Re: [Crypto-panel] Request for review: CPace

Karthikeyan Bhargavan <karthikeyan.bhargavan@inria.fr> Wed, 11 October 2023 09:00 UTC

Return-Path: <karthikeyan.bhargavan@inria.fr>
X-Original-To: crypto-panel@ietfa.amsl.com
Delivered-To: crypto-panel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74DF1C14F749 for <crypto-panel@ietfa.amsl.com>; Wed, 11 Oct 2023 02:00:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.102
X-Spam-Level:
X-Spam-Status: No, score=-2.102 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=inria.fr
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ANd7bg2PkLAG for <crypto-panel@ietfa.amsl.com>; Wed, 11 Oct 2023 02:00:15 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72C9DC15108B for <crypto-panel@irtf.org>; Wed, 11 Oct 2023 02:00:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=inria.fr; s=dc; h=from:message-id:mime-version:subject:date:in-reply-to:cc: to:references; bh=42+L74n7WzLS1ody4Oj0T73cnoQLx+qk36iU6ab46Uk=; b=CzSu6o7Vi9xi2SayOUsRgs8nBBbJ4C30afOmtU+kRG5NcFADhGkrl46m g+s8q3rypisJ0Wx3EJSeBkKoZB1s/a8UHGO5q/1ITFhdYWDcxC0gq21Io 53BdXZAsvm1OzhL/xOExzuREOoxieCZzUFiQdZvIk5f2B0nQYjG0wLTVS o=;
Authentication-Results: mail3-relais-sop.national.inria.fr; dkim=none (message not signed) header.i=none; spf=SoftFail smtp.mailfrom=karthikeyan.bhargavan@inria.fr; dmarc=fail (p=none dis=none) d=inria.fr
X-IronPort-AV: E=Sophos;i="6.03,214,1694728800"; d="scan'208,217";a="68378553"
Received: from 249.28.30.93.rev.sfr.net (HELO smtpclient.apple) ([93.30.28.249]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 11 Oct 2023 11:00:13 +0200
From: Karthikeyan Bhargavan <karthikeyan.bhargavan@inria.fr>
Message-Id: <D94E0BE0-0C11-41B8-9479-F4A355B54164@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_2EA656D0-AEDC-4F18-8818-E21CF19A0614"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6\))
Date: Wed, 11 Oct 2023 11:00:03 +0200
In-Reply-To: <CAMr0u6nu-mC0hQKQVBTwKB8jW=6Rn9eiibU-FN+p6ntJNwittQ@mail.gmail.com>
Cc: crypto-panel@irtf.org, Bjoern Tackmann <bjoern.tackmann@ieee.org>, Karthikeyan Bhargavan <karthik.bhargavan@gmail.com>, Thomas Pornin <thomas.pornin=40nccgroup.com@dmarc.ietf.org>, Thomas Pornin <thomas.pornin@nccgroup.com>, draft-irtf-cfrg-cpace@ietf.org, cfrg-chairs@ietf.org
To: "Stanislav V. Smyshlyaev" <smyshsv@gmail.com>
References: <CAMr0u6kAW_rEK3_7Y64nU=-DP=7JjXM-oiX1XB+_973yP+pf0w@mail.gmail.com> <CAMr0u6nPOnUDCvfZ7mM_8nYWcmbp3nt+jp1O7tAP7byMWWWgWw@mail.gmail.com> <CAMr0u6nu-mC0hQKQVBTwKB8jW=6Rn9eiibU-FN+p6ntJNwittQ@mail.gmail.com>
X-Mailer: Apple Mail (2.3731.700.6)
Archived-At: <https://mailarchive.ietf.org/arch/msg/crypto-panel/rl1qmD3BSmVCGJRq-XXc8J7Yz_Y>
Subject: Re: [Crypto-panel] Request for review: CPace
X-BeenThere: crypto-panel@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Crypto Review Panel review coordination <crypto-panel.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/crypto-panel>, <mailto:crypto-panel-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/crypto-panel/>
List-Post: <mailto:crypto-panel@irtf.org>
List-Help: <mailto:crypto-panel-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/crypto-panel>, <mailto:crypto-panel-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Oct 2023 09:00:20 -0000

Ok. I will put this on my stack.

All my best,
Karthik

> On 11 Oct 2023, at 10:56, Stanislav V. Smyshlyaev <smyshsv@gmail.com> wrote:
> 
> Dear Bjoern, Karthik and Thomas, 
> 
> The chairs would like to ask each of you to review the CPace draft, "CPace, a balanced composable PAKE", draft-irtf-cfrg-cpace-10 (https://datatracker.ietf.org/doc/draft-irtf-cfrg-cpace/).
> 
> There were a lot of reviews of the protocol and the early versions of the draft, see https://github.com/cfrg/pake-selection
> There were several important questions in those reviews which had to be addressed during the evolution of the draft in CFRG: some of them are underlined in the following paper: https://eprint.iacr.org/2021/839.pdf – we would like to ask you to pay special attention to these issues.
> 
> It would be great if you could do it before the middle of November.
> 
> Best regards,
> Stanislav (for CFRG chairs) 
> 
> On Thu, Oct 5, 2023 at 10:51 AM Stanislav V. Smyshlyaev <smyshsv@gmail.com <mailto:smyshsv@gmail.com>> wrote:
>> Hi all,
>> 
>> We still need reviewers (three or four) for the CPace draft.
>> 
>> Since CPace was a winner of the PAKE selection process, we have to be 100% sure that all concerns have been properly addressed.
>> 
>> Bjoern, Russ, Karthik, we will be happy to receive reviews from you (taking into account your reviews provided during the PAKE Selection process).
>> 
>> Chloe, Julia, Jean-Philippe, Scott, if some of you could review the CPace draft, despite the fact that you've just reviewed the OPAQUE draft (thanks a lot once again for this!), that would be amazing as well.
>> 
>> Best regards,
>> Stanislav (for CFRG chairs)
>> 
>> On Mon, Sep 25, 2023 at 3:17 PM Stanislav V. Smyshlyaev <smyshsv@gmail.com <mailto:smyshsv@gmail.com>> wrote:
>>> Dear Crypto Panel Experts,
>>> 
>>> The chairs would like to ask the Crypto Panel to provide three (or more) reviews for the CPace draft, "CPace, a balanced composable PAKE", draft-irtf-cfrg-cpace-10 (https://datatracker.ietf.org/doc/draft-irtf-cfrg-cpace/).
>>> 
>>> The CPace protocol was selected as a result of the PAKE selection process in CFRG (as well as the OPAQUE protocol which has recently been reviewed by the Panel). 
>>> 
>>> There were a lot of reviews of the protocol and the early versions of the draft, see https://github.com/cfrg/pake-selection
>>> There were several important questions in those reviews which had to be addressed during the evolution of the draft in CFRG: some of them are underlined in the following paper: https://eprint.iacr.org/2021/839.pdf
>>> 
>>> Hence we would like to ask the reviewers to pay a lot of attention to reviewing this draft, trying to take into account as many considerations provided in the previous reviews as possible.
>>> 
>>> Stanislav (on behalf of the CFRG Chairs)