[CFRG] Re: draft-irtf-cfrg-pairing-friendly-curves-13: closing #74 and #84 (comments by Aug 3)
Emil Lundberg <emil@yubico.com> Mon, 27 July 2026 17:34 UTC
Return-Path: <emil@yubico.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C44C411F6254F for <cfrg@mail2.ietf.org>; Mon, 27 Jul 2026 10:34:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785173660; bh=TRQSksdSzaPkAwwGtB99EDG4wj5l0hZNWN/yIzAl8DA=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=x9lI3+eo/y+juxCoaCVLtk+YOFThZXItLJqrNND/HCzaGT4f0IokVxPNYJSk3zubk owAbywnik15H9cImFlUHAp5vdZCieiwjGLWgEIaDa5TGbMTj8sd/nl7UjD1gw3Tj/b jLBcTCrFKkRiTZ8DtzW0cZp3XG2QUXgte83ygkpI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.087
X-Spam-Level:
X-Spam-Status: No, score=-2.087 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=yubico.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VlPHqXt_ruhw for <cfrg@mail2.ietf.org>; Mon, 27 Jul 2026 10:34:20 -0700 (PDT)
Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [IPv6:2a00:1450:4864:20::42f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 34D3211F62541 for <cfrg@irtf.org>; Mon, 27 Jul 2026 10:34:20 -0700 (PDT)
Received: by mail-wr1-x42f.google.com with SMTP id ffacd0b85a97d-47f6609c657so1385972f8f.2 for <cfrg@irtf.org>; Mon, 27 Jul 2026 10:34:20 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785173653; cv=none; d=google.com; s=arc-20260327; b=Pg7BOgvU9q5RjthR1OcsBuYLpAu17q/EE2O+vkATRwAOvfXue7C9fAwJQzNFuJRGX5 yI61zffKEXOC7cE+jdUdD/AdKfB6IB/o83ULIzrv/VBHrEgMPgbwTw9gHZxzy0xXg+qT QXnsfVWof1A7EjcGnMaBHrWHAVCnDnjKdGOm1byyVScJdTmphS00iKoAHhnC5UFbV1rs gJGNM0RO4J35VSokTpO6LEzaDh7V6q35gONEQW81rjHjAZ0fSVmvY4Egx2ZhxKGZwYE5 5GX1DJOxPPfqTNeyonkywAf6WTYB3Sq4F7vQaPqw7Id8nFaEWezqJLmlM3rpEL43n+g1 3aWA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=TRQSksdSzaPkAwwGtB99EDG4wj5l0hZNWN/yIzAl8DA=; fh=cNAJyXuG7jQmobNXuWAwvfqQjb8IunhiD6BXTs5jD4E=; b=swBOjg0GpVNG9B7yJhWxQ9EsI9Bv0rqZXuNIrmorwCYYm7I2mZmbM6AZhdtfwKs/yp ubcBWa29vFVG7urs2TLZz50Gk2aVIJIy5RuB7aETsDf+VwwqHRik8gl/uM7HOdxuK85x DWBF5/MCOLm1YTf0Jg8BfcQ/bOiByNLojDHBSgeAspvkNaN841xy5mxm798PxI7WSMVC ygSBbkX9kC3i+xr6tvQ9sakKBufg4wGjTqHOnwJzX305Ficq3ksfossW5TcuL71J3sZL qMdJO5fexWBWTWg2/8ZlVcuXB6XnF1m32b4KAE2k1flyaiP3TGyQ/17u/ufX1GhR6x88 ZCGA==; darn=irtf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yubico.com; s=google; t=1785173653; x=1785778453; darn=irtf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TRQSksdSzaPkAwwGtB99EDG4wj5l0hZNWN/yIzAl8DA=; b=Fz5abT/eYUbFgDTGAG1ts+yMkziwCLuVJgXFaSB7JWzU4Cs9kEvOKAFnY5mtChnJDZ QDWgxBxHpa3optgYI1USAGPuF9Bn+QOPDRkxWOtrFN7KbXK07WfVFZ4LKWufgcymJ1Yn hClmQf+IyV4ZwrlNsZ7wE0FiFLuqDU3PULRNT4iykWwaa1bMWDJfi0aqtsV0xvA9sZz9 QdfbGTMf/g6Vg6LHawNoUPA15C8zXBBXNkawwhDwsIjgyNujI2AzPSZ5BbdTKdaQ9Dzm 4UxEOh1YScjp3NqoxCyZ+TOPtEQfkWCsBroNuT7TL72HV/jU2lL9zRhIEnp/+1bjqOEC D+Yw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785173653; x=1785778453; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=TRQSksdSzaPkAwwGtB99EDG4wj5l0hZNWN/yIzAl8DA=; b=o8STDhmGIQ4Mi0bnyqBIpidnvVn/cwJW3xk+EjBzWcWAb9Lvvi7hJoM661/t24ofGI UT5k8EtEddDL3eT7Xt4czAhWMYgiHVhfdsyU4XbmHuvYuPY0hr6p4p/jfx3VIbGgqGf9 Sn4IEX6jMLteWrjpmakeVetsalYp+Jl6wLFFwBX6ILnef4v3lRhQEKgfkK7f9ayctdT0 TGW7ErDJqVSHP0Ex+1Xx/ElIzY6k0v5UnOmofibdo0Ax9uEZc12WSEQPTS67S2q9hMsY +oVmytNhgTFDkXupGu3Hh/HhDCfLT29wmJCFtVm3JoM/wb0fHvg1zg8XTTkfCS5g27Df P/tQ==
X-Gm-Message-State: AOJu0YyPvAGV8qz1xGRqZCkXrGO/vwQINd7nOb5UMQSTLDlTe0hc8Tmj DuqxHqxXcjc0AVtp5Xcfq5lYhRVh9GPCPoKNDw5GU8FANENtfg0bn0zGbw8BWP79ClhcGFyZdcT MV4XRcAIcAED4U/g2VFFwvOqoYlsVX86sZGc7+4xvQw==
X-Gm-Gg: AR+sD12LQ/tFiHEg+rajn2YjZu5nlrMixZZ1Nkv7BSVP+wwpTtTNiT8qW53aM2EjyFy /3Yp7EwAwCQoX1k19jKWKmEIJlvoJLTIsslm2XFNQerfSgENaANVSx/lka8DqhCevcfU5wrmU4D BXG4Ly27chMdUJpGTlgcNY1MrXg9cMa2aAqldInBtp3ugY7wcO/1WQruRQm3Rcy2fRcjR3h50TS VUZLzaKH/I7aBhyAVfFIk2nFLNVVpDBM5Dcp4zH9qRDoyY9MEj7ggDrHeqk6aRxw95xWGEcNkAU 8vLUL2kxPidla6ypUBhV68LdUkEOVjgz
X-Received: by 2002:a5d:64eb:0:b0:47f:93ea:cf47 with SMTP id ffacd0b85a97d-47f9fe97d00mr12404538f8f.37.1785173652863; Mon, 27 Jul 2026 10:34:12 -0700 (PDT)
MIME-Version: 1.0
References: <CANZ5RKVS0Hjxg=OmEqHUGvXc8pRGtaE9eDGXgDbAQ+v_wYB3dA@mail.gmail.com>
In-Reply-To: <CANZ5RKVS0Hjxg=OmEqHUGvXc8pRGtaE9eDGXgDbAQ+v_wYB3dA@mail.gmail.com>
From: Emil Lundberg <emil@yubico.com>
Date: Mon, 27 Jul 2026 19:33:55 +0200
X-Gm-Features: AUfX_mwDlnY0JcWOThrdYEak-3RQz77dR6UdaySk5KeArhxSHhHZQy2t4kDkjME
Message-ID: <CANMnvkzU3sbvz4JqxsXiqYF6m4420dyLjjMdX-QQg09-U=H_GQ@mail.gmail.com>
To: Yumi Sakemi <sakemi-yumi@gmo-connect.jp>
Content-Type: multipart/alternative; boundary="00000000000071148f06579b214e"
Message-ID-Hash: JDLTVK6A3TR53HTZXFWY6ZVNJHQA75YJ
X-Message-ID-Hash: JDLTVK6A3TR53HTZXFWY6ZVNJHQA75YJ
X-MailFrom: emil@yubico.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: CFRG <cfrg@irtf.org>, Satoru Kanno <kanno@gmo-connect.jp>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: draft-irtf-cfrg-pairing-friendly-curves-13: closing #74 and #84 (comments by Aug 3)
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/UIDHgwRtkl86O37kQDET-wWWwPc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
Hi Yumi, Yes, here are the issues I found with the serializations and deserializations: 1. The octet string encoding in Section 2.5 <https://www.ietf.org/archive/id/draft-irtf-cfrg-pairing-friendly-curves-13.html#name-representation-convention-f> (from ietf-lwig-curve-representations) is little-endian (polynomial coefficients in ascending order s_0 + s_1*i + s_2*i^2 + ... for both polynomials over GF(p) and over GF(p^d)), while the serializations in section 5 are big-endian (coefficients in descending order). But it also seems like section 2.5 is not referenced anywhere, at least within this same document? So perhaps section 2.5 can be deleted, then. Sections 4.2 and 4.3 as well as Appendix C still write polynomials in little-endian order, but I don't think that is a problem since the indeterminate powers are explicitly written out each time to disambiguate. 2. The deserialization procedure in section 5.3 <https://www.ietf.org/archive/id/draft-irtf-cfrg-pairing-friendly-curves-13.html#name-point-deserialization-proce> implicitly only works for E(GF(p)): Steps 5-7 unconditionally parse the whole x_string (and y_string where present) using OS2IP; for E' the coordinates need to be split into m parts. I can submit a pull request to GitHub with a suggested fix if you'd like (you are of course welcome to edit it however you like to fit your writing style). 3. Also in section 2.5, the reference [MP04] is described as "Cocks–Pinch curves of embedding degrees five to eight and optimal ate pairing computation" in "Cryptology ePrint Archive Report 2019/431, 2019", but the eprint link leads to "Compressed Pairings" by Scott and Barreto which is 2004/032. The reference text seems like it should point to https://eprint.iacr.org/2019/431 , but the reference in section 2.5 is "using the compression method [MP04] may be more effective." which does seem to rather refer to "Compressed pairings". Although this reference may be redundant if section 2.5 is deleted as discussed in point (1). I also have some more review comments unrelated to issues #74 and #84, so I'll post them separately. Thanks again for your work! Emil Lundberg Staff Engineer | Yubico <http://www.yubico.com/> Den mån 27 juli 2026 kl 08:25 skrev Yumi Sakemi <sakemi-yumi@gmo-connect.jp >: > Hi Emil, and CFRG, > > Thank you again for the discussion during the pairing-friendly-curves slot > at IETF 126 last Friday -- both the feedback on the draft and the chairs' > guidance on next steps were very helpful. > > Two quick follow-ups: > > To Emil -- during Q&A you mentioned spotting an issue with the > specification of the serialization procedure, but didn't have time to go > into the details. Would you mind sharing what you found (on the list or on > GitHub, whichever is easier)? We'd like to file it as an issue and get it > fixed. > > As the chairs suggested in the session, we're planning to close issues #74 > and #84, since we believe -13's Section 5 addresses them. If anyone has > comments or objections, we'd appreciate hearing them by August 3rd, before > we close them out and move toward the next Crypto Panel review. > > Thanks again, > Yumi > > > > > -- > > --- > > Yumi SAKEMI > > GMO CONNECT, Inc. > > sakemi-yumi@gmo-connect.jp >
- [CFRG] draft-irtf-cfrg-pairing-friendly-curves-13… Yumi Sakemi
- [CFRG] Re: draft-irtf-cfrg-pairing-friendly-curve… Emil Lundberg