[openpgp] Re: WG: BSI view on KEM combiners
Daniel Huigens <d.huigens@protonmail.com> Wed, 04 September 2024 08:54 UTC
Return-Path: <d.huigens@protonmail.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A446CC18DB92 for <openpgp@ietfa.amsl.com>; Wed, 4 Sep 2024 01:54:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=protonmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BsIFPSKGyvPh for <openpgp@ietfa.amsl.com>; Wed, 4 Sep 2024 01:54:00 -0700 (PDT)
Received: from mail-40134.protonmail.ch (mail-40134.protonmail.ch [185.70.40.134]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53F7AC16943F for <openpgp@ietf.org>; Wed, 4 Sep 2024 01:54:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1725440038; x=1725699238; bh=A+eeTYM57xgjE7B7YDGGR8HcDgUkD2PGciiLYhf0npw=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=IjXpxym2a2Y7BFB5x8acmb2nU6pcrK3z8a5JFNaCh2OD1SYP7K//4eI7+9CKVgKvq ZjI/xzx9LvV1+UeN+hiMiaiyVSbI71DwfVXWaFoAUeP1wT4YdEZ5Dd4RwMXfe394+t LGxBWKVT91Jnpbg5akpsakK+KpVl5rksknKMmXzuWCRMoodYUt+SuP1W2/pkihzgWw r0a/6WyqXoKr6nR5F6q8xF0qmpMBUH1bnYGV8MxwDLhEPrK4lDPImza0Ggok3KQOnB KPCeXNlKWuk0Z4GZtZH7suZFUfhks3iCHP9jk468l5Hmj9IyxxsN1l925mOLWmyQnc ByYb4xw7NNMmA==
Date: Wed, 04 Sep 2024 08:53:55 +0000
To: Falko Strenzke <falko.strenzke@mtg.de>
From: Daniel Huigens <d.huigens@protonmail.com>
Message-ID: <4LUdegqW5U4r-Y2qEU9l9ns8HQrhT-IM8F04GHYiiEdvaJlg_8YZwcdMZCN3IorYyAWUrKFJwEJR5BHVxdBe0mRC4BvWYop5yN3utWevzF8=@protonmail.com>
In-Reply-To: <2940b781-52de-42c8-aef9-78d6cb970b08@mtg.de>
References: <5681EF18-EB2C-49FD-A3B0-735C6542725D@amongbytes.com> <334c62d3389847e0b345269b54af639c@bsi.bund.de> <vD0ZBoCGhXaNfOahJkzFeuXbrf9UMnGrJ9SvapIzYNjqIRtNBkAJK-Mj0UWqsMj5gfuIxwtitmIOKJYpQx8lnAAlbYerdG_ZxxS0OAlBVhE=@protonmail.com> <845c1aeb783048a6a25329f3fe55f708@bsi.bund.de> <bW9aKCOk9HHb5xrHdoUlRC2aCpmZ6ZeReYYFFtf4P7TrbqN_q4Pnn-ibbWs9uehRzm6i_tverpxR0yxd3gxWhK8_w-s8lOx1I4B6Gf64Qyg=@protonmail.com> <df35291f726b48c8b37bec61bcdeb16a@bsi.bund.de> <uSMSFmH_6jyl4mrcWthHS1_eJjjo0FaROQU4BDyy3oRlH-l8qtjgoOO3KdbkvU4K0O7fdNaxAMuth8sAPtN2aOpi-bK_eVijo56xnPnnvcQ=@protonmail.com> <2940b781-52de-42c8-aef9-78d6cb970b08@mtg.de>
Feedback-ID: 2934448:user:proton
X-Pm-Message-ID: c601941e527148ab3ff2369f48881513d05d4aee
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="b1_MYAnhWZHoyUNjvSrx3kWQC0gI4LsfGKEwfZFxXJ4hc"
Message-ID-Hash: YAGTUV2KVW2ZD6GZ5QLEIMVDFOCDSUBU
X-Message-ID-Hash: YAGTUV2KVW2ZD6GZ5QLEIMVDFOCDSUBU
X-MailFrom: d.huigens@protonmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "Ehlen, Stephan" <stephan.ehlen=40bsi.bund.de@dmarc.ietf.org>, "openpgp@ietf.org" <openpgp@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: WG: BSI view on KEM combiners
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/3iiybm3MWhA6xSo6EvCQ7MDh75M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi Falko, On Wednesday, September 4th, 2024 at 07:00, Falko Strenzke wrote: >> > > Britta's concerns were formulated with respect to cryptographic mechanisms, while yours seem to be entirely with respect to parameter choices. And I cannot really see how CFRG could help us regarding the choice of parameters. Pedantically speaking, X25519 vs ECDH-brainpoolP256r1 is not just a different parameter, it's a different algorithm. And in any case, CFRG could definitely help with defining a combination of two KEMS (both the KEM combiner and the specific component algorithms). For example, [draft-connolly-cfrg-xwing-kem](https://www.ietf.org/archive/id/draft-connolly-cfrg-xwing-kem-04.html) proposes one such combination that we could adopt wholesale in draft-ietf-openpgp-pqc (though that's a separate discussion). Then, if CFRG also defines a combination of ML-KEM+Brainpool, perhaps we could simply add a registration to the public-key algorithms registry, with a reference to the CFRG spec, without needing any separate spec in the OpenPGP WG? > What exact question do you suggest should be asked to CFRG? What aspect to you expect to be clarified or resolved through that? I didn't mean to propose to ask them a question per se, but rather to inform them of the position of the BSI (given that it might have implications for the use of cryptography in all IETF protocols), and then (if they agree it's a valid concern that should be addressed in the CFRG) propose to standardize a combination of ML-KEM+Brainpool (for example), that could then be used in OpenPGP. This way, we have a higher chance of achieving some consistency between the algorithms used across IETF protocols. Best, Daniel
- [openpgp] WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] BSI view on KEM combiners Kris Kwiatkowski
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker