Re: [COSE] [jose] Fwd: New Version Notification for draft-reddy-cose-jose-pqc-kem-00.txt

tirumal reddy <kondtir@gmail.com> Wed, 06 March 2024 06:15 UTC

Return-Path: <kondtir@gmail.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5621AC15107A; Tue, 5 Mar 2024 22:15:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.104
X-Spam-Level:
X-Spam-Status: No, score=-7.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f6fEpVblKady; Tue, 5 Mar 2024 22:15:51 -0800 (PST)
Received: from mail-ed1-x535.google.com (mail-ed1-x535.google.com [IPv6:2a00:1450:4864:20::535]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7ADAFC14F5F7; Tue, 5 Mar 2024 22:15:46 -0800 (PST)
Received: by mail-ed1-x535.google.com with SMTP id 4fb4d7f45d1cf-565c4d0fa48so2215730a12.1; Tue, 05 Mar 2024 22:15:46 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1709705740; x=1710310540; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=smuIwkoBt55PHHywALB5rLeIIVawCNMG7OOubQxr3ZY=; b=TZD9wbV+pl5n07IzVLP/+zUzg47n3jYm2aF1B9iX7/HYYQMNRf37jTI6sYBx/UeKvy xQyEQFx9//zn0Z5U9MGRyr61h99qSCB+U+KPAD15CUNK8Ux3k8OLm08T08jzPUcY14Ce tMWw3NJO8rANV5MoLKux9fg3lO+Fhs+/yoThdxsi4AIGbZBSWSbipSKkBcM04wzNMv5d YH4bP30Rdw+MTSZACXot5fM34erMgV81bYCiKIFBzsTuGIV5Qa9ZEmGei03bgUbJv493 KZWcleKEnuAFzrDoGOdDp9dpazp8XOIFwbwzx2/bgNo1HjIM884mFOlkMs4KXZ5y8UCi Jx2g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1709705740; x=1710310540; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=smuIwkoBt55PHHywALB5rLeIIVawCNMG7OOubQxr3ZY=; b=C3bLgg9sj/Oq5cU2fThvYc0E2SLa/spO4WABkQhdDkdQ5/Eavgl5FhExRTka1jCgaQ 0BOFBcq1twsQ4fCZkNjsHiAN9/vopzNn98hCfe8fQYlR82DeBiDKPr0+e96hHOwn8TFK UAovgXbiArsccx8U/h2x9X4PtHQo+HjWP00nr94Ce7RGKal42dRwxy6DQnuWOBQvqk/q EKPD5Jl77iF3ntt3ddPS+nTzWl1XOWozZDVKA4sbc8tBNyaBQP5pg52k3pcGZEjV0ar2 uTR3k/d6pfV3TEDCGZdlb4Y9XU5TW+mQbbKwc5JR6wijgnEiLvIAWxiDvsUWQ/X8OvSd sXyw==
X-Forwarded-Encrypted: i=1; AJvYcCUVzKOSDrTd2vYbvP/MvjPfYRCPgv7BhIUA4G5xNmlfptcPNVuFLqzpG4E+QEVtJU+zEGhJrnBhhHo4bJ8ZhE6WerOvH6dmrfrHpFKA
X-Gm-Message-State: AOJu0YzsqCnuP0zEi+Az6nCsS+emFUJIVl7eqex9P1/yG6sxdx6W5cD2 EwCbUKeXSZQ5WaSBE0S0s4+3ouRwlqt0MtvZDn5hgyEbtfrLxH5XEqRIGOsgQy8cTEqa6GAeI+2 NJGGYOr9ke6m9kmGFK1UI5piCpcI=
X-Google-Smtp-Source: AGHT+IGp1PDHn2ubvjFTAh1OcCLoMFud+eS+c4/kPeJIbJ/LZGBXi1SEBObPGU2LcyWzpye+ahdgMjAQx55W0zWNnCs=
X-Received: by 2002:aa7:c1c7:0:b0:567:ef00:ca64 with SMTP id d7-20020aa7c1c7000000b00567ef00ca64mr319585edp.3.1709705739650; Tue, 05 Mar 2024 22:15:39 -0800 (PST)
MIME-Version: 1.0
References: <170944215832.65165.15558599263256086018@ietfa.amsl.com> <CAFpG3gdGiw2wap8C1H+AOWvEn1ewSjmtBmghKKAvNBmXnDmoYg@mail.gmail.com> <CAN8C-_KZifohssn3WoZa6Qn3QMeh0YMya6c8RGa1ZieWgRY9=A@mail.gmail.com> <CAFWvErUpD+p5enboksM1QiPq1ixJnRMi2NM4oyu+_8XQo_f++Q@mail.gmail.com>
In-Reply-To: <CAFWvErUpD+p5enboksM1QiPq1ixJnRMi2NM4oyu+_8XQo_f++Q@mail.gmail.com>
From: tirumal reddy <kondtir@gmail.com>
Date: Wed, 06 Mar 2024 11:45:03 +0530
Message-ID: <CAFpG3geYihGp_YDaqB1pP+BXjSUUXit-HPVVN0wxB9PokOXywQ@mail.gmail.com>
To: AJITOMI Daisuke <ajitomi@gmail.com>
Cc: Orie Steele <orie@transmute.industries>, cose <cose@ietf.org>, JOSE WG <jose@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000484fe00612f7e316"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/6SiLARZ1HeZTysQXdPkxQhxW-8E>
Subject: Re: [COSE] [jose] Fwd: New Version Notification for draft-reddy-cose-jose-pqc-kem-00.txt
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Mar 2024 06:15:52 -0000

On Tue, 5 Mar 2024 at 20:12, AJITOMI Daisuke <ajitomi@gmail.com> wrote:

> > I think we should use HPKE until there is reason not to use it.
>
> I agree.
>
> Regarding ML-KEM, I was thinking that we should add X-Wing as a PQ/T
> Hybrid KEM to the list of COSE-HPKE ciphersuites at first.
>
> X-Wing: general-purpose hybrid post-quantum KEM
> https://datatracker.ietf.org/doc/draft-connolly-cfrg-xwing-kem/
>

X-wing is specific to hybrid schemes and it is back-ward compatible with
X25519Kyber768Draft00. The COSE and JOSE HPKE specifications can use the
above hybrid scheme which is already registered in HPKE IANA registry.

-Tiru


>
>
> Daisuke
>
>
>
> https://datatracker.ietf.org/doc/draft-connolly-cfrg-xwing-kem/
>
> 2024年3月5日(火) 22:32 Orie Steele <orie@transmute.industries>:
>
>> Draft looks very familiar after have spent so much time with HPKE.
>>
>> And it would be nice to have at least one pq encryption suite on track
>> for standardization.
>>
>> Having different direct mode alg values for ML-KEM and HPKE that are both
>> basically telling you to look an enc... Is wasting registry space.
>>
>> alg: dir, is sufficient.
>>
>> The documents that register the new enc modes can explain why.
>>
>> I think it would be better to see ML-KEM suites in HPKE, instead of
>> seeing duplicates.
>>
>> There will also be different security issues, without the HPKE context
>> and key commiting, etc...
>>
>> There will be worse interop with 2 ways to do the same things.
>>
>> With hydrids on the horizon... it's a mistake to register hydrids
>> twice... Once for HPKE and once for standalone.
>>
>> I think we should use HPKE until there is reason not to use it.
>>
>> Is this draft motivated by implementers who could not use HPKE?
>>
>> Are there critical use cases that multiple vendors need to support that
>> only work without using HPKE?
>>
>> OS
>>
>> On Tue, Mar 5, 2024, 5:34 AM tirumal reddy <kondtir@gmail.com> wrote:
>>
>>> We have published a new draft
>>> https://www.ietf.org/archive/id/draft-reddy-cose-jose-pqc-kem-00.html,
>>> that describes the conventions for using Post-Quantum Key Encapsulation
>>> Mechanisms (PQ-KEMs) within JOSE and COSE.  Although this mechanism could
>>> be used with any PQ-KEM, this document focuses on Module-Lattice-based Key
>>> Encapsulation Mechanisms (ML-KEMs).
>>>
>>> Comments and Suggestions are welcome.
>>>
>>> -Tiru
>>>
>>> ---------- Forwarded message ---------
>>> From: <internet-drafts@ietf.org>
>>> Date: Sun, 3 Mar 2024 at 10:32
>>> Subject: New Version Notification for
>>> draft-reddy-cose-jose-pqc-kem-00.txt
>>> To: Tirumaleswar Reddy.K <kondtir@gmail.com>, Aritra Banerjee <
>>> aritra.banerjee@nokia.com>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>,
>>> Hannes Tschofenig <hannes.tschofenig@gmx.net>
>>>
>>>
>>> A new version of Internet-Draft draft-reddy-cose-jose-pqc-kem-00.txt has
>>> been
>>> successfully submitted by Tirumaleswar Reddy and posted to the
>>> IETF repository.
>>>
>>> Name:     draft-reddy-cose-jose-pqc-kem
>>> Revision: 00
>>> Title:    Post-Quantum Key Encapsulation Mechanisms (PQ KEMs) for JOSE
>>> and COSE
>>> Date:     2024-03-03
>>> Group:    Individual Submission
>>> Pages:    16
>>> URL:
>>> https://www.ietf.org/archive/id/draft-reddy-cose-jose-pqc-kem-00.txt
>>> Status:
>>> https://datatracker.ietf.org/doc/draft-reddy-cose-jose-pqc-kem/
>>> HTML:
>>> https://www.ietf.org/archive/id/draft-reddy-cose-jose-pqc-kem-00.html
>>> HTMLized:
>>> https://datatracker.ietf.org/doc/html/draft-reddy-cose-jose-pqc-kem
>>>
>>>
>>> Abstract:
>>>
>>>    This document describes the conventions for using Post-Quantum Key
>>>    Encapsulation Mechanisms (PQ-KEMs) within JOSE and COSE.
>>>
>>> About This Document
>>>
>>>    This note is to be removed before publishing as an RFC.
>>>
>>>    Status information for this document may be found at
>>>    https://datatracker.ietf.org/doc/draft-reddy-cose-jose-pqc/.
>>>
>>>    Discussion of this document takes place on the cose Working Group
>>>    mailing list (mailto:cose@ietf.org), which is archived at
>>>    https://mailarchive.ietf.org/arch/browse/cose/.  Subscribe at
>>>    https://www.ietf.org/mailman/listinfo/cose/.
>>>
>>>
>>>
>>> The IETF Secretariat
>>>
>>>
>>> _______________________________________________
>>> jose mailing list
>>> jose@ietf.org
>>> https://www.ietf.org/mailman/listinfo/jose
>>>
>> _______________________________________________
>> COSE mailing list
>> COSE@ietf.org
>> https://www.ietf.org/mailman/listinfo/cose
>>
>