Re: [Crypto-panel] Request for review: draft-irtf-cfrg-dnhpke-03

"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Tue, 28 November 2023 20:33 UTC

Return-Path: <sfluhrer@cisco.com>
X-Original-To: crypto-panel@ietfa.amsl.com
Delivered-To: crypto-panel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3CCB0C15109C for <crypto-panel@ietfa.amsl.com>; Tue, 28 Nov 2023 12:33:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.606
X-Spam-Level:
X-Spam-Status: No, score=-14.606 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b="SSgp1Kqt"; dkim=pass (1024-bit key) header.d=cisco.com header.b="YMk7dSnN"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l6t6kzAsc7VI for <crypto-panel@ietfa.amsl.com>; Tue, 28 Nov 2023 12:33:44 -0800 (PST)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3DBC3C151096 for <crypto-panel@irtf.org>; Tue, 28 Nov 2023 12:33:44 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2575; q=dns/txt; s=iport; t=1701203624; x=1702413224; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=k1yfXqd72DgeJTCndOOkaE0IorJwdgMnRq0eNY1MJEk=; b=SSgp1Kqt6QN8Et685lQYEJ9HZssNIqmAX3vwHncoqQwAYpTdt/dzGFVm njAg19TMsdIOmWEC35roma1i7toLoLEqt10u9J9Jiy+KtKBgtBkFp8Hho b8uTFRoBoyBPKyC1oHN67waxorDGZuDqlow/sstX/HdY6JSB/n+fHyzPO 8=;
X-CSE-ConnectionGUID: py4xOe//SXCeWCwIrECIcQ==
X-CSE-MsgGUID: Cxgi9inDTeWvjesLSfW0Eg==
X-IPAS-Result: A0ADAADGTWZlmJpdJa1aGgEBAQEBAQEBAQEDAQEBARIBAQEBAgIBAQEBQCWBFgUBAQEBCwGBZlJ4AlkqEkiIHgOETl+IYwOdfhSBEQNWDwEBAQ0BAS4LCwQBAYRARgKHKQImNAkOAQICAgEBAQEDAgMBAQEBAQEBAgEBBQEBAQIBBwQUAQEBAQEBAQEeGQUOECeFaA2GRQEBAQEDAQEQFRMGAQEpAwsBCwQCAQgRBAEBHxAnCx0IAgQBDQUIGoJeAYJeAwEQolwBgUACiih4gQEzgQGCCQEBBgQFgU5BsF8DBoFIAYgMAYhvgR8nG4FJRIEVQoJoPmsaAYFbAQEDgSM8hBKCL4J/hiQHMoFDghiCGIhthlFVKkdwGwMHA38PKwcEMBsHBgkULSMGUQQoIQkTEj4EgV+BUQp/Pw8OEYI/IgIHNjYZSIJbFQw0BEZ2ECoEFBeBEgRqBRYSHjcREhcNAwh0HQIyOgIDBQMEMwoSDQshBRRCA0UGSQsDAhoFAwMEgTMFDR4CEBoGDCcDAxJNAhAUAzsDAwYDCzEDMFVEDE8Dax82CRIqCwQMHwIbHg0nJQIyQgMRBRICFgMkFgQ2EQkLKwMvBjgCEwwGBgllKQNEHUADC209FCEGDhsFBGRZBZ9EgnaBWUMQWz1COZM/sggKhA2MApU+F6khZESXfCCNR5VFhH8CBAIEBQIOAQEGgWM6gVtwFTuCZ1IZD44gCQMNCYNWhRSKZXY7AgcLAQEDCYZIhBkBAQ
IronPort-PHdr: A9a23:pwcHGBCuMjavhn0fy+2AUyQVoBdPi9zP1kY98JErjfdJaqu8usikN 03E7vIrh1jMDs3X6PNB3vLfqLuoGXcB7pCIrG0YfdRSWgUEh8Qbk01oAMOMBUDhav+/Ryc7B 89FElRi+iLzKlBbTf73fEaauXiu9XgXExT7OxByI7HuFIrPj966zci5+obYZENDgz/uKb93J Q+9+B3YrdJewZM3M7s40BLPvnpOdqxaxHg9I1WVkle06pK7/YVo9GJbvPdJyg==
IronPort-Data: A9a23:r1iFF6OuIpz22pPvrR2il8FynXyQoLVcMsEvi/4bfWQNrUom0mZVm DFMUWHSbK6Nazehetglbt6woRlVu8SEyIRgHnM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCdaphyFjmF/kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/W1/lV e/a+ZWFYwb8gW4saAr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQrl58R7PSq 07rldlVz0uBl/sfIorNfoXTLiXmdoXv0T2m0RK6bUQNbi9q/UTe2o5jXBYVhNw+Zz+hx7idw /0V3XC8pJtA0qDkwIwgvxdk/y5WJbwa6JjKZj+Egeee8GbZUmHB6NRlNRRjVWEY0r4f7WBm7 /cULnUGaQqOwrnwy7OgQe4qjcMmRCXpFNpA4Tc7kneIVrB/HMyrr6bivbe02B8riMRTHezTf eISaCFka1LLZBgn1lI/Uc5hw7f53CCgG9FegHmFqqtm4m7/8AFOzrrgK/7udOPSaMoAyy50o UqdojymWUtFXDCF8hKO6GO0muiKhSr9VYY6Faek+LhtmlL7+4AIIAcdWV3+qv6jhwvlHdleM EcTvCEpqMDe6XBHUPHlTkGoh3PD+SUscNdvOPIb8iym66HttlPx6nc/chZNb9kvtckTTDMs1 0OUk96BOdCJmOPNIZ563unMxQ5eKRQowXk+iTjopDbpDvH5q401yxnIVNsmS+i+j8b+Hnf7x DXiQMkCa1c705RjO0aTpAyvb9eQSn7hElVdCuL/AjrN0++BTNT5D7FEEHCChRq6EK6XT0Oao F8PkNWE4eYFAPmlzXPVGbxcQuv3uqnVaVUwZGKD+bF/rVxBHFb9JehtDM1WfR8B3jssIGa2P xGL4Wu9GrcJbST0BUOIX25BI593lfe7T4uNugH8ZdtVaZ85bx6c4CxrfgaR2Wur+HXAYolhU ap3hf2EVC5AYYw+lWLeb75EjdcDmHtkrUuNHs+T8vhS+efEDJJjYe1bYALmgyFQxP7snTg5B P4FZpLWm04ACregCsQVmKZKRW03wbEALcmeg+Rcd/WIJUxtH2RJNhMb6epJl1BN90iNqtr1w w==
IronPort-HdrOrdr: A9a23:fH2Dp6hjDIdSJ1WIoown90yCZnBQX5923DAbv31ZSRFFG/FwyP re/8jzhCWVtN9OYhAdcIi7Sdi9qBPnmaKc4eEqTM6ftXrdyRuVxeZZnMXfKlzbamLDH4tmpM VdmsdFeaDN5DRB/KHHCUyDYqgdKbq8geGVbIXlvgtQpGhRAskKgXYde2Km+w9NNXZ77PECZe KhD7981kCdkAMsH7+G7xc+Lo7+juyOvqjLJTQBABkq4hSPizSH1J7WeiLz4j4uFxl07fMH62 bqryzVj5/Pjxi88HDh/l6Wy64TtMrqy9NFCsDJoNMSMC/QhgGhY5kkc6GevRguydvfq2oCoZ 3pmVMNLs5z43TeciWeuh32wTTt1z4o9jvL1UKYu33+usb0LQhKSfapxLgpNycx2XBQ++2U45 g7mV5xcKAnVC8oqR6No+QgkSsaznZc70BSytL7xEYvIrf2IIUh37D3unklUKvp2EnBmd0a+C 4ENrCH2N9GNVyddHzXpW9p3ZilWWkyBA6PRgwYttWSyCU+pgEy86I0/r1Wop47zuN3d7BUo+ Dfdqh4nrBHScEbKap7GecaWMOyTmjAWwjFPm6eKUnuUPhvAQOAl7fnpLEuoO26cp0By5U/3J zHTVNDrGY3P0bjE9eH0pFH+g3EBG+9QTPuwMdD4IURgMyweJP7dSmYDFw+mcqppPsSRsXdRv aoIZpTR+TuKGP/cLw5ljEWm6MiX0X2fPdlzerTAWj+1/4jAreawtDmTA==
X-Talos-CUID: 9a23:4ikq8mzGH9309Z3sqyYKBgUMC5w1VXCai0zgCEKHInlIUpC+aFSprfY=
X-Talos-MUID: 9a23:I+fqCg/PjDIAuAZnTYv/VkGQf+x47KX/CUYhrZg5pcuJLghLNQjFoTviFw==
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-core-3.cisco.com ([173.37.93.154]) by rcdn-iport-7.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 28 Nov 2023 20:33:43 +0000
Received: from rcdn-opgw-4.cisco.com (rcdn-opgw-4.cisco.com [72.163.7.165]) by rcdn-core-3.cisco.com (8.15.2/8.15.2) with ESMTPS id 3ASKXhXU016855 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <crypto-panel@irtf.org>; Tue, 28 Nov 2023 20:33:43 GMT
X-CSE-ConnectionGUID: EvW8whcyR2WnO4esen4iLA==
X-CSE-MsgGUID: lLNj61lZT3+2IsjHXIIVmg==
Authentication-Results: rcdn-opgw-4.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=sfluhrer@cisco.com; dmarc=pass (p=quarantine dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="6.04,234,1695686400"; d="scan'208";a="12465424"
Received: from mail-mw2nam10lp2101.outbound.protection.outlook.com (HELO NAM10-MW2-obe.outbound.protection.outlook.com) ([104.47.55.101]) by rcdn-opgw-4.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 28 Nov 2023 20:33:42 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Xz2UtBDANjrXjF6zYu8fsFtpCrcYb9vkXARPHV9hDBmhwInGoet8V7d+H8AuNuZqOPRBbLUnYfRNjqdVG6/9FqpCnceNh9pzEWOTdsSLEeDt1xB22Olnx8E0E8ALLq8J8ZOkwOjpAtoVwMndVozobBj49im1+uhfYTQa9gdw5+6dOFt8bONR/U2iKpGyFivz57+ZCnF3BSBwYMOxmyOL6L0bDw53YDdwC1zIEO5096/EI3uOi9GnFabPHjDREJJoGLuxSRkbZdEqrL0mdekEzit/Fem+9WKuIZAxfV316o2kWupTFleo/erWE2lmrgGmPo7auT8ysFLSrhsKRy+ozQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=cIzlAx2c4zgZFFlr1pkuwOIXyZ0avePeIawByWLgzzU=; b=oa+AHKIt6gXPEqU85JnhGpJjYaDTfykwKu0MIVT/X/07r2qjnefZtSZg8E1rI25Ms34AgG1l6pHfzAQ938SW+hFfQPzhoE9GV0kuZZEfKVKRlF6OyxO/X9FgRG/tznvrlxYGmq31Cy1EVU5ukxrsMzf5SrWA9xd/rFSxGr2+flzmdkofSD38KkxoTBCCG3Z0roNtsdMn55ct1Sem8z1czSbXFA7RMbcOnEbH35VliUsuLjLfvlIB5s+vzzR5qk7DDMG3i8BeLpA+zsprnT6UvJcNtSNt9PscJWs79MDRctqEO2KfbJi84m7WzWzY1NeDwZ/cNdtidwTXcWEGKS4bgg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cIzlAx2c4zgZFFlr1pkuwOIXyZ0avePeIawByWLgzzU=; b=YMk7dSnNore8VlSUlZaDLG1zrrzb9mqYiWHHsbvOEulSKsCzNM0p1YJ5r0gpvRjjhqO+Z9gEw9dmFR02rNer+yhtjq2HIqEZhe75Qs0UXljAR1gnPdanMxLfjC001U4uRjYtja5YAB7DUkbhaGEK2qRTLgfyqxezVnVYRawvDyU=
Received: from CH0PR11MB5444.namprd11.prod.outlook.com (2603:10b6:610:d3::13) by MW4PR11MB7079.namprd11.prod.outlook.com (2603:10b6:303:22b::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7025.28; Tue, 28 Nov 2023 20:33:40 +0000
Received: from CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::63a:96cd:589f:5b76]) by CH0PR11MB5444.namprd11.prod.outlook.com ([fe80::63a:96cd:589f:5b76%6]) with mapi id 15.20.7025.022; Tue, 28 Nov 2023 20:33:40 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>, "crypto-panel@irtf.org" <crypto-panel@irtf.org>
CC: "daniel.harkins@hpe.com" <daniel.harkins@hpe.com>, "cfrg-chairs@ietf.org" <cfrg-chairs@ietf.org>
Thread-Topic: [Crypto-panel] Request for review: draft-irtf-cfrg-dnhpke-03
Thread-Index: AQHaGJy3VdJQn7pd5kGmfvqmVyladLB9D8fggBMskkA=
Date: Tue, 28 Nov 2023 20:33:39 +0000
Message-ID: <CH0PR11MB5444C6D8E240BC7CF65210BCC1BCA@CH0PR11MB5444.namprd11.prod.outlook.com>
References: <c1c33cb6-a804-4e17-b082-0aecf5056df1@isode.com> <CH0PR11MB5444D586C90F11749F27E461C1B0A@CH0PR11MB5444.namprd11.prod.outlook.com>
In-Reply-To: <CH0PR11MB5444D586C90F11749F27E461C1B0A@CH0PR11MB5444.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CH0PR11MB5444:EE_|MW4PR11MB7079:EE_
x-ms-office365-filtering-correlation-id: 33556f14-08b1-4c6b-6296-08dbf0514e62
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 5Hk9+Rlg1kQ2zTxgl6awAi5AuhnDhFJUoRnoMMfIOgtSdcS4+iPxTVYVQ1/v3Jo/ERN8nQpuz+XB1jvEbPuEboF3J2eSblKQRzsBVKznnyvsZPwXh0EExkuombEhvDXFPhfWEfimj8+utHoacRFigSdeiSHNFsxYiHxywYtP8ItaTVQqYMCo6WWGnEFk7MzwpeUUxMBCd2Ulkjo5muwNQtYFqPUFywtkmJugZO9Tm3Lm4L4tQVbBRFy1q/hYdHBJNdH5khzd2iJHhXiDPZ/SlHzUYg75xgjGu0k1AA1vdvzV+WyagoYzvLGKF3k+B88WpDWcnr1W+LjevVCSzpJLH2MX0faf5HdZNZeiM5v+XPqodJUzWSfZ14FOl/Krzu/T2sShyTjsSKSwmtwjQmF50quwquGEtuJzOkThj77NQLfee1OwZDVU9LW1a8VDJHAarD5m9axzs4SBoYu06h8UZOX8Xo8ngK2qya7nQ9s5ylLCDYI6qIS2zN0kRL/GEAAe0S7WeHo6MV5vCaN6YRxzuvF6d/ZlOh/Gtxt6knWrpeJWovG3BqyNssRxnSt5RVhygNsQnLPqu08Ajx2RDw+hnGnWPxZM1u/EPnBgkZ2dqRY=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5444.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376002)(136003)(396003)(366004)(39860400002)(346002)(230922051799003)(186009)(1800799012)(64100799003)(451199024)(38100700002)(41300700001)(33656002)(38070700009)(122000001)(55016003)(83380400001)(5660300002)(26005)(86362001)(2906002)(9686003)(6506007)(7696005)(53546011)(52536014)(8676002)(8936002)(71200400001)(4326008)(478600001)(966005)(66946007)(110136005)(66446008)(66556008)(54906003)(316002)(66476007)(64756008)(76116006); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: iuC/oBFVtAcV1gLpVgKc4UpgnO4caxSD1NAFs3sODibN/BRx2OvClc7mboDcu4AVX4zWAFR5X1Zn/tdfudS99by+g57ZYASR3H0+x2NsGW4ifmdxOpvNplLA2qzgbh9UWEPjE+incJNHmVrQecxyj5u0R8gNi6/3q6NeeB7TMID2EPHUf6kc0sFotyyOPp7rLk2f0YmR65RwZ7z2KuOrIJgPP9HLDDuPhEiUqasOEEnAAJgWjMwApwuoQyWngUsIrIePgsG51IL+OMnPKZ7JzxxxxiMC+GDgUzhoI/NskdpXHuCEPs4Fdo8i8GnK7Iy7SSKMy4lC3IB/ETrLTRLCxws+FVY3qwDGWQejuJoLatgV/OqmQCe6m4bWURw7uoHvEF1F6ILBzhzLL22J1iTcCJYxC7cZJ5WwfvKEI8Q0HHE1oKWUWiyloHEy5EgoqXCpcdnaSDNkiMX0QIy4mTFkprZTIuRTYuuI2WD9CFKNr0a/z17VClZCLVwlmgejh528mg1h4LGWq7GlSGNnzGFq+ivaCzeSwT+BwnlTpSbxJElB13oit59hYm1CttLU0w6m6hClGy0V80jA6Ome1AdIc7tVWvWfWctd+fhC4OmiZUgODz63faSiko9dz+z6i8KEu6OvCVCwVNhCBDdDt+rH3gngJ/yC0Zaf3XnIcD8QRbvB3Yxtb1Po26ksGXcpU6KM19KnYI5aYII+ISUruYQ6dXoZb9cSm/cqlxqg/Cgez8SlsBURkAP1LjxKSGwkwxdumh6bTkwRan4CELzbEGbpd2dm+vHmpgbV0R/B5pLiawBbVNlWHWo2tBhHFAUJkAzCxmrK4TL88c1DeUDioWH8KfaDz0T2R/gF8Q88twWat2ujubsg2FTGVJcw9wf2raRn44O0pzHjdUb+i6fWHQ1yGfxUnLn/L520y+ey7y/61S/5U04IKDKRSrJnk0Aq4k9BzewyDTIfrACv/qe/0ZyPMypZRjkizZhXm0+cB/RRkj8/HadD0Xl/UNp7+fI2IDURAXwjJwbTQBbhW81J0RHyH3LvJXUfMQaNtd+yDzpV2WAgBgG170Qr+ihKBd7GfXBQM0DlhNA4PLp7P590/UaQQTsW03WDCC1rKi8QMKaS2kkKYPF6gJH5MMro9XIECFOfWxFh6wp3k4f6cWmBnj9zjrHm3R8ijI6UTVYmxtcxAHHoRw+iKWLD0awv+SDxWKJkCxh9oFoZFGlnoEQzkBgiW6b6emd6ShrufBimF3HykTlSaiNdCWpsmml3epCew/x/QTK7WWw/Wb9Epvh/3CfdgJ7xvR45l4xXG/2lGWsCfDVx0XPkmRDWsC9/FFxYkgmy//h2W/yjHWmjApXGiqAmlLsQKo2e52BBkV/Nk2J2PyX6uk2nvl/6H1/a+9myrJiR3kO47icm277qpnO7qchoQmaiYXlqaUj2uFhVtaVGpOXkHxvqfiuG2M+yQfDmPZZ1SnHFBmeH60l3JCiQS9WW+AovDArHOWCNOInygMOLwmhlB2gvOCeB/unPPoFDZpLYclfFr+qIhNrpG2Wb3mPjyRpV13D0KOA9oLIj/20nk8o=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5444.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 33556f14-08b1-4c6b-6296-08dbf0514e62
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Nov 2023 20:33:40.0750 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: wHetjSFXBYavkNofFUOhoAzChu05MSdbAfzmMujVeiyIv4JzAKIh6NbiRUlw0QU9nWFXacG/8FjAfb8bVxi8Bw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW4PR11MB7079
X-Outbound-SMTP-Client: 72.163.7.165, rcdn-opgw-4.cisco.com
X-Outbound-Node: rcdn-core-3.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/crypto-panel/mVv0Qf3MKZGtzfTSoC8My6kgd1s>
Subject: Re: [Crypto-panel] Request for review: draft-irtf-cfrg-dnhpke-03
X-BeenThere: crypto-panel@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Crypto Review Panel review coordination <crypto-panel.irtf.org>
List-Unsubscribe: <https://mailman.irtf.org/mailman/options/crypto-panel>, <mailto:crypto-panel-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/crypto-panel/>
List-Post: <mailto:crypto-panel@irtf.org>
List-Help: <mailto:crypto-panel-request@irtf.org?subject=help>
List-Subscribe: <https://mailman.irtf.org/mailman/listinfo/crypto-panel>, <mailto:crypto-panel-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Nov 2023 20:33:49 -0000

Ok, I went through the draft, it mostly looks good.  I do have the following comments:

- You define the ciphersuites "AES-256-SIV" and "AES-512-SIV".  However, RFC 5297 has AEAD_AES_SIV_CMAC_256 and 512 - are those the same thing?  If so, you might want to make the names consistent.

- Calling it 'deterministic' feels wrong - the encryptor injects randomness (by his part of the ephemeral key exchange).  I realize why you call it deterministic (because the symmetric part is); I would consider some discussion of this.

	- Because of this, much of the discussion that you put about deterministic encryption being safe if the message space is "random enough" can be replaced by the simple requirement that the encryptor always selects his point randomly.

- In section 1.2 (addressing lossy networks), you said that one of the things you did to address that is to make things deterministic.  Actually, you didn't do that for that reason - instead, you did it to save a few bytes on the wire.

Typos:

- Section 1.2: "impracticle" -> "impractical"

- Section 1.2.1: "pre-peneded" -> "prepended"

- Section 1.2.1: "Determinsitic" -> "Deterministic"

> -----Original Message-----
> From: Scott Fluhrer (sfluhrer)
> Sent: Thursday, November 16, 2023 10:21 AM
> To: Alexey Melnikov <alexey.melnikov@isode.com>; crypto-panel@irtf.org
> Cc: daniel.harkins@hpe.com; cfrg-chairs@ietf.org
> Subject: RE: [Crypto-panel] Request for review: draft-irtf-cfrg-dnhpke-03
> 
> I'll take a look at it...
> 
> > -----Original Message-----
> > From: Crypto-panel <crypto-panel-bounces@irtf.org> On Behalf Of Alexey
> > Melnikov
> > Sent: Thursday, November 16, 2023 9:53 AM
> > To: crypto-panel@irtf.org
> > Cc: daniel.harkins@hpe.com; cfrg-chairs@ietf.org
> > Subject: [Crypto-panel] Request for review: draft-irtf-cfrg-dnhpke-03
> >
> > Dear Crypto Panel Experts,
> >
> > The chairs would like to ask the Crypto Panel to provide another
> > review for draft-irtf-cfrg-dnhpke-03, "Deterministic Nonce-less Hybrid
> > Public Key Encryption"
> > (https://datatracker.ietf.org/doc/draft-irtf-cfrg-dnhpke/). In
> > particular, chairs would like to understand from the review whether
> > the provided extension to HPKE is reasonable and whether it is well
> specified.
> >
> > Best Regards,
> > Alexey (on behalf of the CFRG Chairs)
> >
> > _______________________________________________
> > Crypto-panel mailing list
> > Crypto-panel@irtf.org
> > https://mailman.irtf.org/mailman/listinfo/crypto-panel