Re: [COSE] Draft IETF 117 COSE agenda

"Tschofenig, Hannes" <hannes.tschofenig@siemens.com> Thu, 20 July 2023 09:48 UTC

Return-Path: <hannes.tschofenig@siemens.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A90DC14CE4F for <cose@ietfa.amsl.com>; Thu, 20 Jul 2023 02:48:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=siemens.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id h3w1mdoza9Du for <cose@ietfa.amsl.com>; Thu, 20 Jul 2023 02:48:47 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2056.outbound.protection.outlook.com [40.107.20.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E289FC14CE3F for <cose@ietf.org>; Thu, 20 Jul 2023 02:48:46 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=go3+C/WwVceZl212Ic6WeZspOH9HAFpf06sHHjZ9aav7/pWJYibhQClJ34lqCQWj0lAYCttDdG7q+x2TTu++zaeoKzofrMoUIhb5nOTTPPU+KaTGxu/1HqMvtYvtylHduoLuVLIted992hwC3wl9WuXPHUHH3NSD5xVfc0LPxK3Ckz3B/jGlnqwSW5eHxt3OuQzkw1G08ft0RAnuhD4ffPEfGxYfyw2s/jAeD3qbALPWHpL1q6uuDubsjzkPUu9MglXOaIyC/h8y0c92Yg0oqyDjvqBE5VbdWV+5/1hqnQIEDnZQoA4IqjzRVD1iKPJldr4OnYhOf2IL25sM7lniKQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=9qttAHuWVYGTExY3yEgalAEHKiktqI4vlYDrXJ5c4RM=; b=e8q7fUNEgGvaVUgRQuZx1EtLEPIWmfFWdQ5J1NO1cay5CVzdntiiCFPaVH7KYRZTQiZ2h25Gg7LlLHW3cy0cn655oZF8wUMaIn54UEBiuuAeruLcYgYtcbIUaqPXLD4CR8/3zQZC7/J7/O5wwKkvWfgiAsQvhcJwnHevnKjh9wxcqd/ekiY5v8iqbzBdPJmxn6bv9LKJiIryEpqt6+fdv+0fII9P2rpUFQge5SDnMo1PUOaPYpchadfOHdAuZlwnR1X9ubWMK51FnppKf37p68bGeE3TbEivwvqqpSxVZDNg1qM/l/XnJhijCLWnrn92Zhtx+PiR9weETGDKM4P1mw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=9qttAHuWVYGTExY3yEgalAEHKiktqI4vlYDrXJ5c4RM=; b=yQW/K4lQ+3opcONdo3drUWhPPzBhJQ5QX473OvPOHgM2X4BN86LL9KPa8NFljJnWqn4FsmdwMqonuhudKv1AFJr3lW1sXCP6zPsMnBMktXP2WPalni/ZSV8ht90QbFQuGz7nbvID7W2EOSvgq5EjK42QFvVOn+uo2SuMcg3A78Cq8x/hz7lqlZuiTmz/OTZFI8WqvrKiTdz5+cJ0jSwpzjfLbai2q1p+RC+OJUE7IoW9e2FVObOULshuMJedIjZ3mRMnoCGcAYi6tZcWnFJiFF8QZsiLQJaILAdffbMaEQpa/h6yX5+JnnT6rMxpDTuEglyN/EP5ZlfaYaNfei6Nsg==
Received: from AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:5ab::22) by AS8PR10MB6996.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:5a7::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6588.31; Thu, 20 Jul 2023 09:48:44 +0000
Received: from AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM ([fe80::d2e9:efb4:5e60:2c60]) by AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM ([fe80::d2e9:efb4:5e60:2c60%5]) with mapi id 15.20.6588.031; Thu, 20 Jul 2023 09:48:44 +0000
From: "Tschofenig, Hannes" <hannes.tschofenig@siemens.com>
To: Michael Jones <michael_b_jones@hotmail.com>, cose <cose@ietf.org>
Thread-Topic: Draft IETF 117 COSE agenda
Thread-Index: Adm5nPWN7H2vcrPeSseRlHnamti7dAAZhSIgABd9EgAAI0NbYA==
Date: Thu, 20 Jul 2023 09:48:44 +0000
Message-ID: <AS8PR10MB742780E62E842650D76B42B1EE3EA@AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM>
References: <SJ0PR02MB74394E66F880D4948217ED57B738A@SJ0PR02MB7439.namprd02.prod.outlook.com> <AS8PR10MB7427A0FF328462A6212E2590EE39A@AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM> <MW4PR02MB74281BC30C2B395F77E3F1FCB739A@MW4PR02MB7428.namprd02.prod.outlook.com>
In-Reply-To: <MW4PR02MB74281BC30C2B395F77E3F1FCB739A@MW4PR02MB7428.namprd02.prod.outlook.com>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Enabled=true; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SetDate=2023-07-20T09:48:43Z; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Method=Standard; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Name=restricted; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ActionId=7948e0b0-b592-46e1-9172-a3451181e6b0; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ContentBits=0
document_confidentiality: Restricted
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: AS8PR10MB7427:EE_|AS8PR10MB6996:EE_
x-ms-office365-filtering-correlation-id: aad57da9-b58e-4814-64bf-08db890681ad
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: n0G2fn5Dw5Hw8JB2FZNiruGsfQBLEx6XxM6uM1DdM7TD9wZvc0Y26emMe+YSY5+y5FkI1eCnST9vlkR5gFWjx+Vlkgy0PBCDO3pYu1JKgU0Bg04qMFFs0gW7icfUWoy5t5ucxw9EbOIt9MsDiHTXV088LHNffQQyJd9aPOBcESF/b43ot9BmZUW8WkFTetEnP4SyTG14Rif4KXj3Al6MtPQqy/LTzx/uSnKUlmpS5m/ZESDW1+I5k4XzVs46D6NxaLbEVuOaG7FoEHTDG29daV0UhJKGLgZwwiCYvdkAJySCi6jn+nS6WGObxAh4tamJuBikPAGcClaIP6KlyJNwlCJbYGc1e1K4ubSqyK8Gas7Cxqpv0USNvtRS3o0oMe7o7zmRD/8/G3q5+iDhZevm0y/zOyY6wkCg0BtK5eivfCsWJoZJuLAyQ9JCwjsFCZFyJiu511La8gg8eAZQ5NmCt2iqMRG/6ec1XN38iC9+ANLrPSHLODgryTtTzKgAS53sU+GMq94FYEAbgxKjhieDDOPBANC2OjOl+5UBFUOHL4epi8ANL7Y6GvVOgBVoIUC0PqVWVdSPou/2qsDqRKkJMgFLB9aAEpwKwDShIoUV8Mg=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(4636009)(366004)(376002)(136003)(39860400002)(396003)(346002)(451199021)(38070700005)(76116006)(86362001)(2906002)(33656002)(55016003)(6506007)(38100700002)(186003)(83380400001)(55236004)(9686003)(26005)(53546011)(82960400001)(7696005)(166002)(122000001)(66556008)(110136005)(71200400001)(5660300002)(66946007)(66476007)(64756008)(66446008)(478600001)(41300700001)(45080400002)(8676002)(8936002)(316002)(52536014); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: nmQQB5QVpsRZXb9eoj7NChDQUVIo6LOtrkR9yA5XpMSddBQs6wNG9QPnwaPyBRyJWhQ9cWltDJ8l65/XpF4pPxyr/6Jdh6Huoryb2/MllMTA8kTV0aXXJXRbkFkeOFwJa+rBFGaAF84yKz8+NqPXLSR0bDYS61OeAPVLlvhqIuFFDnlcliIM/noyU7MmfgJw1dNc5AXnitnrpDBqdmn23MK5lj3xu8jKV08Tho+hOVLP95mixPZ6vyqTYKIhLxpQPRkALMN/tt7reeOeK1LWq4UqXO5mu3wsZsd4WYQGWRgYxKisnCgtIzBG2MvFRTF0Ue8nqxTdox3WMH5z8cDtoD0uDaye2T3aNRoKvoI8ekFpkd8eRkJ8gMiR52F3vivH5JblvJHkok+etWPF/zfKusg2eJDkTH5XZAiCZXZM2D88AETVT4bRL+rEIV1sWQFPmoLLGgAGJ/6ZBCkYL5MkBbN04ezh/SlbJjGxhTSmufagbWGOQU2BUXMJcuuYBhbfIjhsBDvOZDoRo7dkLGygK1EDTRGCPNeBWx05itVw6fcQAUjjdPXQZj45hx8NiXyGx+KMDTx0qCJ0weOx/FS/c4daLnnJlc47ypKBwqDSVrswx5MUTzm6JVo0wd8MSBYRUnKPX49AB2HEytrcWQAqIt0AyTaSG9RGFMahYfYkcBLIDj+zrBCEwdPG/6vud/T3lSl+W8O8fkkqd0easQn2FLeTtx4DdTXSPCaMqGecd2V7MquC0ZOk8uJROv9floBLZOfE3YYPIiiS9g2qfEKf7uY7+7mpNpSSxijK4G5LF02aCPJ3xiGjIlDIRSA3WvGnZOOXN1dzt/HrUMQFV57hSI0DqoH+gSh1qYL2MRuACJD+dBpaevDm8Ja8/T0GKBhHGPdBnZiKwvZT1xmZh9cpWkAeE50Lis+t7s8cPQ0zFe5Up6s8vMaZjK1ULkzcI+KrrAK4jIhgQidVvoJ8bRUidKyzIZ7r2BZ1KmmFAi9d5IjHwaJhRYKrGpE0WgvQiK9aoHks/i4/h669xDDykeCbAERemrSemNvk0OoBoz650Qkfk3d0eaICJcNlEFz9xHo4wd/1lMVtHpbgWtPPsjpA5v3mm6jUKvb8epSK7oQEDBEsFfKDLu2wYW3gK30wWNUO3ix7VvK75oYpLMuDsg7r7ureEmWZd3lAPW8ykPQyP9QrKeEX305/mkd3RjQz6jSoAUcfvopB1BF4DHn7Ux4RXZpVngSnO9iD/PkmWDNPH9TeKroKoggemQro+6drlu3GnLV94K2wQR4YVoOZAOr3YSCLdRVxP5+QxIIrLR3bz/pyd3XGvoaKovPd+/VWdD1J1vxw9b1ueoETGpyyOco8HBvhUoLRmOp8M1VVk3jXoP7Dp7W3LKVrQ06hQiZM3f87LHLY9YMUyKfCJM876jUDSqCYpYFlMpsKvuhzEx9Epu7STNbnCcCjZ4TsZQC3xGRbsnZTQ1Wlfq+KRkXb25JXUdVfv6OWAWTqHiTE0y7YHbm4ggxpsChaAqJvbotxZwLnUrX6tM/Z7y5sOhuUJBiwuiD3qbvBACJrmc1aJyMxQt+PRhosPLwL6r857fa1xmCxxEcafP1aqq/OX0UpNLA4ug==
Content-Type: multipart/alternative; boundary="_000_AS8PR10MB742780E62E842650D76B42B1EE3EAAS8PR10MB7427EURP_"
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AS8PR10MB7427.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: aad57da9-b58e-4814-64bf-08db890681ad
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Jul 2023 09:48:44.0944 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ioQddguMYFSDCeMcKQq3XIQ6ZFScKNREZemax+2PUJHdU1jwPInD45WNiR08gtgOKhoKxycuMwktCRCBaJH+6tj1x+l3TK7yY3oZ/tp6df4=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR10MB6996
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/p7bi1g4Ls9HnmklMmm0Uk1_M1D4>
Subject: Re: [COSE] Draft IETF 117 COSE agenda
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Jul 2023 09:48:51 -0000

Hi Mike,

Here is the question the working group is facing.

Should there

  1.  be a single value associated with the combination of KEM, KDF, and AEAD, or
  2.  individual values for each of them.

The former design is often called ciphersuite.

We used (a) in earlier versions of the COSE-HPKE draft (see, for example, draft-ietf-cose-hpke-01<https://datatracker.ietf.org/doc/html/draft-ietf-cose-hpke-01#name-iana-considerations-6> ) and (b) in later versions of the draft (see, for example, draft-ietf-cose-hpke-05<https://datatracker.ietf.org/doc/html/draft-ietf-cose-hpke-05#section-3.1>).

Based on my assessment of the feedback from the group, there is a preference to switch back to the ciphersuite approach.

Ciao
Hannes

Von: Michael Jones <michael_b_jones@hotmail.com>
Gesendet: Mittwoch, 19. Juli 2023 18:52
An: Tschofenig, Hannes (T CST SEA-DE) <hannes.tschofenig@siemens.com>; cose <cose@ietf.org>
Betreff: RE: Draft IETF 117 COSE agenda

As a chair, I'd like clarity on what you mean by "the single algorithm design".  Do you mean that each algorithm identifier fully specifies all the cryptographic parameters being used?  Or do you mean that a single algorithm identifier is used for all the HPKE possibilities?

Speaking as an individual contributor, I fully support the first (fully specified) choice.  Whereas the second possibility will cause endless interoperability problems.

                                                       -- Mike

From: Tschofenig, Hannes <hannes.tschofenig@siemens.com<mailto:hannes.tschofenig@siemens.com>>
Sent: Tuesday, July 18, 2023 10:51 PM
To: Michael Jones <michael_b_jones@hotmail.com<mailto:michael_b_jones@hotmail.com>>; cose <cose@ietf.org<mailto:cose@ietf.org>>
Subject: AW: Draft IETF 117 COSE agenda

Hi Mike,

the content issue with HPKE is the single algorithm design. I have posted a summary about it to the list, see [COSE] COSE-HPKE and the Single Algorithm Discussion (ietf.org)<https://mailarchive.ietf.org/arch/msg/cose/_GQXXpltAgXNozXIFC9z1yY1CCM/>

It needs a consensus call from the chairs to finalize it.

You could start this call today and be done with it by the time of the meeting.

Ciao
Hannes

Von: COSE <cose-bounces@ietf.org<mailto:cose-bounces@ietf.org>> Im Auftrag von Michael Jones
Gesendet: Dienstag, 18. Juli 2023 19:33
An: cose@ietf.org<mailto:cose@ietf.org>
Betreff: [COSE] Draft IETF 117 COSE agenda

Ivo and I propose the following agenda for our meeting in San Francisco.  We have a two-hour timeslot.  Please provide any feedback by tomorrow, at which point I'll revise and post the agenda to the meeting materials.

                                                       -- Mike

CBOR Object Signing and Encryption (COSE)

13:00-13:05 Opening remarks - the chairs (5 minutes)
13:05-13:25 Post-Quantum Signatures draft-ietf-cose-{dilithium,sphincs,falcon} (20 minutes) - Mike Prorock and Orie Steele
13:25-13:35 draft-birkholz-cose-tsa-tst-header-parameter (10 minutes) - Henk Birkholz
13:35-13:45 draft-ietf-cose-cbor-encoded-cert (10 minutes) - Göran Selander or John Mattsson
13:45-13:55 draft-steele-cose-merkle-tree-proofs (10 minutes) - Orie Steele
13:55-14:05 draft-birkholz-cose-cometre-ccf-profile (10 minutes) - Henk Birkholz
14:05-14:15 draft-isobe-cose-key-thumbprint (10 minutes) - Hannes Tschofenig
14:15-14:25 draft-jones-cose-typ-header-parameter (10 minutes) - Orie Steele and Mike Jones
14:25-14:40 Summary of contentious issues in HPKE (15 minutes) - Orie Steele
14:40-14:55 draft-ietf-cose-hpke (15 minutes) - Hannes Tschofenig
14:55-15:00 AOB (5 minutes)