[CFRG] Re: ML-KEM for HPKE: just use seeds
Deirdre Connolly <durumcrustulum@gmail.com> Sun, 13 October 2024 15:48 UTC
Return-Path: <neried7@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58D6CC14F70D for <cfrg@ietfa.amsl.com>; Sun, 13 Oct 2024 08:48:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.858
X-Spam-Level:
X-Spam-Status: No, score=-1.858 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y0Yi1NBaNk2D for <cfrg@ietfa.amsl.com>; Sun, 13 Oct 2024 08:48:06 -0700 (PDT)
Received: from mail-ed1-x52a.google.com (mail-ed1-x52a.google.com [IPv6:2a00:1450:4864:20::52a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D3347C14F5F6 for <cfrg@irtf.org>; Sun, 13 Oct 2024 08:48:06 -0700 (PDT)
Received: by mail-ed1-x52a.google.com with SMTP id 4fb4d7f45d1cf-5c96b2a10e1so1336630a12.2 for <cfrg@irtf.org>; Sun, 13 Oct 2024 08:48:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1728834485; x=1729439285; darn=irtf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=e8gvO+MvICH7wGFf5EcU6CLrYsIw3h2aQd1L8nDJFfU=; b=DRr6CaSHAoA76+of1mR5bK4TF7vMfn79JOXbLwq+qE4Ams+dmBrqTf06URtKG/AJDi Ix4FYai4lhN3SG4anmvrSKF7aPSh60Jvkl9Wftpa18dkXMtwAY9F6Ewank8Q+Y1A6B8k ZraodwhitGKp2UjU7vNTdGtf1hzr4UR04G1h9O1QNheQcC5JmuLes5WfCHz+ns5SOrVY M8e0E3g3e9DT5BEghvby29MRe3goNzIY2ZrGsbo1yBeKC4m17u5ShliCbrmQ9DB/uYiX y4MCsYW5tJo4IyS27dgIoeos6d/4HnED42p2s0AilnmisoNFiVZNfS1z29TDw1exOtRj ytGg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1728834485; x=1729439285; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=e8gvO+MvICH7wGFf5EcU6CLrYsIw3h2aQd1L8nDJFfU=; b=qHFmt3lxf97GeKEFiGH7Z/YG+y5KS/X/FZdUP6HvrHcSjxdoBgTKCJN4VmtDNd5Tq/ PspXfiM/S7isspM9hqJUZArQP1oQ8VaWqNlB1uDIKpSAMbTIuyFBwPPlCL4o4MRqDN9X K5RAV0X/kV+vLGXy0XDDy+T6YG5i4apzsuAtw/qildmUWJBJ2MEipnaE8f5u19GMVHAh BRBMxE8tLVfr0BI6P5CYR7Dyv/F/m2tXnEnXMGeuxHnpNKjdLzlFWSAT72VCRTBkcXRP 05sJgeLMtB9zTg1hm5+uSAXBOVuieqG84gSUDysTgcbg9zRkVHEQq9UF+yvSQSnXVFR5 tXiA==
X-Gm-Message-State: AOJu0YxpSgmOjoaM8IkP1krPRjqi7fauYRtGqx3121OjUGTip2eHM+Z9 MPofvqWeaF9GWxcdtDDS3ZgiuRCzWEMoknqzWFZwM/zxkfGdDlu1bcjMbgk4SY3Q+G8VH1/3HbR OeT5wFT8zBEVgvuyCAA0V96ysC4Y=
X-Google-Smtp-Source: AGHT+IH3PQnu5Tht4iEog8vCQWCmQIeH04R9pzmCIaqKi+Vr9wP9pPGtsCa8xWQuknlCIprQvHJBn/RKIbeR2I609cg=
X-Received: by 2002:a05:6402:3494:b0:5c5:c5c0:74ec with SMTP id 4fb4d7f45d1cf-5c948d4b4c0mr6543043a12.24.1728834484411; Sun, 13 Oct 2024 08:48:04 -0700 (PDT)
MIME-Version: 1.0
References: <CAFR824xpwetkdZZL29TZoa2pEE6Ke537eNuritKbBJZ0wiCKYQ@mail.gmail.com> <CAKoiRuaocTHe0YJr=cdF57v0mcFOYi8K39jr_s0tqOX9OG4xXA@mail.gmail.com> <CAKoiRuZRH4QkMi8DXc-PrBZYsVcbXiqgzR+ZX6q9GTZB9ymBJA@mail.gmail.com>
In-Reply-To: <CAKoiRuZRH4QkMi8DXc-PrBZYsVcbXiqgzR+ZX6q9GTZB9ymBJA@mail.gmail.com>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Sun, 13 Oct 2024 11:47:53 -0400
Message-ID: <CAFR824wfQRw0sYPn9se0gHzCQd=7U1RFn0wFs3rNyJ-yrnsqNg@mail.gmail.com>
To: Rohan Mahy <rohan.mahy@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000051aa0906245da524"
Message-ID-Hash: W42INSTCU2VG2OD5FJUBIZXZSLWRZHPB
X-Message-ID-Hash: W42INSTCU2VG2OD5FJUBIZXZSLWRZHPB
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: CFRG <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc5
Precedence: list
Subject: [CFRG] Re: ML-KEM for HPKE: just use seeds
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Mdlc0OUFbnpjaIvV3D151iZVfYo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
Yes you are correct - I was thinking I was registering a whole 'HPKE' ciphersuite which is incorrect, this is just for the KEM, which is fully described by FIPS 203 and doesn't need the extra KDF and AEAD definitions, I'll be removing that text. On Sat, Oct 12, 2024, 5:56 AM Rohan Mahy <rohan.mahy@gmail.com> wrote: > Apologies for my hasty response on too little sleep. > > After skimming FIPS203 again, it looks like the hash function is fully > specified, so just deleting the paragraph about KDFs and AEAD seems best to > me. > > And NSecret is indeed always 32. It might be worth a note so readers less > familiar with ML-KEM don't think it is a typo. > > Thanks, > -rohan > > On Sat, Oct 12, 2024, 02:23 Rohan Mahy <rohan.mahy@gmail.com> wrote: > >> Hi Dierdre, >> Thanks very much for getting this out. My main technical concern is this >> paragraph, which does not provide a clear mapping of ML-KEM size to its >> KDF, and muddles cipher suite definition with KEM definition: >> >> We use HKDF-SHA256 and HKDF-SHA512 as the HPKE KDFs and AES-128-GCM and >> AES-256-GCM as the AEADs for ML-KEM-512, ML-KEM-768, and ML-KEM-1024. >> >> Please define the specific KDF to use clearly in text or in a table. (I >> think we can leave AEAD out of this.) I heard much talk of using ML-KEM-768 >> for the 128-bit and 192-bit security levels. Should we have 3 or 4 >> definitions for HPKE KEM? >> ML-KEM-512 (SHA256) for ?? >> ML-KEM-768 (SHA256) for 128? >> ML-KEM-768 (SHA384) for 192 >> ML-KEM-1024 (SHA512) for 256 >> >> Regarding the IANA registration section, it requests 0x0512, 0x0768, and >> 0x1024. Please don't. 0x0040, 0x0041, etc would be much better. Is NSecret >> really only 32 for all three KEMs? I would have guessed these increased to >> 48 and 64. >> >> I'll propose an editorial PR soon, but these are my only substantive >> issues. >> Thanks, >> -rohan >> >> >>
- [CFRG] ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds Rohan Mahy
- [CFRG] Re: ML-KEM for HPKE: just use seeds Rohan Mahy
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds John Mattsson
- [CFRG] Re: ML-KEM for HPKE: just use seeds Markku-Juhani O. Saarinen
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds John Mattsson
- [CFRG] Re: ML-KEM for HPKE: just use seeds Nick Sullivan
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly