Re: [jose] Support PQC in JOSE

Antonio Sanso <asanso@adobe.com> Mon, 01 February 2016 16:20 UTC

Return-Path: <asanso@adobe.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E76D1B3219 for <jose@ietfa.amsl.com>; Mon, 1 Feb 2016 08:20:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.453
X-Spam-Level:
X-Spam-Status: No, score=0.453 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FRT_ADOBE2=2.455, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4fiEZ6zRMobw for <jose@ietfa.amsl.com>; Mon, 1 Feb 2016 08:20:10 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1bon0633.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::1:633]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D0C981B3218 for <jose@ietf.org>; Mon, 1 Feb 2016 08:20:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=adobe.com; s=selector1; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=/a2L1zhQLsfnUiYpKIThcsxeNmJprONaaO6retX5d7Q=; b=bHzsSqJYk9PJvl2bYjiQs2wYjsm8Nc+sIXxbIV0NV/1tF5M0g3yBV4X9VCu0i8U5g1MPA3sxQkbe3RuqRmjEPwKYH0QDM7TOqR8aT0qZnlKXT8yie4m5dpMhe+2itJaA54mLCQTp5yyowGs3nwyp/6WB8F1wHCBpZ6Vx2vO+QHs=
Received: from BY1PR0201MB1030.namprd02.prod.outlook.com (10.161.203.148) by BY1PR0201MB1031.namprd02.prod.outlook.com (10.161.203.149) with Microsoft SMTP Server (TLS) id 15.1.390.13; Mon, 1 Feb 2016 16:19:53 +0000
Received: from BY1PR0201MB1030.namprd02.prod.outlook.com ([10.161.203.148]) by BY1PR0201MB1030.namprd02.prod.outlook.com ([10.161.203.148]) with mapi id 15.01.0390.019; Mon, 1 Feb 2016 16:19:53 +0000
From: Antonio Sanso <asanso@adobe.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Thread-Topic: [jose] Support PQC in JOSE
Thread-Index: AQHRXNLNeRZx+kc1Wky9E5QMX6Y7B58W+dWAgABZToCAABOigA==
Date: Mon, 01 Feb 2016 16:19:53 +0000
Message-ID: <6E42F709-2273-42BE-874D-7020D3A240A4@adobe.com>
References: <69E1ACAC-AAEE-49D8-953F-FAE3649EB3D2@adobe.com> <30A36E2A-2263-4F5A-A093-3D54B3842E8F@adobe.com> <56AF7B9D.5020807@cs.tcd.ie>
In-Reply-To: <56AF7B9D.5020807@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: cs.tcd.ie; dkim=none (message not signed) header.d=none;cs.tcd.ie; dmarc=none action=none header.from=adobe.com;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [193.104.215.11]
x-microsoft-exchange-diagnostics: 1; BY1PR0201MB1031; 5:wPMg2F/OLSqQVPmNmgtm7ttMind9rb2tPIKGxCnvGd+4vRa7rvGPX4S+1xOnLDhYC+wB3fW9mz7ssZLEcw5REcURN/XrpM17m7Rvw/5yHMAU1zOJ39ITJv6sx4wqD+V+i6FVQw2c0UC6w2YFcIRNCw==; 24:/ifcRlEf55DPCvl2QBY6sGOpAem6gu94H6lBhmwQDiC8cySKcFt7NuG0KtWn4/806K5CH1iM3MhRO6bgG6Qad7Ni/p+ddlrmWO2dV5Rg6X4=
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(42139001); SRVR:BY1PR0201MB1031;
x-ms-office365-filtering-correlation-id: 83944109-2eb6-4e5f-6097-08d32b23845e
x-microsoft-antispam-prvs: <BY1PR0201MB103149F1544803E6C0F90B00D9DE0@BY1PR0201MB1031.namprd02.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(32856632585715)(22321516928792);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(61426038)(61427038); SRVR:BY1PR0201MB1031; BCL:0; PCL:0; RULEID:; SRVR:BY1PR0201MB1031;
x-forefront-prvs: 0839D067E7
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(24454002)(377454003)(479174004)(2900100001)(2950100001)(5002640100001)(15975445007)(189998001)(11100500001)(3470700001)(5008740100001)(36756003)(77096005)(40100003)(5004730100002)(3846002)(102836003)(3280700002)(3660700001)(19580395003)(19580405001)(1220700001)(586003)(1096002)(4326007)(2906002)(76176999)(87936001)(92566002)(82746002)(122556002)(54356999)(10400500002)(50986999)(66066001)(83716003)(110136002)(5001960100002)(99286002)(86362001)(106116001); DIR:OUT; SFP:1101; SCL:1; SRVR:BY1PR0201MB1031; H:BY1PR0201MB1030.namprd02.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <CF5A22E25EB44648AB3B960FB6FE205F@namprd02.prod.outlook.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: adobe.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Feb 2016 16:19:53.1499 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: fa7b1b5a-7b34-4387-94ae-d2c178decee1
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY1PR0201MB1031
Archived-At: <http://mailarchive.ietf.org/arch/msg/jose/muTVBiCqXSs0Wg2UzRPGQXcQ13Q>
Cc: "jose@ietf.org" <jose@ietf.org>
Subject: Re: [jose] Support PQC in JOSE
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Feb 2016 16:20:12 -0000

thanks. It sounds reasonable.

I will subscriber to CFRG mailing list so .

regards

antonio

On Feb 1, 2016, at 4:37 PM, Stephen Farrell <stephen.farrell@cs.tcd.ie> wrote:

> 
> The IRTF's CFRG [1] are at the beginning of considering PQC
> so I'd say discussion would be much better off there and not
> (yet) in the IETF. IMO none of the PQC schemes are ready for
> prime-time right now, so CFRG is a much better venue.
> 
> Cheers,
> S.
> 
> [1] https://irtf.org/cfrg
> 
> On 01/02/16 09:50, Antonio Sanso wrote:
>> ops it look like I kind of fat fingered , meant 
>> 
>> A quantum computer will break totally this (thanks to Shor's algorithm).
>> 
>> On Feb 1, 2016, at 10:27 AM, Antonio Sanso <asanso@adobe.com> wrote:
>> 
>>> hi *,
>>> 
>>> I know that this might sounds a bit crazy but I think that is time to kind of think about Post Quantum Cryptography (and JOSE should not be left out).
>>> But let me rewind a bit. 
>>> According to the last research (done from IBM et al) and NSA suggestions, having a quantum computer is “only” 8/15 years from now (maybe earlier)
>>> Taking as example JWS it support RSA signature. A quantum computer will break computer will break totally this (thanks to Show algorithms).
>>> Thinking about start to expand JWS specification to use some of the PQC is not so inimmaginable IMHO.
>>> For example having JWS supporting Hash based signatures would be a great move (always IMHO :)) for JOSE and JWS. 
>>> 
>>> WDYT?
>>> 
>>> antonio
>>> 
>>> P.S. a great post about Hash based signatures and Merkle tree is at https://www.imperialviolet.org/2013/07/18/hashsig.html
>>> _______________________________________________
>>> jose mailing list
>>> jose@ietf.org
>>> https://www.ietf.org/mailman/listinfo/jose
>> 
>> _______________________________________________
>> jose mailing list
>> jose@ietf.org
>> https://www.ietf.org/mailman/listinfo/jose
>>