0040, 0x0041, etc would be much better. Is NSecret
>>> really only 32 for all three KEMs? I would have guessed these increased to
>>> 48 and 64.
>>>
>>> I'll propose an editorial PR soon, but these are my only substantive
>>> issues.
>>> Thanks,
>>> -rohan
>>>
>>>
>>>