Re: [jose] Fwd: New Version Notification for draft-reddy-cose-jose-pqc-kem-00.txt

Orie Steele <orie@transmute.industries> Tue, 05 March 2024 13:32 UTC

Return-Path: <orie@transmute.industries>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2CEA4C14F69D for <jose@ietfa.amsl.com>; Tue, 5 Mar 2024 05:32:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=transmute.industries
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sqtn0FNY7fZq for <jose@ietfa.amsl.com>; Tue, 5 Mar 2024 05:32:30 -0800 (PST)
Received: from mail-yw1-x1136.google.com (mail-yw1-x1136.google.com [IPv6:2607:f8b0:4864:20::1136]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B456C14E515 for <jose@ietf.org>; Tue, 5 Mar 2024 05:32:30 -0800 (PST)
Received: by mail-yw1-x1136.google.com with SMTP id 00721157ae682-60983233a0dso51072537b3.3 for <jose@ietf.org>; Tue, 05 Mar 2024 05:32:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=transmute.industries; s=google; t=1709645549; x=1710250349; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=5ARAN7iittrG2Lz+qxJ00Y4lqgTsjo/V8QCbh02SyDw=; b=ATPsExGcQd2fsYQR2pxYInZdxVMSjnCY9EgY/j3QPDq5LOKDWKO/rJAnDUoGt7Zy4F H5Xyq5RsjVN6u5MTBXQdf58Ug422TcZ7326fGpVHyrOi30XLdRU6RQ4xYC6Ww1kdB/1v f0WvTkb2XzeZ5r2iblrL/s73ecnXq87KSV8U0VQt220LJCqEF2DkvXb4qe9R3wDiYc9z 6baiP3luNveTIfO9gHutKHDFaa0KEtSwfpxhmSttuz4SixXY0tgXpoFsuw7+7MWr1330 bDYp9v0L6RHf8HZURTkKUEREdTz2COrVyEa8j2f2LNEAkRk73+zNxtp4OyY7nClurllq Tpng==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1709645549; x=1710250349; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=5ARAN7iittrG2Lz+qxJ00Y4lqgTsjo/V8QCbh02SyDw=; b=AEjUI5VApDXhsVFlUJ8bq74gvoARf6KGFUuFOym3oVryBnGBKD5z7N8Uf78hUQkRUJ uZmT+F3DmLv1/R8H9RzJccR/AO/wFQ0ROMtmNk/ayByRW5YPM2gRoQsa0Kmqqmc1j73i JdYjVXmXVWbNy3kVx9n/29e4YZVk71nuKxMYn2y9HqFOk82aeDZic5SouOaZkvXngb7w bCTXCljyRJ3P3YyJVaDdSDFTlkOYkHjJ7M9sjngqJ3p2rWsv2VRE21/kPvIPSeelMD8Z T++BEZh701TooNp0h2lhQYR49nkHubDaqYLMZOQusA5JLFS+RkW2Dqm2UQoiH2rRXfyj IZcg==
X-Forwarded-Encrypted: i=1; AJvYcCX2qrLnSR+vQvHjUQ3QmZwOWMFAhs2sPwffCppNlRPPFczK4QYXsRxB1ZikVtu+xS9E2CrwRNOwcYNYEYiO
X-Gm-Message-State: AOJu0YztEfyPP3l8UMQB2xS8ua+V1EtMnUoHE4DX6a4coOfJV8RkT5wV B0Qe5kVSeVY3ronp8K+wL9tUgY7Sqbvhpe/wOwuj+KpSuelg04okhrsJMVsLL4S3tBFMHymDFYB gFnmNWJujS4fvIePJl7cyFbmo8qyQvPWHYYu7xv1k1DpiyYyJmj8=
X-Google-Smtp-Source: AGHT+IHnl+02AcbeffEc/Hf5Om1dxUv1vxaKO04UFHmzhybjAyEG25W4stMqP2grxKQcdC/VWZMsM7ezvFEdEOK8vbU=
X-Received: by 2002:a25:ab47:0:b0:dc6:c2b2:c039 with SMTP id u65-20020a25ab47000000b00dc6c2b2c039mr8551437ybi.41.1709645549092; Tue, 05 Mar 2024 05:32:29 -0800 (PST)
MIME-Version: 1.0
References: <170944215832.65165.15558599263256086018@ietfa.amsl.com> <CAFpG3gdGiw2wap8C1H+AOWvEn1ewSjmtBmghKKAvNBmXnDmoYg@mail.gmail.com>
In-Reply-To: <CAFpG3gdGiw2wap8C1H+AOWvEn1ewSjmtBmghKKAvNBmXnDmoYg@mail.gmail.com>
From: Orie Steele <orie@transmute.industries>
Date: Tue, 05 Mar 2024 07:32:17 -0600
Message-ID: <CAN8C-_KZifohssn3WoZa6Qn3QMeh0YMya6c8RGa1ZieWgRY9=A@mail.gmail.com>
To: tirumal reddy <kondtir@gmail.com>
Cc: cose <cose@ietf.org>, JOSE WG <jose@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a5646e0612e9dfed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/xhEK2Lg09gabVjnaHwaEcmVPmYs>
Subject: Re: [jose] Fwd: New Version Notification for draft-reddy-cose-jose-pqc-kem-00.txt
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Mar 2024 13:32:34 -0000

Draft looks very familiar after have spent so much time with HPKE.

And it would be nice to have at least one pq encryption suite on track for
standardization.

Having different direct mode alg values for ML-KEM and HPKE that are both
basically telling you to look an enc... Is wasting registry space.

alg: dir, is sufficient.

The documents that register the new enc modes can explain why.

I think it would be better to see ML-KEM suites in HPKE, instead of seeing
duplicates.

There will also be different security issues, without the HPKE context and
key commiting, etc...

There will be worse interop with 2 ways to do the same things.

With hydrids on the horizon... it's a mistake to register hydrids twice...
Once for HPKE and once for standalone.

I think we should use HPKE until there is reason not to use it.

Is this draft motivated by implementers who could not use HPKE?

Are there critical use cases that multiple vendors need to support that
only work without using HPKE?

OS

On Tue, Mar 5, 2024, 5:34 AM tirumal reddy <kondtir@gmail.com> wrote:

> We have published a new draft
> https://www.ietf.org/archive/id/draft-reddy-cose-jose-pqc-kem-00.html,
> that describes the conventions for using Post-Quantum Key Encapsulation
> Mechanisms (PQ-KEMs) within JOSE and COSE.  Although this mechanism could
> be used with any PQ-KEM, this document focuses on Module-Lattice-based Key
> Encapsulation Mechanisms (ML-KEMs).
>
> Comments and Suggestions are welcome.
>
> -Tiru
>
> ---------- Forwarded message ---------
> From: <internet-drafts@ietf.org>
> Date: Sun, 3 Mar 2024 at 10:32
> Subject: New Version Notification for draft-reddy-cose-jose-pqc-kem-00.txt
> To: Tirumaleswar Reddy.K <kondtir@gmail.com>, Aritra Banerjee <
> aritra.banerjee@nokia.com>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>,
> Hannes Tschofenig <hannes.tschofenig@gmx.net>
>
>
> A new version of Internet-Draft draft-reddy-cose-jose-pqc-kem-00.txt has
> been
> successfully submitted by Tirumaleswar Reddy and posted to the
> IETF repository.
>
> Name:     draft-reddy-cose-jose-pqc-kem
> Revision: 00
> Title:    Post-Quantum Key Encapsulation Mechanisms (PQ KEMs) for JOSE and
> COSE
> Date:     2024-03-03
> Group:    Individual Submission
> Pages:    16
> URL:
> https://www.ietf.org/archive/id/draft-reddy-cose-jose-pqc-kem-00.txt
> Status:   https://datatracker.ietf.org/doc/draft-reddy-cose-jose-pqc-kem/
> HTML:
> https://www.ietf.org/archive/id/draft-reddy-cose-jose-pqc-kem-00.html
> HTMLized:
> https://datatracker.ietf.org/doc/html/draft-reddy-cose-jose-pqc-kem
>
>
> Abstract:
>
>    This document describes the conventions for using Post-Quantum Key
>    Encapsulation Mechanisms (PQ-KEMs) within JOSE and COSE.
>
> About This Document
>
>    This note is to be removed before publishing as an RFC.
>
>    Status information for this document may be found at
>    https://datatracker.ietf.org/doc/draft-reddy-cose-jose-pqc/.
>
>    Discussion of this document takes place on the cose Working Group
>    mailing list (mailto:cose@ietf.org), which is archived at
>    https://mailarchive.ietf.org/arch/browse/cose/.  Subscribe at
>    https://www.ietf.org/mailman/listinfo/cose/.
>
>
>
> The IETF Secretariat
>
>
> _______________________________________________
> jose mailing list
> jose@ietf.org
> https://www.ietf.org/mailman/listinfo/jose
>