[openpgp] Re: Fwd: [pqc-forum] Question regarding pure vs. pre-hash ML-DSA
Daniel Huigens <d.huigens@protonmail.com> Mon, 02 September 2024 08:31 UTC
Return-Path: <d.huigens@protonmail.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C0BE8C14F6FB for <openpgp@ietfa.amsl.com>; Mon, 2 Sep 2024 01:31:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=protonmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KUwTwey3CXZ5 for <openpgp@ietfa.amsl.com>; Mon, 2 Sep 2024 01:31:37 -0700 (PDT)
Received: from mail-40131.protonmail.ch (mail-40131.protonmail.ch [185.70.40.131]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A75F8C14F5ED for <openpgp@ietf.org>; Mon, 2 Sep 2024 01:31:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1725265895; x=1725525095; bh=RplRHZj8CyEH1ooeczBPZdP+ezfxqjP61P0irRBbdLo=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=mVKJKVWOcTJPpxKCzD9uLyiC5CVp1qOUhf3Kytqg5SCPAMzBJDfznU6LdFnCy/Wb/ maER7mvfJBGCjxyGPtw8oRTV8h7K6qbmGx1ZjF3sQvYudRbxwBRsNEZ3SbMpCzH0om qnywwhJ1lnpPnlh3OJid34sAoL4/rR/6TauDzLW8NZwDBjJZyL2Guzdxg5+UXJc1KY nNXeihw4Z3EQttd++Kos00tgGSrbM6IDQ+MnrDwnBHFUwEGBLrjAeq0+n4mpSA3QFJ m1Qu7UIVqRzi8P2jfkJJ6HCYmNwVpqIncASZDwu5gDjAzD5xKw+zE2OwRi6t+4wgRp AdtfRJ4phbV+Q==
Date: Mon, 02 Sep 2024 08:31:32 +0000
To: "David A. Cooper" <david.cooper=40nist.gov@dmarc.ietf.org>
From: Daniel Huigens <d.huigens@protonmail.com>
Message-ID: <Ik648NB--vzbbeezJzVFCnUA8s8jtzwz-IQ18uiHnbY0sxP8EVlTCv0VXmQKvNZdVp6lFQbfSdMNk_41p8-I-NXl1c8R635pRdPk0fZvqi8=@protonmail.com>
In-Reply-To: <6e9937c3-bed1-4153-b639-c00d6f577c74@nist.gov>
References: <0555d567-e161-488f-a4eb-30a015f8c0d0@mtg.de> <9f26a754-0268-4fc7-abcc-7eeebe38eb88@mtg.de> <d9b5779c-d5f4-4d42-b102-85b81704c130@nist.gov> <e5eccd432d55049302f646c8d9687487c02d5a53.camel@redhat.com> <6e9937c3-bed1-4153-b639-c00d6f577c74@nist.gov>
Feedback-ID: 2934448:user:proton
X-Pm-Message-ID: 9a26d56fefed0f04a9954ec8092b5c78d84f8941
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: COENA2NDR5OYEROUTTFARQOB43MFPOAH
X-Message-ID-Hash: COENA2NDR5OYEROUTTFARQOB43MFPOAH
X-MailFrom: d.huigens@protonmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Simo Sorce <simo@redhat.com>, Falko Strenzke <falko.strenzke@mtg.de>, IETF OpenPGP WG <openpgp@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: Fwd: [pqc-forum] Question regarding pure vs. pre-hash ML-DSA
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/EihSczKqFVKbd-fGi4I9Xv77VRY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi David (& all, but minus the PQC forum since my message is very OpenPGP-specific), On Friday, August 30th, 2024 at 23:08, David A. Cooper wrote: > OpenPGP is effectively taking two > different approaches to signing, depending on whether RSA, ECDSA, or > EdDSA is being used. With RSA and ECDSA the message that is signed is > the trailer. With EdDSA the message that is signed is the hash of the > trailer. The way it's framed in RFC 9580 (and the way I usually think of it), OpenPGP always computes the hash (of the message+trailer, or salt+ message+trailer in the case of v6 signatures), and then passes that to the signature algorithm: All signatures are formed by producing a hash over the signature data and then using the resulting hash in the signature algorithm. However, it's true that both RFC 8017 (for RSA) and FIPS 186 (for ECDSA) contain a hashing step, and it's not the case that the data gets hashed twice. So, you could indeed also frame it as saying that OpenPGP passes the (salt+)message+trailer to those algorithms. But, given the above quote, I'd frame it more as saying that the hash computed in OpenPGP is used in the RSA and ECDSA signing operations directly (essentially monkey-patching the algorithms to accept a hash digest instead of a message). Though, it's a bit unfortunate that this is not more clearly spelled out. Nevertheless, I would still prefer to keep the invariant that OpenPGP computes the hash as stated in the spec. So, to me, that would imply either using pure ML-DSA, or monkey-patching HashML-DSA to accept a hash instead of a message as well (like we've arguably done with RSA and ECDSA - but doing the same with HashML-DSA seems more like extending a mess than cleaning one up). If instead we want to retcon OpenPGP to the framing you've used, i.e. for some algorithms we pass the message and for some algorithms we pass the hash, that would open the door to "cleanly" using HashML-DSA without monkey-patching it - but it would require monkey-patching OpenPGP in the "PQC in OpenPGP" spec, causing a different mess instead. Hence, I think the pure variant seems like a better fit for OpenPGP. But, let us know if you disagree :) Best, Daniel
- [openpgp] Fwd: [pqc-forum] Question regarding pur… Falko Strenzke
- [openpgp] Re: Fwd: [pqc-forum] Question regarding… David A. Cooper
- [openpgp] Re: Fwd: [pqc-forum] Question regarding… Falko Strenzke
- [openpgp] Re: Fwd: [pqc-forum] Question regarding… Simo Sorce
- [openpgp] Re: Fwd: [pqc-forum] Question regarding… David A. Cooper
- [openpgp] Re: Fwd: [pqc-forum] Question regarding… Daniel Huigens
- [openpgp] Re: Fwd: [pqc-forum] Question regarding… Simo Sorce