[openpgp] SLH-DSA code points

Falko Strenzke <falko.strenzke@mtg.de> Wed, 20 March 2024 09:57 UTC

Return-Path: <falko.strenzke@mtg.de>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3A7ECC151076 for <openpgp@ietfa.amsl.com>; Wed, 20 Mar 2024 02:57:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mtg.de
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hU1FQKHuJTNx for <openpgp@ietfa.amsl.com>; Wed, 20 Mar 2024 02:57:00 -0700 (PDT)
Received: from www.mtg.de (www.mtg.de [IPv6:2a02:b98:8:2::2]) (using TLSv1.3 with cipher TLS_CHACHA20_POLY1305_SHA256 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DEBDEC14F71D for <openpgp@ietf.org>; Wed, 20 Mar 2024 02:56:58 -0700 (PDT)
Received: from minka.mtg.de (minka [IPv6:2a02:b98:8:1:0:0:0:9]) by www.mtg.de (8.18.1/8.18.1) with ESMTPS id 42K9usjh032177 (version=TLSv1.3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256 verify=NOT); Wed, 20 Mar 2024 10:56:54 +0100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mtg.de; s=mail201801; t=1710928614; bh=SU8p1lBqlk1K/Q4wUpwyZvm21IAVoJqEBwg93m3O6TA=; h=Date:To:From:Subject; b=YmKmlgjGW+eefQyRLWdu6kP5NaaOViFvk4xRmNIEWUORvafLwuOFWTMQAnkVsxTCy sY3is56ujGcsOmxHyz9yjRe3r7bMoIa2hPTzlSL+yjDoO/ahokVv+3FpI+pjzSLH8Y 6VcC7pSBLRWmnNyFZsJAw0CEyG63DqvvdKzZXha01r+ImT51ZY9K681mCrPRmfQv9t dNcgGp6pstUPq5uHJwHAgvG7kGIzMKBYMzAmIkdMZfL1jvJEF2VKH6oGUH/NjQt3F2 Ma5MATa8o3FqhHs1XX5pCBR6IS7hPx0IUGGxpZ+DQCe7fZ5Hm/ARjuh0L3z8Gcs9y1 WiZoefeBq+XjA==
Received: from [10.8.0.100] (vpn-10-8-0-100 [10.8.0.100]) by minka.mtg.de (8.18.1/8.18.1) with ESMTPS id 42K9usIX013962 (version=TLSv1.3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256 verify=NOT); Wed, 20 Mar 2024 10:56:54 +0100
Message-ID: <42ff8d55-88a9-4c84-99bd-688f1d29b508@mtg.de>
Date: Wed, 20 Mar 2024 10:56:54 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
To: "openpgp@ietf.org" <openpgp@ietf.org>, Daniel Huigens <d.huigens@protonmail.com>
From: Falko Strenzke <falko.strenzke@mtg.de>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms040101060200000700030809"
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/CVaGl5J_zmeI-QzQytjA45kYSDo>
Subject: [openpgp] SLH-DSA code points
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Mar 2024 09:57:05 -0000

During yesterday's session the discussion came up between Daniel and me 
whether we need all three currently proposed SLH-DSA code points in the 
PQC draft, namely 128f, 128s, and 256s (all with SHAKE).

I attached a visualization of the time and space performance also with 
comparison to ML-DSA-87 (256bit sec, L5). Please note there are two 
sheets which only differ in that one displays the charts linearly, the 
other logarithmically.

My argument for the current triple is that

- 128s is the only SLH-DSA variant coming near ML-DSA regarding 
signature size,
- 128f is a factor of 100 worse in signature generation than ML-DSA, but 
still 10x faster than 128s. Thus where signing time is a cost factor, 
128f has a clear advantage.

So both 128s and 128f seem highly relevant to achieve performance time 
or space wise somewhat close to ML-DSA.

Then of course 256s seems clearly required to have at least one variant 
for 256 bit security.

- Falko

-- 

*MTG AG*
Dr. Falko Strenzke
Executive System Architect

Phone: +49 6151 8000 24
E-Mail: falko.strenzke@mtg.de
Web: mtg.de <https://www.mtg.de>

<https://www.linkedin.com/search/results/all/?fetchDeterministicClustersOnly=true&heroEntityKey=urn%3Ali%3Aorganization%3A13983133&keywords=mtg%20ag&origin=RICH_QUERY_SUGGESTION&position=0&searchId=d5bc71c3-97f7-4cae-83e7-e9e16d497dc2&sid=3S5&spellCorrectionEnabled=false>
Follow us
------------------------------------------------------------------------
<https://www.mtg.de/de/aktuelles/MTG-AG-erhaelt-Innovationspreis-des-Bundesverbands-IT-Sicherheit-e.V-00001.-TeleTrust/> 
<https://www.itsa365.de/de-de/companies/m/mtg-ag>

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>