Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-signatures-02.txt

Christopher Wood <caw@heapingbits.net> Mon, 30 August 2021 13:31 UTC

Return-Path: <caw@heapingbits.net>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 23F0B3A11D6 for <cfrg@ietfa.amsl.com>; Mon, 30 Aug 2021 06:31:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=heapingbits.net header.b=HoCRxi05; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=Zw+DJQ8C
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PoBhMscNra8j for <cfrg@ietfa.amsl.com>; Mon, 30 Aug 2021 06:31:06 -0700 (PDT)
Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BDADC3A1215 for <cfrg@irtf.org>; Mon, 30 Aug 2021 06:30:46 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id 95C083200977 for <cfrg@irtf.org>; Mon, 30 Aug 2021 09:30:43 -0400 (EDT)
Received: from imap41 ([10.202.2.91]) by compute5.internal (MEProxy); Mon, 30 Aug 2021 09:30:43 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=heapingbits.net; h=mime-version:message-id:in-reply-to:references:date:from:to :subject:content-type:content-transfer-encoding; s=fm2; bh=0FTwD tUTEjCqVJb/pZg2apyZdCHxnzOUaZjR/31JFAk=; b=HoCRxi05WqY0JjO2PhGTO neUHczKKVPhMgzJfVwD5o7s9P2l8q4ecfeRin8yWDWUu9pjEomyKmL0P0Y2kX/SC VTuMliqGwGXaOoHMGE8cndmqjL49Sz+0BlnUJkRHJryEEFhZ6r5hK9BIHsoz8ydS HR94BGl7K8pVSqYwB5CaI0mDQeDPizbTkYvx0AKo3UVRBBoYWtpfY2Jzv9PmzDS3 GgMIMn9VbX8DEO8wn16TLJE5sfGij61zUwoAih5sxmZLN66S6bNn2BoIjW7+7Rjw k8CgsnNf9N28FqSw9xLY6GjaNkjsr9k7qheNGU6ZIXmdf2L52efMtA7f16/t+U1A w==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm3; bh=0FTwDtUTEjCqVJb/pZg2apyZdCHxnzOUaZjR/31JF Ak=; b=Zw+DJQ8CJSz1Bryg5RuRqZdub5fuCRlmFG4FBFVRvb+/RYgUPTSD6Mdsg ipWx+yuItmOhysjgseiqrKNvlcWdqBb+CXx6uF+bdeRdu8/4zCjiUOYcnPfmUWLY b/cdlSmCMyWmBudzJHxQcTuazIxHoxPnOd6F7Hnm13aD3C9UniPKgypwrNvnyHT+ Guuhby+hMWvUStS5+zdHiyFdlH6xTc43Yv6wk3cqqrw2UKFJ6DB5qk3imEvX9IUJ vXshMxhymqPJFTuCG3gYdrDknxrtNzrooFU/XQ2sfk3CjPbj27F4W/YEruXkwV4o PzWQNGcV/OX5ACGr8QLmXe2KzpNuQ==
X-ME-Sender: <xms:g90sYUODOXBeKEE3LF9iFfdDgEybhZ8vCKmGHkIdNKWbGtkddH2nRQ> <xme:g90sYa8xJdjW7ZCNG4HkTWtnOuelZAFMiYsAHFTpTRZ6Iwk6_DggD6yNRtcSFuNCg ea6CZk64gyInhRMpn8>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddrudduledgieeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefofgggkfgjfhffhffvufgtgfesth hqredtreerjeenucfhrhhomhepfdevhhhrihhsthhophhhvghrucghohhougdfuceotggr fieshhgvrghpihhnghgsihhtshdrnhgvtheqnecuggftrfgrthhtvghrnhepkeeuleekfe ejgffffefhudduudfhjedtueehheetfeehvdelvefhgfeijefgudfhnecuffhomhgrihhn pehirhhtfhdrohhrghenucevlhhushhtvghrufhiiigvpedunecurfgrrhgrmhepmhgrih hlfhhrohhmpegtrgifsehhvggrphhinhhgsghithhsrdhnvght
X-ME-Proxy: <xmx:g90sYbS5LfmouN8-F-v9tknjpbNEKUtQHu-FOqa8k9jCwSAB7lK2tQ> <xmx:g90sYcs1I7yrUEDhUCaWCKhlWumS69CGZzX8Y7JWe1-f7Cx6ACNqZw> <xmx:g90sYccNupq6sujt1Nn97NPLvntaMGy35rLt9RjMpQbSOfdD6a9DGg> <xmx:g90sYWrz71Gsp9PGFnWZYo3BjiWAcQCp1DQmKAq_tPa0fNec2o7lhA>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 101153C0EB8; Mon, 30 Aug 2021 09:30:43 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-1125-g685cec594c-fm-20210825.001-g685cec59
Mime-Version: 1.0
Message-Id: <ce8921b3-c69d-41b5-80f0-a8060f62c854@www.fastmail.com>
In-Reply-To: <6616faf7-f4b4-4b5c-9f60-1020f714809b@www.fastmail.com>
References: <162791899203.1107.7194332652638927873@ietfa.amsl.com> <0aab06f7-7beb-4ccc-ab8b-3a09d4d3c8fc@www.fastmail.com> <20210802172912.GK6513@yoink.cs.uwaterloo.ca> <a154ab88-7410-4346-8f7a-110f8e9a5591@www.fastmail.com> <CAMr0u6=QrGQt5UPzbwEs+zmLuzgB+KC2OJ0R+C0Md0EkXWWFmw@mail.gmail.com> <b4ab82f15439491bb265ba6d64d60185@uwaterloo.ca> <0EBB4DB4-E732-4188-B535-A4A0D664355A@gnunet.org> <6616faf7-f4b4-4b5c-9f60-1020f714809b@www.fastmail.com>
Date: Mon, 30 Aug 2021 06:30:21 -0700
From: Christopher Wood <caw@heapingbits.net>
To: cfrg@irtf.org
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/de2eVVdI6iir0xKuQBZ2QvlMnNM>
Subject: Re: [CFRG] I-D Action: draft-irtf-cfrg-rsa-blind-signatures-02.txt
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Aug 2021 13:31:12 -0000

Oops -- I meant to -list to keep the thread focused. Sorry about that!

On Mon, Aug 30, 2021, at 6:29 AM, Christopher Wood wrote:
> (-list)
> 
> On Mon, Aug 30, 2021, at 3:17 AM, Jeff Burdges wrote:
> > 
> > I wonder if the underlying RSA scheme should be called roughly RSA-PDH 
> > or something, where PHD = partial domain hash, because the security 
> > does not come via the same argument as in PSS.
> 
> Can you please elaborate on this? PSS _is_ the encoding scheme used in 
> this draft, so I don't see why we'd change the name of the encoding 
> scheme here. 
> 
> Thanks,
> Chris
> 
> > > On 30 Aug 2021, at 05:00, Chelsea Komlo <ckomlo@uwaterloo.ca> wrote:
> > > Section 5.1.1
> > > 
> > > "The blinding factor r must be randomly chosen from a uniform distribution. This is typically done via rejection sampling."
> > > 
> > > Is this not implied by the function random_integer_uniform?
> > 
> > In principle yes, but their desire to use PSS as a “partial domain 
> > hash” worried some of us that people would reuse the PSS “hasher” for 
> > the blinding factor, which instantly breaks the anonymity.  We’ve 
> > enough cases in elliptic curves where being full domain does not mater, 
> > ala ECDSA, that people do fuck this up in blind RSA.  I suggested 
> > finding more specific language for this reason.  
> > 
> > Jeff
> > 
> > 
> > _______________________________________________
> > CFRG mailing list
> > CFRG@irtf.org
> > https://www.irtf.org/mailman/listinfo/cfrg
> > 
>