[CFRG] Re: ML-KEM for HPKE: just use seeds
"Markku-Juhani O. Saarinen" <mjos.crypto@gmail.com> Sun, 13 October 2024 10:45 UTC
Return-Path: <mjos.crypto@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B269C14F5EC for <cfrg@ietfa.amsl.com>; Sun, 13 Oct 2024 03:45:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZhR0_yNNdtnH for <cfrg@ietfa.amsl.com>; Sun, 13 Oct 2024 03:45:17 -0700 (PDT)
Received: from mail-pj1-x1030.google.com (mail-pj1-x1030.google.com [IPv6:2607:f8b0:4864:20::1030]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 676C7C14F5E8 for <cfrg@irtf.org>; Sun, 13 Oct 2024 03:45:17 -0700 (PDT)
Received: by mail-pj1-x1030.google.com with SMTP id 98e67ed59e1d1-2e2d1858cdfso2066259a91.1 for <cfrg@irtf.org>; Sun, 13 Oct 2024 03:45:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1728816317; x=1729421117; darn=irtf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=GRnh2AR8DeHoX3r+4Ua7CVW/1BWBc1PNxuOJc97tAm8=; b=hskHyc0DsrYNEg7bhgCEMmDH1tbChapNqh/78zlkBlUGDul1upRRgzHi/MK14W5cgq 0sx+BpSKujN/UDD/1nQc18MInda/BJSNLGOJtoWk33p3Ja+4Evv65ceu6XfIEfWrMVoS GVaTcgUltqNCmMaSAD/YQij/bDu/1v8dfv4fyZUhZltgLivFAma3o7g3R8KpSjvvyVMO cafiNTGnQOZThq/8LNnhyJ6RKpNJV5ZinEPy42CS4GdlJy5JuosIwSGHwfGnIBGZi9Jc QcUhdf+AfaOMl0Ub3VFTWxw9oEI+s8eHqPamX4M73BXUFcRpzcRx825T0IBKTSAWVuyg Sy2Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1728816317; x=1729421117; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=GRnh2AR8DeHoX3r+4Ua7CVW/1BWBc1PNxuOJc97tAm8=; b=dWOVKd2yRAhjxfTCbKHqnqVGfAay84sjnkQvECdiMMlshh9R845VLN6sM6nxo/nFl/ /wwUT3f+KYdvbviGfNzGrQi880lh+C8xUjn6jebUreF7KnWtogMXca5yJzn6HE59cbyI sjzmHSNwbEHbG23BJoxdNxLmGB5PUPcSFa+vh+h96lFurEZb9uxmdQ7ZO/BlPnH6dU1G g/GDySZ5oviSKN8l4HMY7I+2HwpclfbLGmhr9wO7FLgCjTTRccxmXcVIj/601J4erpBr S3MKuLSXxbYDw+X3wjkQYWd01iD5GpNrokqfMHNptRMk1nStmCjmWA6vAGFIteUjCDJT mq7g==
X-Forwarded-Encrypted: i=1; AJvYcCUvNXZfpaoY9c9hTvkObQx42UnFaMJlK+oSQ1mex3o959Of0P0y/++Ajnd8Z9xVLneokir+@irtf.org
X-Gm-Message-State: AOJu0Yz+ZTUWI5BWfzgO1w3V3bv+i73VbRHV59DE3lghmhDp8vTAtZWo 6nvFayugnu/tMA5dG+UIRwlMzTlGa418n/h4wyBTnkZBiGeJLNDWi5LIvcGYpd5zS5kdrXe5VKe 3ZMijJ7t28NaIInsLIhMmbXyMaHdtHm4lwFI=
X-Google-Smtp-Source: AGHT+IHEqnyVhzvm9c6uVIiRWEQsZZed1dw6cYwZZCD+67EEBs0G+AwhLZjJtiXJcMfKejTkPsnsBn3NI+IBtH1FRE8=
X-Received: by 2002:a17:90a:ac0e:b0:2e0:a926:19b1 with SMTP id 98e67ed59e1d1-2e2f0dc6aafmr10105963a91.38.1728816316615; Sun, 13 Oct 2024 03:45:16 -0700 (PDT)
MIME-Version: 1.0
References: <CAFR824xpwetkdZZL29TZoa2pEE6Ke537eNuritKbBJZ0wiCKYQ@mail.gmail.com> <GVXPR07MB967810A9BD4AEED8A11F8EAA897B2@GVXPR07MB9678.eurprd07.prod.outlook.com>
In-Reply-To: <GVXPR07MB967810A9BD4AEED8A11F8EAA897B2@GVXPR07MB9678.eurprd07.prod.outlook.com>
From: "Markku-Juhani O. Saarinen" <mjos.crypto@gmail.com>
Date: Sun, 13 Oct 2024 10:45:05 +0000
Message-ID: <CA+iU_qmyHFfaXo8pKJoJrnvSn8Sfc9BtnAEUp0sqZAEYV27HkA@mail.gmail.com>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="0000000000006f15790624596a33"
Message-ID-Hash: 6W2T4JI35NCMCGWZJIXM72PIKOS4SNBU
X-Message-ID-Hash: 6W2T4JI35NCMCGWZJIXM72PIKOS4SNBU
X-MailFrom: mjos.crypto@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: CFRG <cfrg@irtf.org>
X-Mailman-Version: 3.3.9rc5
Precedence: list
Subject: [CFRG] Re: ML-KEM for HPKE: just use seeds
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Q2hAFFvPmUeUOAV6gW8CNmjNQBQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
On Sun, Oct 13, 2024 at 8:11 AM John Mattsson <john.mattsson= 40ericsson.com@dmarc.ietf.org> wrote: > I think it would be good if the draft registered KMAC based KDFs. While > HMAC-SHA-2 could make sense in a transition period, it does not make sense > to force future implementations to support both SHA-2 and SHA-3. ML-KEM > uses SHA-3 internally so any implementation of ML-KEM has an implementation > of SHA-3. > +1 Especially in pure hardware SHA-2 is slow & relatively cumbersome to protect against side-channel attacks. It would be unfortunate that after putting a lot of effort to have a protected ML-KEM, the secrets would be just leaked out by the KDF. And of course, since SHA-2 is not not used that much in PQC era, having it around is just an extra hardware cost. The standard NIST SP 800-108r1-upd1 "Recommendation for Key Derivation Using Pseudorandom Functions" defines a KMAC-based KDF. https://doi.org/10.6028/NIST.SP.800-108r1-upd1 This is already covered by ACVP (i.e. I can get a FIPS cert for it.) Some NIST test vectors are at: https://github.com/usnistgov/ACVP-Server/tree/master/gen-val/json-files/KDF-KMAC-Sp800-108r1 I recall SP 800-108r1-upd1 has a version there that can be ran in counter mode (i.e. parallelizable to make it arbitrarily fast if that is a priority for someone.) Cheers, -markku Dr. Markku-Juhani O. Saarinen <mjos@iki.fi> > > > Cheers, > > John > > > > *From: *Deirdre Connolly <durumcrustulum@gmail.com> > *Date: *Friday, 11 October 2024 at 19:20 > *To: *CFRG <cfrg@irtf.org> > *Subject: *[CFRG] ML-KEM for HPKE: just use seeds > > Hello CFRG, I have published a new-new version of 'ML-KEM for HPKE': > > https://datatracker.ietf.org/doc/draft-connolly-cfrg-hpke-mlkem/02/ > > > Previous versions used ML-KEM to craft an updated KDF out of HPKE's > subroutines to achieve similar binding properties to the default KEM for > HPKE, DHKEM. With the final publication of FIPS 203 > <https://doi.org/10.6028/nist.fips.203>, we now have a better compromise: > the officially FIPS-compliant 64-byte seed format of ML-KEM keys. This > format gives us MAL-BIND-K-CT and LEAK-BIND-K-PK security > <https://eprint.iacr.org/2024/523.pdf> out of the box. This seems good > enough for most use cases (especially inside IETF so far) and so I have > updated my document to just say, 'use ML-KEM as it is, but you MUST use the > 64-byte seed format for the keys', and that's it. Hopefully you can take a > look. > > Thanks! > Deirdre > > > ---------- Forwarded message --------- > From: <internet-drafts@ietf.org> > Date: Fri, Oct 11, 2024 at 1:06 PM > Subject: New Version Notification for draft-connolly-cfrg-hpke-mlkem-02.txt > To: Deirdre Connolly <durumcrustulum@gmail.com> > > > A new version of Internet-Draft draft-connolly-cfrg-hpke-mlkem-02.txt has > been > successfully submitted by Deirdre Connolly and posted to the > IETF repository. > > Name: draft-connolly-cfrg-hpke-mlkem > Revision: 02 > Title: ML-KEM for HPKE > Date: 2024-10-11 > Group: Individual Submission > Pages: 7 > URL: > https://www.ietf.org/archive/id/draft-connolly-cfrg-hpke-mlkem-02.txt > Status: https://datatracker.ietf.org/doc/draft-connolly-cfrg-hpke-mlkem/ > HTML: > https://www.ietf.org/archive/id/draft-connolly-cfrg-hpke-mlkem-02.html > HTMLized: > https://datatracker.ietf.org/doc/html/draft-connolly-cfrg-hpke-mlkem > Diff: > https://author-tools.ietf.org/iddiff?url2=draft-connolly-cfrg-hpke-mlkem-02 > > Abstract: > > This memo defines ML-KEM-based ciphersuites for HPKE ([RFC9180]). > ML-KEM is believed to be secure even against adversaries who possess > a cryptographically-relevant quantum computer. > > > > The IETF Secretariat > _______________________________________________ > CFRG mailing list -- cfrg@irtf.org > To unsubscribe send an email to cfrg-leave@irtf.org >
- [CFRG] ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds Rohan Mahy
- [CFRG] Re: ML-KEM for HPKE: just use seeds Rohan Mahy
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds John Mattsson
- [CFRG] Re: ML-KEM for HPKE: just use seeds Markku-Juhani O. Saarinen
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds John Mattsson
- [CFRG] Re: ML-KEM for HPKE: just use seeds Nick Sullivan
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly
- [CFRG] Re: ML-KEM for HPKE: just use seeds Deirdre Connolly