Re: [CFRG] compact representation and HPKE

Richard Barnes <rlb@ipv.sx> Mon, 15 February 2021 16:51 UTC

Return-Path: <rlb@ipv.sx>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74DF53A0D7D for <cfrg@ietfa.amsl.com>; Mon, 15 Feb 2021 08:51:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.004
X-Spam-Level:
X-Spam-Status: No, score=0.004 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q_b-9rWpz-Wb for <cfrg@ietfa.amsl.com>; Mon, 15 Feb 2021 08:51:01 -0800 (PST)
Received: from mail-qv1-xf2f.google.com (mail-qv1-xf2f.google.com [IPv6:2607:f8b0:4864:20::f2f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B1D7F3A0D7A for <cfrg@irtf.org>; Mon, 15 Feb 2021 08:51:01 -0800 (PST)
Received: by mail-qv1-xf2f.google.com with SMTP id p12so3409054qvv.5 for <cfrg@irtf.org>; Mon, 15 Feb 2021 08:51:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Kv2EUbxrNMuCgh7u4O2ioE3vwKQ4iu0KuFDDCCC/MOQ=; b=F9iI3UJBVrqBaR/jyscztz4FvNcCDTwJYBmKfVDWA/U8urS5zbMYHkqoDH8wSSV9+V 3OMHrUxrtSXo/DLPoQNbRhYhX82hgrqMQgw0uZMX9FTlHYGY+VS2+05CFGpF8/tUjma+ PwlhQeGm4AFr9sVDHDeFIr+qZ2y38SqHGe95A/p6dQBJXinuv+Ts0vH41KEffDkoI1Gm X8F0xCjNDIDA74MCv8fPWBK1ZU267zlgNfkxeJEfDnrfn5LqglmIv+yrwVi98KFDsYb8 Y5+tWX7GRrnsIyEpyh8HyIHXfg24cslLUXOTavA3cDYt1D2Es416UVW4gsYAJz70KM/J YsGg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Kv2EUbxrNMuCgh7u4O2ioE3vwKQ4iu0KuFDDCCC/MOQ=; b=auKfObVbAGgGI6XlNqaxnapHht/g8+y7l9HuisbLwH3vYuBbQutekNFumKmFeznWqL 18lnma3P00Qt7jIhHE8EcSgwPV5Oy7W09dVR7IIc2MR6TBEnKTY+EiT0KMawTbc1vzBP M2H3JzbHRnboANWP7G+dhatLASu113Hnuv2EWcnb8EUTzDmIMXjN/13qSwZFwrwaDgsg 94kycqzXyQKiloVaAwyeK8NknYEA6OzsLkgEMOiA8+7IPniXIzm93IvUeqOOIbe73UYn VXehT3oFOSPuI/KlwyNUNlr/x/AWTpRElg5HVrc4uwUFXjsFtNJ736eXqP354PKtSHb3 iFuA==
X-Gm-Message-State: AOAM531mW9lTWA50lv8Sidvxkt8suxqK6NwZ4zUuSrkTEYiBlxpsCunV jT3/W0iq/GzP+Se1wBoHDj+9FXyKhc1WS8WqHOYl4jU0be1wQQ==
X-Google-Smtp-Source: ABdhPJwQgQUFi+UdhGVk/6vcarWgbCzVQicmB1HSLL1hW4fQyKBlDNAQ/7BxQGEXzO5gIy2f1VVdnZVBLvn6LwigsX8=
X-Received: by 2002:a05:6214:1907:: with SMTP id er7mr8163645qvb.27.1613407860775; Mon, 15 Feb 2021 08:51:00 -0800 (PST)
MIME-Version: 1.0
References: <0fcfb0ed-249b-7cd3-09ba-ed1c73122383@lounge.org> <CABcZeBMGJQ7sAKovy3japXVVLWRB8ydpsDzZxhijvFCtXptsZQ@mail.gmail.com> <e19e3ca1-e209-40c6-82e3-24c6d330bff8@www.fastmail.com> <24202a57-0fff-1a56-480c-dfb59989ab8e@lounge.org> <D2A7FD5D-7261-4908-8675-3C7EE2626E8D@inria.fr>
In-Reply-To: <D2A7FD5D-7261-4908-8675-3C7EE2626E8D@inria.fr>
From: Richard Barnes <rlb@ipv.sx>
Date: Mon, 15 Feb 2021 11:50:45 -0500
Message-ID: <CAL02cgRwrzVHShr3uSd6mkzo_2RULKCDzKBfLz-YxTizWq63_g@mail.gmail.com>
To: Karthik Bhargavan <karthikeyan.bhargavan@inria.fr>
Cc: Dan Harkins <dharkins@lounge.org>, CFRG <cfrg@irtf.org>
Content-Type: multipart/alternative; boundary="0000000000006b676405bb62cad9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/WUNnqHXo5JekmausQzPfmVxcjro>
Subject: Re: [CFRG] compact representation and HPKE
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Feb 2021 16:51:03 -0000

Hi folks,

I think Karthik is on the right track here.  While the compact
representation undoubtedly has its benefits, it seems like there is no
disagreement that it is not widely supported in either standards or crypto
libraries.  So there is a sizable community for whom a requirement to use
the compact format would render HPKE unusable.

Given that, I would propose we resolve this issue in the following way:
* In the current document, define KEMs for the NIST curves using the
uncompressed format.
* If there is a community that is *also* interested in supporting the
compact format, they can define new KEM code points for it.

Would folks be comfortable proceeding on that basis?

--Richard

On Mon, Feb 15, 2021 at 11:45 AM Karthik Bhargavan <
karthikeyan.bhargavan@inria.fr> wrote:

> I think the idea of having a compact representation of EC points for use
> in IoT-like scenarios is an attractive one, but the core ciphersuites of
> HPKE should only depend on standardized and widely-implemented point
> formats.
>
> In particular, HPKE is certainly not the right place to standardize a new
> EC point format, however sensible the change may seem.
> A protocol like EDHOC is laser-focused on small wire messages and is meant
> to be implemented by IoT-specific crypto libraries, and so it makes sense
> for that protocol to employ such optimizations.
> Perhaps the LAKE working group could drive a IETF/CFRG standard for x-only
> EC point representations that are more generally usable by other protocols?
>
> Having said all that, HPKE is extensible and we do anticipate extensions
> to HPKE in the near future, notably for adding PQ ciphersuites.
> I think the best way to proceed for compact HPKE would be, along the lines
> of Dan’s suggestion, to propose new KEM algorithm identifiers for compact
> encodings of the NIST curves, and to do this as part of a new CFRG draft as
> an extension to HPKE.
> I suspect that, beyond the point representation, we may find other parts
> of HPKE that would benefit from compaction for low-bandwidth scenarios.
>
> Best,
> Karthik
>
> _______________________________________________
> CFRG mailing list
> CFRG@irtf.org
> https://www.irtf.org/mailman/listinfo/cfrg
>