Re: [Cfrg] Ed448 hash choice

Alyssa Rowan <akr@akr.io> Fri, 16 October 2015 20:08 UTC

Return-Path: <akr@akr.io>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 37CE91B33AF for <cfrg@ietfa.amsl.com>; Fri, 16 Oct 2015 13:08:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x4IDHO7k2qSJ for <cfrg@ietfa.amsl.com>; Fri, 16 Oct 2015 13:08:03 -0700 (PDT)
Received: from entima.net (entima.net [78.129.143.175]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D1261B33B0 for <cfrg@ietf.org>; Fri, 16 Oct 2015 13:08:00 -0700 (PDT)
Message-ID: <562158FE.8010800@akr.io>
Date: Fri, 16 Oct 2015 21:07:26 +0100
From: Alyssa Rowan <akr@akr.io>
MIME-Version: 1.0
To: cfrg@ietf.org
References: <87twprupdy.fsf@latte.josefsson.org> <20151016150447.GW15070@mournblade.imrryr.org>
In-Reply-To: <20151016150447.GW15070@mournblade.imrryr.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/cfrg/N5mPTtCqcY5pE0RQhc9fnf8nNQQ>
Subject: Re: [Cfrg] Ed448 hash choice
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Oct 2015 20:08:05 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2015-10-16 16:04, Viktor Dukhovni wrote:

> 1.5) SHAKE256 for internal hash and SHAKE256 for pre-hash.

Another +1 for this option overall - it makes perfect sense.

BLAKE2 is brilliant, and I'm OK with that too, but we've got
choices to make as to how to stretch it if we use that.

Using the SHAKE256 XOF, and sticking with that for Ed448, seems
like the most natural solution to me.

Remember that NIST approved SHAKE256 as an XOF, _not_ a hash
function, because different length outputs of the SHAKE* functions
with the same inputs share prefixes. Maybe avoid calling it a hash?

As Taylor suggests, for that reason, domain-separation of the two
uses would be a sensible, conservative choice to avoid any potential
problems.

- -- 
/akr
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJWIVj0AAoJEOyEjtkWi2t6E3QQALP9/RZcJtun+DXIcg+pQGmX
EI1c2OjjNGGba73RKGFbW7UH6C52gj5iHGwaUS1IQqgzbt+cYwr00hUcylZgdU1f
BNB1JrjHZFTrhoFKFzRCaX8PrlniHJKmL838LxLbtxDwlwthau02LbEXQ2HgWzcp
/uclpYv1fZ3vF3MkmQHJNkWqitfIORyskHMDwuF/VTHETZjbOph3iOFzHGOfsbYm
JMU1iFshgw3TvMUPL06BXzz6GX02KXMHa3bZWp64r8Q+rwA7N5NM/CQdvq351cTG
3yB4ALr1SgkcggvFUt0dfOE6X2EtrffGy2RQHih+PoYulmuYMG2zO5I/JgMSbuCz
y7RHmpI+XS2QSxMHEXjIHSu8O2xM8dp9awr7kR1zGqdj4QDc/08tJpH6K7Netuud
gHFMN0dOoue6QkaI9C8sRDXh3Oop03Qf6XfeV4T8mIrdU7J8cXdIFTyYQU2tj+4L
MieQXGdXrLK89iZYhIHwPQc32qjaPC+xXHv1gE8/Pk7YrEPPdsJ4IOCtGyKuwDPw
y/cr8jiSTSokfqWSHUIFcQgJCTYhHLMderD2SIzCkmifni4Ckz0X86qvuExGa0iJ
S73sTxrOd9RjTYU4Hh91IQNIJpIWIST5Ey46+1bbrq+kkU67qUfxd1crT8czwaFs
8d0riZd1PR3kNrmzpIud
=ht4J
-----END PGP SIGNATURE-----