[Lwip] draft-ietf-lwig-curve-representations-13

Göran Selander <goran.selander@ericsson.com> Fri, 06 November 2020 16:20 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: lwip@ietfa.amsl.com
Delivered-To: lwip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D3BB3A07EA; Fri, 6 Nov 2020 08:20:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JKLnmBUdCG-K; Fri, 6 Nov 2020 08:20:51 -0800 (PST)
Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-eopbgr50071.outbound.protection.outlook.com [40.107.5.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1AC53A0A47; Fri, 6 Nov 2020 08:19:35 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ZH0WVdrUOQSPux/R6VFKbZkg5KRWDzFoCKCkQ418m4z8KKPG+K5xsiz7XbOhJ75w3yNvGP22n3Qwf5BQDygP7PjmQxo0/3cXLXUK10dbfVuGFiu3L4cYAQi3z5bdOdXyEJl4zIQ/2Bgh6JqTISwXg3BMz+NiOBxTKpL8QQ3i7pR+zqnnOltgkVNN+wev6M2bTg1ugT6pOr6AkWDiPuM1jvxgHzB4Ee7gCsNBvKDdNQAJDjDTkraCJA0AzF+0CqUjLVhe676XtPm3AoHV0SLp+Crk9/+YKax3ZNMpCtDfpiv7xwem50G1SJVYCmO7TRRjezKGFl7z0sFY23+y628BAA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=OYcX0LwiPWDgM6jptZmnBHReYqkbb0JN7AXfLViY+nY=; b=T4eoz5pyFZuYqgTIvDNXy52kqInVUBRcujPxch0SgcaZhszMxEAwtcWTjgK1Nq4w1LrHy2MfCOa2kJcRv/tg7cLi2sa14WkckdPl4CXjGyJJgfCDOePzWdMPl7NvF/dIi857xPuvd1vwgqomhxzH7WJYpiK0C8Y3X7UTc2sw0T3jZCEVdA39HX8yKpPxjZ5GUup08zpdc8xXzi45PsHD44XnSAtiPQqZUBkERdzzqnzW7AbUZ8iPLQc7KPo1yMK4yjroxECBEuB2LqCiSluRafAWTOgIiVO4aajrVYr+m++gZVZM16R5j2hMUvhfYSsmlPG/BFver6rreIjM3QjG+A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=OYcX0LwiPWDgM6jptZmnBHReYqkbb0JN7AXfLViY+nY=; b=dx4ad2o4U3c7BJ4HturvBL1dLvrBYhslZ59Hrgli44lbunKmz7uVhUBwnvF6zvoy/joJA26b8g2IAo78Q1gwZr3pMh+iD6i64NlrNgqrexphjyeoPWspoMl3zQhfvmw5seUTsiG2NeQoMwiwp+sNBHN9udg9a+YEL4R2uTQGOLs=
Received: from HE1PR0702MB3674.eurprd07.prod.outlook.com (2603:10a6:7:82::14) by HE1PR0701MB2747.eurprd07.prod.outlook.com (2603:10a6:3:99::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3541.10; Fri, 6 Nov 2020 16:19:33 +0000
Received: from HE1PR0702MB3674.eurprd07.prod.outlook.com ([fe80::c99c:9978:10bb:e231]) by HE1PR0702MB3674.eurprd07.prod.outlook.com ([fe80::c99c:9978:10bb:e231%3]) with mapi id 15.20.3541.015; Fri, 6 Nov 2020 16:19:33 +0000
From: Göran Selander <goran.selander@ericsson.com>
To: "lwip@ietf.org" <lwip@ietf.org>, "cose@ietf.org" <cose@ietf.org>
Thread-Topic: draft-ietf-lwig-curve-representations-13
Thread-Index: AQHWtEV8sjA+ZZRJFUGqrpJal9HOIQ==
Date: Fri, 06 Nov 2020 16:19:33 +0000
Message-ID: <HE1PR0702MB36745AEC1C6E929CA4D9A1C7F4ED0@HE1PR0702MB3674.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [83.251.145.232]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 2d883b45-ffae-4c4a-f74d-08d8826fbf12
x-ms-traffictypediagnostic: HE1PR0701MB2747:
x-microsoft-antispam-prvs: <HE1PR0701MB2747C0B2D0CA58847E847B0EF4ED0@HE1PR0701MB2747.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 5taRm1Rkkr8anPQjpQaBFhvChi3kasKT/jm7eZPrs5Ccoa845sDVM5smOS6WcMI4ncde/CC6IE2m1VtiIt86GaALZYwVIvlZUMtPFB092UaLVkjJCNHrA8Eqo8a/3Hf7rRpQCgpSmTucfO7G0+FydZ36miXEcBqHKu12S4+D8UsQ3MD074P3VPGx+kBikVtTLl35jPSuTBSz698JgR+8Lj9BZETlBdc+sN670E4a/x0xpbT+IkWR6HYR9qSpBHUdiWWrk6dTby7z4sUALEjt+eCoESZR/y5Io5qMr0oppsPuKVxQ81RcxIGlwV4JdeqX
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0702MB3674.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(376002)(346002)(396003)(366004)(136003)(39860400002)(7696005)(5660300002)(9686003)(52536014)(478600001)(55016002)(64756008)(186003)(71200400001)(66574015)(66476007)(450100002)(316002)(66556008)(110136005)(2906002)(86362001)(26005)(4743002)(66446008)(33656002)(83380400001)(6506007)(76116006)(66946007)(8676002)(8936002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: RHPDGSQlr9Fu+toVHBV+yxoVm2RV1LWu27UAY+XzpaN0mquhLsrvQNlAqjYO6cD/PkIhpebOSDbU4X/W8XMP5lVK8QtQQhY991shHs1ox0rI8X++/t+3u9q1HE83XUZ1qpLqNSGgDbXIbuBMA6xRFhy/qF9i0Hh5QcQDJeTNDeVGWFSzGRxnFVJD1j6nQFX24Rs1SjIDZDASs1LEVultu38pZqqDzEDIiBzDhg7t5iFaJW6xzfe2wPB20JVS4xdGGDTNgax+3iXMJWPBlUwDfyHOYNNLWeRmhFFOm3L0XYYVJyN2RRiPj5M+2MxjHKvsvm8u77N4qTPpu813L42Y9C+NyM/Q6aJuflOkFfHK1E349F28auToRzfQ29/C4zaRzlCqKkkhNETvBEhA5SZjglHPlhxv7OqRiz+S8hxj/toPlBXYoOlkoPaFj/ZNcdS3egDBEhpjAcl8M12I/kTPRXJIn2QvdwDxdgROJs8APDF56sM8GOoUZ8DHFOJfgFeerTNZumvXixr3Sl+SZvXYTg+Htz5CO0L2efLhOujnCucKMdHpakiR4SpkeQXMkxNuFUDpNjrUbRdLG81PFhOMyD+XRY9EkHXayNVHEj2coM0c2gD7lLPaZRMbeOZH2wphohaVNhrPRLeZ6xlSVvdR8g==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_HE1PR0702MB36745AEC1C6E929CA4D9A1C7F4ED0HE1PR0702MB3674_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0702MB3674.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2d883b45-ffae-4c4a-f74d-08d8826fbf12
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Nov 2020 16:19:33.0357 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: bbB8M4Hw6GIJD+9zb5DQJb/ZOX/7iz8BUdxTkJAGSCL7G+UcSypIeZFP/ROqpKKPdnGhpdBjaL1bSHBZ6gr8IhrUG9yQCaNtTbY2IEhdlCw=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2747
Archived-At: <https://mailarchive.ietf.org/arch/msg/lwip/5PzSpQy1468XQR5MD2x-A8f_Kh4>
Subject: [Lwip] draft-ietf-lwig-curve-representations-13
X-BeenThere: lwip@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Lightweight IP stack. Official mailing list for IETF LWIG Working Group." <lwip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lwip>, <mailto:lwip-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lwip/>
List-Post: <mailto:lwip@ietf.org>
List-Help: <mailto:lwip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lwip>, <mailto:lwip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Nov 2020 16:20:53 -0000

Hi,

Apologies for cross-posting LWIG and COSE. I had a brief look at draft-ietf-lwig-curve-representations-13 and noticed it registers a lot of new COSE (and JOSE, PKIX, and CMS) algorithms. Has this draft been discussed in COSE (JOSE/CURDLE)? If not, perhaps it should be before being progressed?



  *   The draft needs to manage the overlap with NIST SP 800-186, which should be referenced and mappings, name of curves, etc. aligned. The draft defines Wei25519 and Wei448. It is unclear if these are identical to W-25519, W-448 as defined in NIST SP 800-186. We probably would not want two slightly different definitions and/or names, multiple COSE code points, etc.



  *   The draft registers the COSE algorithm "ECDSA25519" as "ECDSA with SHA-256 and curve Wei25519". That is not how the other COSE signature algorithms work. They work like PKIX where the curve is given by the public key. Also, why cannot W-25519 be used with the existing ES256 signature algorithm?


  *   The draft registers the COSE algorithm "ECDH25519". There are no COSE ECDH algorithms for P-256, why is an ECDH algorithm for W-25519 be needed?

Other questions. I may have missed it, but


  *   is it described what are the expected security properties of ECDSA25519 (including mapping) compared to Ed25519? For example w.r.t. side channel attacks?



  *   has any performance measurements been made comparing ECDSA25519 (including mapping) and Ed25519?



  *   similar questions on security and performance with Wei25519.-3 instead of Wei25519. If I understand right, the former mapping is not reversible, but could benefit from optimized code with hardcoded domain parameters.



  *   ANSI X9.62-2005 was withdrawn in 2015 and is behind a paywall, is this reference necessary?


Göran