[openpgp] Re: WG: BSI view on KEM combiners
Paul Wouters <paul@nohats.ca> Wed, 04 September 2024 16:26 UTC
Return-Path: <paul@nohats.ca>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2956DC14F61D for <openpgp@ietfa.amsl.com>; Wed, 4 Sep 2024 09:26:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.547
X-Spam-Level:
X-Spam-Status: No, score=-5.547 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.1, MIME_HTML_ONLY_MULTI=0.001, MIME_QP_LONG_LINE=0.001, MPART_ALT_DIFF=0.79, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_SOFTFAIL=0.665, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3i965Shp61A2 for <openpgp@ietfa.amsl.com>; Wed, 4 Sep 2024 09:26:47 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [IPv6:2a03:6000:1004:1::85]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6BBA1C14F71E for <openpgp@ietf.org>; Wed, 4 Sep 2024 09:26:47 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4WzSYb6DPmzFHq; Wed, 4 Sep 2024 18:26:43 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1725467203; bh=WZdsi3voA+iDU7u74+xuzHhDopvPrJFTNNAqZHWVwFE=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=RtXFNomkwcOpQZQ3zIzcg0smAHgqBEsBmWYChodcjUOeEt7W04S2GZAPj9bEJqt8B EGopoZ/XCnE3BnWkhmMLkEmVstHQCd2uNUdRNxs110OLL2+/95BIKrzq7sAnH9+/gF 5CeEcgQd0KIVpaBSVY+G6a9YjjR0rIE9GDUnHKyU=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id 1GAz1nqt2JiY; Wed, 4 Sep 2024 18:26:42 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Wed, 4 Sep 2024 18:26:42 +0200 (CEST)
Received: from smtpclient.apple (unknown [193.110.157.208]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by bofh.nohats.ca (Postfix) with ESMTPSA id 97CB212FD15A; Wed, 4 Sep 2024 12:26:41 -0400 (EDT)
Content-Type: multipart/alternative; boundary="Apple-Mail-C51EA61F-AA03-4452-BD26-3A8135946783"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (1.0)
From: Paul Wouters <paul@nohats.ca>
In-Reply-To: <8abbc4c2-3285-4a12-8ea9-b081cebb1e54@mtg.de>
Date: Wed, 04 Sep 2024 12:26:30 -0400
Message-Id: <5F1A73F3-B786-41C3-862A-F3A854B96F1A@nohats.ca>
References: <8abbc4c2-3285-4a12-8ea9-b081cebb1e54@mtg.de>
To: Falko Strenzke <falko.strenzke@mtg.de>
X-Mailer: iPhone Mail (21G93)
Message-ID-Hash: 33JFA4N5XIUFQQAMS4JQSNW6SYR33HWN
X-Message-ID-Hash: 33JFA4N5XIUFQQAMS4JQSNW6SYR33HWN
X-MailFrom: paul@nohats.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "Ehlen, Stephan" <stephan.ehlen=40bsi.bund.de@dmarc.ietf.org>, openpgp@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: WG: BSI view on KEM combiners
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/JKcINmFVq3FAVqdRl3UO7RlviDM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi Daniel,
Am 04.09.24 um 10:53 schrieb Daniel Huigens:
Hi Falko,
Pedantically speaking, X25519 vs ECDH-brainpoolP256r1 is not just a different parameter, it's a different algorithm. And in any case, CFRG could definitely help with defining a combination of two KEMS (both the KEM combiner and the specific component algorithms). For example, https://www.ietf.org/archive/id/draft-connolly-cfrg-xwing-kem-04.html" title="draft-connolly-cfrg-xwing-kem-04" rel="nofollow">draft-connolly-cfrg-xwing-kem proposes one such combination that we could adopt wholesale in draft-ietf-openpgp-pqc (though that's a separate discussion).
What I don't see is what is specific to Brainpool parameters here. Everything you suggest regarding CFRG defining a combination of two KEMs that we adopt equally applies to the combination of ML-KEM+X25519 (and also ML-KEM+NIST-P-...). Otherwise please clarify where you see the difference. So how should we understand your standpoint – do you also suggest to first ask CFRG to standardize ML-KEM+X25519 (and +X448) before we can finalize it in draft-ietf-openpgp-pqc, at the risk of delaying the – in my view overdue – introduction of PQ/T encryption in OpenPGP?
Are you suggesting that we now adopt draft-connolly-cfrg-xwing-kem, an individual draft?
Adopting any construction that is not finalized as an RFC or at least very close to finalization in my view is not a good idea. This is why I am looking forward to the publication of [1] and (also any concrete output from CFRG of course, it's just that that doesn't seem to be at hand right now).
Then, if CFRG also defines a combination of ML-KEM+Brainpool, perhaps we could simply add a registration to the public-key algorithms registry, with a reference to the CFRG spec, without needing any separate spec in the OpenPGP WG?
I don't think that CFRG will write a spec that defines how an algorithm is used in OpenPGP.
Key, signature and ciphertext formats still have to be formally defined.
In any case, as stated above, we are happy to check if we can align the OpenPGP KEM more with LAMPS based on [1] – but certainly not just for the combinations with Brainpool parameters.
By the way, check out the https://www.ietf.org/archive/id/draft-ietf-lamps-pq-composite-kem-04.html" rel="nofollow">current specification of composite KEM in LAMPS. They currently define https://www.ietf.org/archive/id/draft-ietf-lamps-pq-composite-kem-04.html#section-2.3.4" rel="nofollow">their own combiner and a pretty rich https://www.ietf.org/archive/id/draft-ietf-lamps-pq-composite-kem-04.html#section-5-4" rel="nofollow">set of PQ/T combinations (compared to OpenPGP):
- [openpgp] WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] BSI view on KEM combiners Kris Kwiatkowski
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker