Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-signatures-02.txt
Watson Ladd <watsonbladd@gmail.com> Tue, 31 August 2021 21:10 UTC
Return-Path: <watsonbladd@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id D00D23A0E5D
for <cfrg@ietfa.amsl.com>; Tue, 31 Aug 2021 14:10:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id LZaVMB7CAx20 for <cfrg@ietfa.amsl.com>;
Tue, 31 Aug 2021 14:10:17 -0700 (PDT)
Received: from mail-il1-x130.google.com (mail-il1-x130.google.com
[IPv6:2607:f8b0:4864:20::130])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id BD7323A0E3F
for <cfrg@irtf.org>; Tue, 31 Aug 2021 14:10:17 -0700 (PDT)
Received: by mail-il1-x130.google.com with SMTP id l10so761945ilh.8
for <cfrg@irtf.org>; Tue, 31 Aug 2021 14:10:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
h=mime-version:references:in-reply-to:from:date:message-id:subject:to
:cc; bh=L1GCPDT4dLiqOiRjhVdZyokXmuHEo09gRD3lx4VhM6I=;
b=lYG4FiQZ/pRhEFVvkZdGSvWeM3bXdoX7/diKflsKUFQMgiHRCca7ZwjNck8S9f3QYj
HekKyBmXw2GCkPxZScsp4g+q+6Nb2lDlLr/6J42nN/u+Hmi/pV80Yw0DN/j1syqPG2Q5
djk+nxHKAImM8tRRaKD3thh0/ajsqCA+gPzUHEzf7BtMR1tIDP+4boFYtgxjIpGXw8BU
YM4NX3qCEWmr2X4yoycx6KK5YNefKED2nR2f/NWIyibMZOyrJkyO4b0dfM/FjQvLKbk3
PBzn3GYBUvjjXyIbP1p+WhEJc+ETBJK5FA9g/OVZCs3kQv4vDXo9FiThbXZh3PDSpHpk
g/BA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:mime-version:references:in-reply-to:from:date
:message-id:subject:to:cc;
bh=L1GCPDT4dLiqOiRjhVdZyokXmuHEo09gRD3lx4VhM6I=;
b=X/CLRU1Psun0sjDTYWEDE65sGa+G4X7/8x9qpMP/59JjyChGQzPkh6DxFX8ng7Ajls
163/0TPkSxUDpsfQUfCh7CvUv+6nRJMdNTOX8GYye8+W3wzZ6zaP8VLAY4i5lMDA6BQR
XAaurEBNYC5E29Bjf1REUNA9SAJ2hhnzeiBEs7Y9roMrJwkBmrldJeuGmDkPIx4rTxeQ
uKGORUtXz8JNAVz4X7OZVgnF7RqewGikSqhvSyTKiQrtAycxBoGW9P5Kvgz/e0li4s9v
1KUYszXlnMe3cJgsu0IvBE/kl3tyU60eaSmpSFDWHGuSvEUt2PQ5wFUUlVGknoFlNFtX
IgAg==
X-Gm-Message-State: AOAM5332HI2XlRZNnkwqYLg6cohAzLQwzUquYTl1kQal1tXmVDdHwmSe
ryz9/g8ZP40TDovUqXit6HV596uZdpREilBm32I=
X-Google-Smtp-Source: ABdhPJyicTQiic4b7Xwyij2LiejmMC1FvgTLU+46YDwjYXE2U31/6zpGdc7OGAct8G1JUxMI5YKfp25l87W8Ibclz1E=
X-Received: by 2002:a05:6e02:108:: with SMTP id
t8mr21932289ilm.216.1630444215490;
Tue, 31 Aug 2021 14:10:15 -0700 (PDT)
MIME-Version: 1.0
References: <162791899203.1107.7194332652638927873@ietfa.amsl.com>
<0aab06f7-7beb-4ccc-ab8b-3a09d4d3c8fc@www.fastmail.com>
<20210802172912.GK6513@yoink.cs.uwaterloo.ca>
<a154ab88-7410-4346-8f7a-110f8e9a5591@www.fastmail.com>
<CAMr0u6=QrGQt5UPzbwEs+zmLuzgB+KC2OJ0R+C0Md0EkXWWFmw@mail.gmail.com>
In-Reply-To: <CAMr0u6=QrGQt5UPzbwEs+zmLuzgB+KC2OJ0R+C0Md0EkXWWFmw@mail.gmail.com>
From: Watson Ladd <watsonbladd@gmail.com>
Date: Tue, 31 Aug 2021 17:10:04 -0400
Message-ID: <CACsn0cnAwO=KfSW3mwRKrjmDZ5w4HTcRgszw0kP1ceJGa_mEog@mail.gmail.com>
To: "Stanislav V. Smyshlyaev" <smyshsv@gmail.com>
Cc: CFRG <cfrg@irtf.org>, cfrg-chairs@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/ZNT94u3u5HMLi1ICt_LpLRVMhGA>
Subject: Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-signatures-02.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>,
<mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>,
<mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 Aug 2021 21:10:19 -0000
Salute omnes, I've taken a look at the draft. First I think that the section on randomized vs deterministic signatures is a bit confusing. The server never sees the unblinded message, so it's not possible to use the salt as a subliminal channel. The draft also says that applications using a deterministic salt should take into account the security considerations but doesn't say what the security considerations that should be taken into account are. In the section discussing related protocols one of the big advantages of RSA over alternatives, namely verification speed, is given short shrift. In cases such as privacy pass where issuance is gated by an expensive verification, but verification must be exposed, expensive verification is a liability. RSA verification can be as small as three multiprecision multiplications: very hard to do much better. I have also not verified the test vectors. Sincerely, Watson -- Astra mortemque praestare gradatim
- [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-sign… internet-drafts
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Christopher Wood
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Ian Goldberg
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Christopher Wood
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Stanislav V. Smyshlyaev
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Scott Hendrickson
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Stanislav V. Smyshlyaev
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Salz, Rich
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Ian Goldberg
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Chelsea Komlo
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Jeff Burdges
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Christopher Wood
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Christopher Wood
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Christopher Wood
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Jeff Burdges
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Scott Hendrickson
- Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-… Watson Ladd