Re: [COSE] COSE HPKE Public Key Format Consensus Call

AJITOMI Daisuke <ajitomi@gmail.com> Thu, 22 September 2022 22:00 UTC

Return-Path: <ajitomi@gmail.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C0870C152576 for <cose@ietfa.amsl.com>; Thu, 22 Sep 2022 15:00:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vy7iz7nmvH26 for <cose@ietfa.amsl.com>; Thu, 22 Sep 2022 14:59:57 -0700 (PDT)
Received: from mail-oi1-x234.google.com (mail-oi1-x234.google.com [IPv6:2607:f8b0:4864:20::234]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 08095C14CF0A for <cose@ietf.org>; Thu, 22 Sep 2022 14:59:56 -0700 (PDT)
Received: by mail-oi1-x234.google.com with SMTP id o184so14084444oif.13 for <cose@ietf.org>; Thu, 22 Sep 2022 14:59:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date; bh=PiWCHyHFOeKymGCdHvtk82uxwFaj+HchChjTqaAoP0Y=; b=dG0Zzzx4QJmuxfIxovXU7TlsNVEpLSmh/lEgrLq4yIG+iW1yq9sk3hHT8K2qLvF6I9 crpbsCPuLfYvLD7N0IZVVgJlGiJ6TMm6gZYO24XJBhRLnB/QERsXs5+UNsEWB8lSEzep ajKRrbkQ1WzzFBzHtewmAantP8q9gkzIp6bu+7fEXYmAX2KUSvo1ZIU8ClBds8QK03KC JxzstUlrp7GFJdrnJ2zkoUpzrARu+F8D4iniApOSBuzLa2VweGfIOxX69A30anDcUgi6 1nQ0PI74FZokNuAi0LWwAyw6A69EG2zfIax70m9SobqXY9JyDqsrIVFmkehpRrN1a1AA +4JQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date; bh=PiWCHyHFOeKymGCdHvtk82uxwFaj+HchChjTqaAoP0Y=; b=kV96bocZjSj6OBR4lwl3vYoCKwTagcAbVNueUxqcRG7hx94vUmph6FTBZjg/fYMP3j EyU2VfTByBlDPBZa8xTWHXtL8lU9dvm3TmEfA+1AFQUN0PyDpJypnfhI2Ntsbw7xrge6 sPwET9e6ooHBcdctUv6ZEkyOyJ0hXQypgftc9xtBfxLPfk9geuMrrICdQKM9N0NVGO8U zq2qYQZNBfPPpC0yW4gPvYOSh0tCPtUH0j1OnUHkHNvDEfX9VbBfdOqkQ702imMdAv11 QNVelHehz8KW6uy/hM7ao6Jg1h1guJCd0J/+3b684o8Q4uKVamZ4BQgOuDbpfuNbsQhr HB5A==
X-Gm-Message-State: ACrzQf1xS52jc4Z5jHTS+G0/mQ0XSlxjPTWmyClnGTKD+A7b0zrx7W+y PzCT+aSWDPurWBK01f6UdTnEm6yFtZekKOXXi3E6pKelDA==
X-Google-Smtp-Source: AMsMyM4yGdWOmGq56lL003iLIhr0jzS6Do+l5CL3THomsRt3BrqE3yV7Kn0TlkFrGeV6G59JBUZUM4QyPTQ53Y7efc4=
X-Received: by 2002:a05:6808:13d4:b0:34f:b867:8994 with SMTP id d20-20020a05680813d400b0034fb8678994mr2640989oiw.116.1663883995956; Thu, 22 Sep 2022 14:59:55 -0700 (PDT)
MIME-Version: 1.0
References: <CO1PR00MB130824EBDD7C1420E9D3065CF54E9@CO1PR00MB1308.namprd00.prod.outlook.com>
In-Reply-To: <CO1PR00MB130824EBDD7C1420E9D3065CF54E9@CO1PR00MB1308.namprd00.prod.outlook.com>
From: AJITOMI Daisuke <ajitomi@gmail.com>
Date: Fri, 23 Sep 2022 06:59:43 +0900
Message-ID: <CAFWvErXY4NmpAr5SwN7UTsYmYJiL0HdxhmFrdPjpm0Ca0Hh++Q@mail.gmail.com>
To: Mike Jones <Michael.Jones=40microsoft.com@dmarc.ietf.org>
Cc: "cose@ietf.org" <cose@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000086c96b05e94b2e4d"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/KgmZ24AwkmFsde_sfGhqiDGg2T4>
Subject: Re: [COSE] COSE HPKE Public Key Format Consensus Call
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Sep 2022 22:00:00 -0000

Thanks for initiating the consensus call.

> 3.  Other (please describe in sufficient detail to enable its
specification)

+1 to my proposal described in my previous post[1].

I have made a chart comparing my proposal to the current draft. As
described in the chart, there are some problems with the current draft that
cannot be overlooked. I would be happy if you could use it as a reference
for your vote.
https://docs.google.com/presentation/d/1azfHu93NCm5M9KUbpbtRze7aitvpBAj9SxhpvHe877M

In addition,  Mr. Richard Barnes also pointed out on the JOSE WG mailing
list that it is incorrect to use COSE_Key to represent encapsulated
keys[2]. I have the same opinion.

As I mentioned repeatedly,  the encoding format of the recipient public key
and the encapsulated key (ephemeral sender's public key) should be
considered separately.
The former should be able to be expressed with COSE_Key, but the latter
should not.

Best regards,
Daisuke

[1] https://mailarchive.ietf.org/arch/msg/cose/ZY5v7jJr4SxHGIbeA3dgLC6eZDg/
[2] https://mailarchive.ietf.org/arch/msg/jose/IKIR_XusfHD26ewqZSt5ad2WUc8/

2022年9月23日(金) 2:09 Mike Jones <Michael.Jones=40microsoft.com@dmarc.ietf.org
>:

> As discussed at IETF 114, the HPKE draft uses the COSE_Key public key
> representation.  The authors described that Ilari Liusvaara had proposed
> using a different public key representation, which is detailed in Slide 2
> of
> https://datatracker.ietf.org/meeting/114/materials/slides-114-cose-cose-hpke-00.
> As recorded in the minutes
> <https://datatracker.ietf.org/doc/minutes-114-cose/>, consensus during
> the meeting appeared to be in favor of continuing to use COSE_Key.
>
>
>
> This note initiates a consensus call by the chairs on the topic of what
> public key format the COSE HPKE specification will use.  Working group
> members are requested to express their preferences within two weeks of this
> note (by Thursday, September 6th) for either:
>
>
>
> 1.  Continuing to use COSE_Key
>
> 2.  Using the different format proposed by Ilari Liusvaara
>
> 3.  Other (please describe in sufficient detail to enable its
> specification)
>
>
>
>                                                        Thank you,
>
>                                          -- Mike (for the COSE chairs)
>
>
> _______________________________________________
> COSE mailing list
> COSE@ietf.org
> https://www.ietf.org/mailman/listinfo/cose
>