[CFRG] Re: KEM combiners design team output
Neil Madden <neil.e.madden@gmail.com> Mon, 15 July 2024 10:23 UTC
Return-Path: <neil.e.madden@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D803C151078 for <cfrg@ietfa.amsl.com>; Mon, 15 Jul 2024 03:23:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wfl_BkgvLL7n for <cfrg@ietfa.amsl.com>; Mon, 15 Jul 2024 03:23:02 -0700 (PDT)
Received: from mail-wm1-x32c.google.com (mail-wm1-x32c.google.com [IPv6:2a00:1450:4864:20::32c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 92F05C15106B for <cfrg@irtf.org>; Mon, 15 Jul 2024 03:23:02 -0700 (PDT)
Received: by mail-wm1-x32c.google.com with SMTP id 5b1f17b1804b1-42666a5d33dso3324085e9.0 for <cfrg@irtf.org>; Mon, 15 Jul 2024 03:23:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1721038981; x=1721643781; darn=irtf.org; h=to:in-reply-to:cc:references:message-id:date:subject:mime-version :content-transfer-encoding:from:from:to:cc:subject:date:message-id :reply-to; bh=5+GasVJO5fDRwhUCR2ip3X+5/ho7RJEyPvVMb1DYDOQ=; b=AbIzaNHcbBW4UaX/pI2pPtv0+DhivA7kVx4U5SCLDz5f+v4DjTiWV7IB51YcIovj1W s6zNqb5LH8IGxtlhcc/k1FkIQYAejX+7fTrZJzbK/MLW9qluwSflnSVPpf7oOAxkgZ0b Rank6C+k/fBWGMidoyzyx94hb7AnsPygWlp8PFuLr6LWxcfjg87Qjuv+WnbOGfNkzuk1 zJ0Z0tHgsLSIK2REfwQ5vzPwMkZ8CBgdORzDSIGVzq29QHyOsVgBaQTWTvv67Hj9BcEJ e5MCePmWQbH74IEAeUOq/oPbDGtLtB/tqFixsykJd3K5fP+TgH2I4AOJYzVyn6ru7B5y iJVA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1721038981; x=1721643781; h=to:in-reply-to:cc:references:message-id:date:subject:mime-version :content-transfer-encoding:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=5+GasVJO5fDRwhUCR2ip3X+5/ho7RJEyPvVMb1DYDOQ=; b=VFY6fsMvnsc+gbZUBu84ekSEoudQAWJndq/r9j2sysmyhpguNfoOPjRRnBB4S9Sr+o K0ZDeamOOYHobVl5JmdAY+t5BPwvt/FdjIwn7sx2RiB2bkvKb+61VVvGJUS6hycntOQv AVtB1XheXYUUrtAN0dq2qC0cPUI4YukmUtq96B7v/yliseIsRCesGDOEEMBamhIv8hLG cr4x1ExLDflRKeyrXoNQ0P2XBMTGzQtts7f7S/CzimJcaMPx6BLa85KR9h9irNTWkEYa wE2lGhl96tgWlw4ZdgA/QNmgoIraiEDuk5lDphYLmZ6yphWbc5OBs6HT8mkNjpIr1H/u /lxQ==
X-Forwarded-Encrypted: i=1; AJvYcCW9eBh/CxzC1Yzh+K++nsWL5cJCR7rWLsLKHd+w4MMHFi0oW9wBblZteEH5yHRCb2pE45ARMO+xGIY5PZe8
X-Gm-Message-State: AOJu0YxFRlC+U1VjCPfUEiDShN0f6nOcG2ICSlHymYypbIf9DyXEpELH kYrfUJfvqryyj8+UnKfWLux6FAcYo6I0XplhhYFGJTDiH83g9HsR
X-Google-Smtp-Source: AGHT+IH0XJH1IDMkgor6lyWfBU1No5x0OPMhVB4hYrifZEWdwQmbMhcgjtjEk6Yrjy+f4nGQlFrRWg==
X-Received: by 2002:a05:600c:1c24:b0:425:7ac6:96f9 with SMTP id 5b1f17b1804b1-427982db3d0mr64138075e9.0.1721038980350; Mon, 15 Jul 2024 03:23:00 -0700 (PDT)
Received: from smtpclient.apple (183.75.159.143.dyn.plus.net. [143.159.75.183]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-426725597bdsm140854585e9.0.2024.07.15.03.22.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 15 Jul 2024 03:22:59 -0700 (PDT)
From: Neil Madden <neil.e.madden@gmail.com>
X-Google-Original-From: Neil Madden <Neil.E.Madden@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail-3873122A-16A6-4BAA-9ED7-3841C4146806"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (1.0)
Date: Mon, 15 Jul 2024 11:22:48 +0100
Message-Id: <5A2A5B49-9164-49D8-A872-AAE19A3B0938@gmail.com>
References: <CAMjbhoWSOeTaLx0GvgFsNw2cOk7UCQSj4G3QxCfeTjf_V=OV5Q@mail.gmail.com>
In-Reply-To: <CAMjbhoWSOeTaLx0GvgFsNw2cOk7UCQSj4G3QxCfeTjf_V=OV5Q@mail.gmail.com>
To: Bas Westerbaan <bas@cloudflare.com>
X-Mailer: iPhone Mail (21F90)
Message-ID-Hash: APNOUPC47HPOZHDYXEDS3VMT5QN3AZUT
X-Message-ID-Hash: APNOUPC47HPOZHDYXEDS3VMT5QN3AZUT
X-MailFrom: neil.e.madden@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: cfrg@irtf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [CFRG] Re: KEM combiners design team output
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/l0Y00X_wwjfDq_wrhtsCHm8W3so>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
> On 15 Jul 2024, at 10:49, Bas Westerbaan <bas@cloudflare.com> wrote: > >> Regarding security properties, I am particularly interested in authenticated KEMs. Obviously most of the discussion around PQ KEMs is about IND-CCA, but almost all of my use-cases want data origin authentication. We don’t seem to have any good candidates for PQ AKEMs, > > We do have PQ AKEMs that aren't that bad today: combine any PQ KEM and PQ signature scheme. If you take say ML-KEM-512 and ML-DSA-44 for this (the weakest parameters), that is 768 + 2420 = 3188 bytes. When base64-encoded that already blows the 4kB cookie limit in browsers. I would say that is bad, compared to 32 bytes for an X25519 AKEM: a 2 orders of magnitude size increase is quite a hard sell! > That will do for HPKE. Signal requires a bit more than an HPKE AKEM: they would also like to have deniability, which you don't get when using a signature scheme instead of DH for authentication. IMO repudiation should be the default (eg https://blog.cryptographyengineering.com/2020/11/16/ok-google-please-publish-your-dkim-secret-keys/) Let’s not entrench cryptographic schemes that cause further unintended consequences. Besides, signatures are just the wrong tool for the job for authentication: as evidenced by the amount of context you have to include in a signature to prevent misuse (timestamps, nonces, user info, session ids, transcript hashes, etc), precisely because signatures are equally valid for all parties at all times. Many protocols IMO would be immeasurably improved by de-Fiat-Shamir-ing them back into identification protocols (looking at you, FIDO). — Neil
- [CFRG] KEM combiners design team output Stephen Farrell
- [CFRG] Re: KEM combiners design team output Russ Housley
- [CFRG] Re: KEM combiners design team output Neil Madden
- [CFRG] Re: KEM combiners design team output Jack Grigg
- [CFRG] Re: [EXTERNAL] KEM combiners design team o… Mike Ounsworth
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Mike Ounsworth
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Mike Ounsworth
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Andreas Hülsing
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Deirdre Connolly
- [CFRG] Re: KEM combiners design team output Ilari Liusvaara
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Andreas Hülsing
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Simon Josefsson
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Ilari Liusvaara
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Bas Westerbaan
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Mike Ounsworth
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Ilari Liusvaara
- [CFRG] Re: KEM combiners design team output Stephen Farrell
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Simon Josefsson
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Ilari Liusvaara
- [CFRG] Re: [EXTERNAL] Re: KEM combiners design te… Simon Josefsson
- [CFRG] Re: KEM combiners design team output D. J. Bernstein
- [CFRG] Re: KEM combiners design team output Bas Westerbaan
- [CFRG] Re: KEM combiners design team output Neil Madden
- [CFRG] Re: KEM combiners design team output Neil Madden