Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-signatures-02.txt

Christopher Wood <caw@heapingbits.net> Mon, 30 August 2021 13:29 UTC

Return-Path: <caw@heapingbits.net>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16F4E3A11CB for <cfrg@ietfa.amsl.com>; Mon, 30 Aug 2021 06:29:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=heapingbits.net header.b=MEZg9yit; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=CUdasRd7
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f8rydxBEXsCC for <cfrg@ietfa.amsl.com>; Mon, 30 Aug 2021 06:29:48 -0700 (PDT)
Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DDFB93A11C2 for <cfrg@irtf.org>; Mon, 30 Aug 2021 06:29:48 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id B3DDE3200949 for <cfrg@irtf.org>; Mon, 30 Aug 2021 09:29:46 -0400 (EDT)
Received: from imap41 ([10.202.2.91]) by compute5.internal (MEProxy); Mon, 30 Aug 2021 09:29:46 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=heapingbits.net; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type:content-transfer-encoding; s=fm2; bh=wqJyW TJaOrGxayJ7SO2kS0NBym0B3tF67bwFrq3OsIA=; b=MEZg9yitkj2Dtf+d6ykyM KwloV4/+UuaPRM6pp9SeUdTHrfqx36uizWLJyCzJklTIG5m9637z7ksNUQWP9RZk GglU5DqEpg7U8ngMYVxbO3ARw+yd2oyxwhuafXC+CNVJtSC05EByHVEiXTnwcT6/ +W6M5uMKAaaaNFtikWH/FwTYwmYJYTyrHG9nXFokZGKyV+BzL8Y1l4g6PLQqio4s S8iQmSKKWoNwyZoveeXam2P2Fo3tJrTXwp4IG7MELKtBW94gLxY3WyAJwTVxeblP hEkmD9ciGXSSQlGiF5gt4q1Jynwa58DUzORrASoNE71hJ5I/1MLZ+m+V+tBiWAmu Q==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm3; bh=wqJyWTJaOrGxayJ7SO2kS0NBym0B3tF67bwFrq3Os IA=; b=CUdasRd7byJl7eZp7M7A0AwFRcpWyLV+1+DX8w0BWiD29HPAJVpapVWGM vKa0dQE412nCO18yaI8UvAd/V1Ay36vZwgc7ShWLc+4hZa1/+MhOZx9wunHyPDsv Ca2KuBrR5CvLB0sbRV/9Rz7G2aVQE+1j8lBq53QZ4gvwe5LVI0PfLn3U0yIG78Gd lP5ObQowm9DurCDTVrBS+eiJ43pQrP6M2WL8nNnUW67I1XpXk11p4qYH+gIJncE8 r3oehq1jtOjtTYVerUhvlna3CxdaacoTwUutVsz/yKFuGNMqRc3rJjjgry2VcSpA d4cjn1TTYHn4DWN27IOhEBWuVQMzA==
X-ME-Sender: <xms:Sd0sYUL-kyqqybmLC7ocyJDXzOOmCwm8mBVSbeGaNjXSeoBi97r-AQ> <xme:Sd0sYUKqQAA8hmA5CLnqA9fFga3IIaWvsGtgojCROm8GMXw-rC2vhjyIEuQq1lpqC -4KPDl2Idcc3EO6Boc>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddrudduledgieeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefofgggkfgjfhffhffvufgtgfesth hqredtreerjeenucfhrhhomhepfdevhhhrihhsthhophhhvghrucghohhougdfuceotggr fieshhgvrghpihhnghgsihhtshdrnhgvtheqnecuggftrfgrthhtvghrnhepkeeuleekfe ejgffffefhudduudfhjedtueehheetfeehvdelvefhgfeijefgudfhnecuffhomhgrihhn pehirhhtfhdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrih hlfhhrohhmpegtrgifsehhvggrphhinhhgsghithhsrdhnvght
X-ME-Proxy: <xmx:Sd0sYUsiuFxCtNDAer2Mlpy8DmCvN0j8F6rLZwh_yb6_TDjR-fxJfQ> <xmx:Sd0sYRZoPdWazftTnLXWNw0pMn8zgP-I_rBL39xNqIe7OMYtrwDhRA> <xmx:Sd0sYbbZNDtlBHc2FRnNLH8OxA08LPR1AbV0BNSUZSABB3qbaifVAQ> <xmx:St0sYUkv2bFOx9wesNYKzARGYMQ_9xq2OVZDtA3ttt6e4wppJY9RJg>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id A15393C0EB8; Mon, 30 Aug 2021 09:29:45 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-1125-g685cec594c-fm-20210825.001-g685cec59
Mime-Version: 1.0
Message-Id: <6616faf7-f4b4-4b5c-9f60-1020f714809b@www.fastmail.com>
In-Reply-To: <0EBB4DB4-E732-4188-B535-A4A0D664355A@gnunet.org>
References: <162791899203.1107.7194332652638927873@ietfa.amsl.com> <0aab06f7-7beb-4ccc-ab8b-3a09d4d3c8fc@www.fastmail.com> <20210802172912.GK6513@yoink.cs.uwaterloo.ca> <a154ab88-7410-4346-8f7a-110f8e9a5591@www.fastmail.com> <CAMr0u6=QrGQt5UPzbwEs+zmLuzgB+KC2OJ0R+C0Md0EkXWWFmw@mail.gmail.com> <b4ab82f15439491bb265ba6d64d60185@uwaterloo.ca> <0EBB4DB4-E732-4188-B535-A4A0D664355A@gnunet.org>
Date: Mon, 30 Aug 2021 06:29:25 -0700
From: Christopher Wood <caw@heapingbits.net>
To: cfrg@irtf.org
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/T4aZ30GseKiuy4SYtCSPIuIVJFQ>
Subject: Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-signatures-02.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Aug 2021 13:29:55 -0000

(-list)

On Mon, Aug 30, 2021, at 3:17 AM, Jeff Burdges wrote:
> 
> I wonder if the underlying RSA scheme should be called roughly RSA-PDH 
> or something, where PHD = partial domain hash, because the security 
> does not come via the same argument as in PSS.

Can you please elaborate on this? PSS _is_ the encoding scheme used in this draft, so I don't see why we'd change the name of the encoding scheme here. 

Thanks,
Chris

> > On 30 Aug 2021, at 05:00, Chelsea Komlo <ckomlo@uwaterloo.ca> wrote:
> > Section 5.1.1
> > 
> > "The blinding factor r must be randomly chosen from a uniform distribution. This is typically done via rejection sampling."
> > 
> > Is this not implied by the function random_integer_uniform?
> 
> In principle yes, but their desire to use PSS as a “partial domain 
> hash” worried some of us that people would reuse the PSS “hasher” for 
> the blinding factor, which instantly breaks the anonymity.  We’ve 
> enough cases in elliptic curves where being full domain does not mater, 
> ala ECDSA, that people do fuck this up in blind RSA.  I suggested 
> finding more specific language for this reason.  
> 
> Jeff
> 
> 
> _______________________________________________
> CFRG mailing list
> CFRG@irtf.org
> https://www.irtf.org/mailman/listinfo/cfrg
>