[Cfrg] seeking feedback on draft-irtf-cfrg-vrf

Sharon Goldberg <goldbe@cs.bu.edu> Mon, 02 July 2018 17:14 UTC

Return-Path: <sharon.goldbe@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02D98130E54 for <cfrg@ietfa.amsl.com>; Mon, 2 Jul 2018 10:14:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.398
X-Spam-Level:
X-Spam-Status: No, score=-1.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AQEk57z_ZpRX for <cfrg@ietfa.amsl.com>; Mon, 2 Jul 2018 10:14:02 -0700 (PDT)
Received: from mail-it0-x22a.google.com (mail-it0-x22a.google.com [IPv6:2607:f8b0:4001:c0b::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4EEF1127598 for <cfrg@irtf.org>; Mon, 2 Jul 2018 10:14:02 -0700 (PDT)
Received: by mail-it0-x22a.google.com with SMTP id 16-v6so13096113itl.5 for <cfrg@irtf.org>; Mon, 02 Jul 2018 10:14:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:from:date:message-id:subject:to:cc; bh=dahHvHsFnI12QytQB9HlFGkP/OZiqG4ffCIMWRy0TEk=; b=oqSx559zueC4tP8Kc0ub92VuIpMSwcjzGzTq9vS+HdBk7kKqLakFhD15K1tlkzO6Yz pmaWH0ckuN8vvdQoApEy5ZSHeTFparP8lTpfwqXMdOHMb8j4Pjjg9QCbFRZJlSYW+2Ky SRRH/0LJAzLNSZVVJqLRovFbNPrL6zrjAKGrKC55nqtNn7eVSviPxRDjXx8GtaVcAqCH Or2Omk+W3nVCdMwSDT8CPSZzf1vlE+S+SVrYm9FpBt73zp3mZZhIs7HpI6dLhhrGPyn8 KpmCV50NNx9MybhRqW8E9U6/O6WnLXUTNXHnvK1WvV+kI7O8kCpwFZ2TWvT9HNwEJwVl ULZA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:from:date:message-id:subject :to:cc; bh=dahHvHsFnI12QytQB9HlFGkP/OZiqG4ffCIMWRy0TEk=; b=gpBCMGg7/w8rQZ2WT06s/EstiRaJRFuVu8W+PdVXG60CMvfErPt5N6J+EhLSErtdBo +6g6FSekAsNd0iybMFWUtvTdScFdYhdDKlwvZCpWc9QQkfeVyYGmkUhspMxau8duXe0i WnGYLO5sRq8StlOoKvCvlh9Qif3OQPUAQp78l9GBk9swj5bG35ntk43hrN3aztfPPVYk iVzN+y+nYxUGHKXCKb+jDF8SWCfUTxjnIMpnG+YzaWGfyiM6q+yXNVblwIAPcuSesXG5 NkOrnzIxPnP0epOj7KqDWqfuWp+4zj65pFiKJX2wdyRAJMS2Sqo6bXr32uR1/nn4+2sp 630Q==
X-Gm-Message-State: APt69E0In2QoSHNeOVRmra/VBcgUngJZDf9R03ehpAs+tqoPOkicIcTB /y4waWcUazua/9963NDuQOeJ3Y/SPx/nP7Rpa0zImg==
X-Google-Smtp-Source: AAOMgpcxZkT881UXCmhEeYjleXvw+sLoMbHEbAeizwQ86GpJyezXPD+7FspW0Z6Yvt0wLWtEyptzPRxIXL/l+FtSPek=
X-Received: by 2002:a24:946:: with SMTP id 67-v6mr4862462itm.85.1530551641469; Mon, 02 Jul 2018 10:14:01 -0700 (PDT)
MIME-Version: 1.0
Sender: sharon.goldbe@gmail.com
Received: by 2002:a6b:9404:0:0:0:0:0 with HTTP; Mon, 2 Jul 2018 10:13:20 -0700 (PDT)
From: Sharon Goldberg <goldbe@cs.bu.edu>
Date: Mon, 02 Jul 2018 13:13:20 -0400
X-Google-Sender-Auth: H5sxchjphS1USZOD4-nPvssPnhM
Message-ID: <CAJHGrrTU8eM1cT0B6Stkh4sj1HoY7wiDVSyFr7ZHnXxjKdmy_g@mail.gmail.com>
To: cfrg@irtf.org, Leonid Reyzin <reyzin@cs.bu.edu>
Cc: jan@ns1.com, Dimitrios Papadopoulos <dipapado@cse.ust.hk>
Content-Type: multipart/alternative; boundary="000000000000e678320570075220"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/vLaqYcY-i0uTSQZqDshArj6e4Rw>
Subject: [Cfrg] seeking feedback on draft-irtf-cfrg-vrf
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Jul 2018 17:14:04 -0000

Dear CFRG,

We have a new version of draft-irtf-cfrg-vrf, specifying Verifiable Random
Functions (VRFs).

https://datatracker.ietf.org/doc/draft-irtf-cfrg-vrf/

This revision updates the elliptic curve VRF (ECVRF).  Key changes include

1) Add a new Curve25519 ciphersuite that uses elligator2 for hashing
2) Add domain separation for hashing
3) Make nonce selection deterministic

Here's a slide deck summarizing the update, that we will present at
IETF102.  We also have very specific places where we are seeking feedback
from the RG, which are summarized in the slides. Please have a look.

http://www.cs.bu.edu/~goldbe/papers/VRF_ietf_02.pdf

Thanks,
Sharon Goldberg + Leo Reyzin
Boston University

-- 
Sharon Goldberg
Computer Science, Boston University
http://www.cs.bu.edu/~goldbe