[CFRG] Request for feedback on Hierarchical Deterministic Keys

Sander Dijkhuis <mail@sanderdijkhuis.nl> Sat, 07 December 2024 19:28 UTC

Return-Path: <mail@sanderdijkhuis.nl>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7915C14F68F for <cfrg@ietfa.amsl.com>; Sat, 7 Dec 2024 11:28:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sanderdijkhuis.nl
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3x3G1WCoNIZS for <cfrg@ietfa.amsl.com>; Sat, 7 Dec 2024 11:28:27 -0800 (PST)
Received: from mr85p00im-hyfv06011401.me.com (mr85p00im-hyfv06011401.me.com [17.58.23.191]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8FC36C14F6BC for <cfrg@irtf.org>; Sat, 7 Dec 2024 11:28:27 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sanderdijkhuis.nl; s=sig1; t=1733599707; bh=gcLIKRIPMaCaS2Wp/Hv9TEcORLJqz+toShjQM3/7biw=; h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type: x-icloud-hme; b=rckOdagAMF4vMFWEq7Cy2C8Nki2o84eAAkqeZRhscmSZVk/D4HtnAN8B/OkI24KEU qxJFvDFDWTYuXGMhu6YBUlCXUotz7/D7BsLojKHpoKGAQ+ScSPh5KX4jxlVFj9KZBC Draf3DoJS15GLpLosKvRRjm6kCQRpPVDLQZe9RvC29DB8+0sEg1PyXhEaoeB1gtrky 1YOJG/vIN2/75wZubgaTnvNIzSIQH1qEbSzcZedpYD/NBEI5K0WIgFNt+Qi4lMwd/S 8UxMToKDowXsVdl+8y8iSg44sTsiPQmMwMWFq4zJL5SvjaruEqFlJZPV+OE79wYsIH rASS9q19UyBYg==
Received: from [10.101.2.142] (mr38p00im-dlb-asmtp-mailmevip.me.com [17.57.152.18]) by mr85p00im-hyfv06011401.me.com (Postfix) with ESMTPSA id 4F91A357ADED for <cfrg@irtf.org>; Sat, 7 Dec 2024 19:28:25 +0000 (UTC)
Message-ID: <c5ad20a8-2cf7-4359-95a0-e6c6c69fb9e0@sanderdijkhuis.nl>
Date: Sat, 07 Dec 2024 20:28:21 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: cfrg@irtf.org
From: Sander Dijkhuis <mail@sanderdijkhuis.nl>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-Proofpoint-GUID: AN7NFVhRnpbOhvigiTGd7rWjn4_iaotk
X-Proofpoint-ORIG-GUID: AN7NFVhRnpbOhvigiTGd7rWjn4_iaotk
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1057,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2024-12-07_02,2024-12-06_01,2024-11-22_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 clxscore=1030 spamscore=0 phishscore=0 mlxscore=0 malwarescore=0 suspectscore=0 bulkscore=0 adultscore=0 mlxlogscore=706 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2308100000 definitions=main-2412070164
Message-ID-Hash: FCSDFPD37WPZ5ASLS74F4KWJOJ3XPM6X
X-Message-ID-Hash: FCSDFPD37WPZ5ASLS74F4KWJOJ3XPM6X
X-MailFrom: mail@sanderdijkhuis.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Request for feedback on Hierarchical Deterministic Keys
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/gpSTjXtM3YfCvtXmWpDxo_vcggc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

Hi CFRG,

I would like to request your feedback on an Internet-Draft:

Hierarchical Deterministic Keys (HDKeys)
draft-dijkhuis-cfrg-hdkeys-01
https://datatracker.ietf.org/doc/draft-dijkhuis-cfrg-hdkeys/01/

The spec results from an informal collaboration among participants in 
large scale pilots for the EU Digital Identity, incorporating ideas from 
BIP-32 and ARKG. We aim to standardise the algorithm for use with common 
wallet protocols and widely available cryptographic mechanisms for 
EU-governed applications. The CFRG seems the best place to do so.

In the EU Digital Identity context, providers issue digital documents 
with proof-of-possession public keys bound to a secure cryptographic 
devices, preventing cloning and unauthorised use. To ensure 
unlinkability across relying parties, they should never see the same 
public key. HDKeys allows re-issuance of documents with unique public 
keys derived from a single device-bound key. The algorithm combines 
deterministic key derivation and blinded proof of possession. It can be 
distributed in such a way that enables binding to regular ECDSA or ECDH 
devices.

HDKeys can be applied with current certified provider hardware and 
wallet secure cryptographic devices. Therefore it enables a transitory 
solution for EU Digital Identity Wallet until more efficient or 
effective alternatives are widely available. Promising alternatives 
include multi-message signature schemes such as BBS, which requires 
development and certification of HSMs, and ZKP circuits for common 
digital document proofs, which are under development. EU Member States 
need a transitory solution to meet the December 2026 launch deadline 
without unnecessarily compromising privacy. For more details, see 
§4.4.4.2 of:

ETSI TR 119 476 v1.2.1
https://www.etsi.org/deliver/etsi_tr/119400_119499/119476/01.02.01_60/tr_119476v010201p.pdf

The European Commission considers referencing HDKeys in the context of 
two wallet architecture topics:

Topic A: Privacy risks and mitigations
https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/issues/327

Topic C: Wallet Unit Attestation (WUA) and key attestation
https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/issues/333

To enable adoption for EU Digital Identity, HDKeys needs further review 
and standardisation. I look forward to hearing your first feedback 
regarding the approach, initial draft, and feasibility to adopt.

Best regards,

Sander