[openpgp] Re: call for adoption of draft-ehlen-openpgp-nist-bp-comp?

"Hale, Britta (CIV)" <britta.hale@nps.edu> Wed, 28 August 2024 17:07 UTC

Return-Path: <britta.hale@nps.edu>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A69CEC16943E for <openpgp@ietfa.amsl.com>; Wed, 28 Aug 2024 10:07:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.908
X-Spam-Level:
X-Spam-Status: No, score=-1.908 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SUfAvH8QhAVR for <openpgp@ietfa.amsl.com>; Wed, 28 Aug 2024 10:07:05 -0700 (PDT)
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10on2063.outbound.protection.outlook.com [40.107.92.63]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8FFD2C151551 for <openpgp@ietf.org>; Wed, 28 Aug 2024 10:07:05 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=IM3yZ52pnKVPhntdlSDYh0ZX/s0Bf6fgzUrcCvBKSIZ9DIZxAzeNkufxrE+XqhkjhrZiKVw0SBJSURcuhq+GDWj1u/hIsoRhIwREBYAVi2uFvzxhdIjCze6i4AF5nsMF7UJtuj/Ox3PH2AaRBkhsmqHNt6cHnE7tRh574CjlmnQIgyvHmDHg1O+dUvOo6LSlMUg+B9QfrVJv0rMuMDtY7XLCO0dz+eZH0xqA1k9SJNGwyPSJlKn4mH4tcPgFe/nRSJAoBoCU50MV0ERJFUhoNaDeNf2TvAukmp8pcE//BJ62Jyu4NXRierz4aGVr6Xkp3p3H/m9OZ9sRAglsfumbDg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8+xqkSL09G2Vsc/5/Iatztp+Hr6g6zR0sJNtwu3Du30=; b=C0aAu2fe1tekCYG8pVr/DKWpb4561hrc0RYkIcqKWQ3+Xv+dGqwkHyAT+EVHL9HMpznLvyg4FnetWBLT1R2Btt3+oWxnBIXlfNthnraDeRQ07T5i9EPw2zoYNsznJHIDeSQGUylqS9n/c3djlZuSjlBxrjwFSTtvbJjpkxv6ZU25INPUxfaO8t8YEcYfD0oPgUQ98wQMSSj3qZQC/naUtj+2F+QgE6EtS3rLH5HmdyDEfntluHveRrzZHvjtpmUmhH1CzM49wr/42NBKAfsbyXfszexxRtwe3Qg2mqmM4XQWnBYWnsFoqlt9qq6YV/YDYaRFRFqo5fm/3y799tUqRA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nps.edu; dmarc=pass action=none header.from=nps.edu; dkim=pass header.d=nps.edu; arc=none
Received: from BY5PR13MB3348.namprd13.prod.outlook.com (2603:10b6:a03:1aa::23) by MN2PR13MB3710.namprd13.prod.outlook.com (2603:10b6:208:1ed::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7897.27; Wed, 28 Aug 2024 17:07:01 +0000
Received: from BY5PR13MB3348.namprd13.prod.outlook.com ([fe80::e4c7:c5b3:6a81:8232]) by BY5PR13MB3348.namprd13.prod.outlook.com ([fe80::e4c7:c5b3:6a81:8232%4]) with mapi id 15.20.7897.027; Wed, 28 Aug 2024 17:07:01 +0000
From: "Hale, Britta (CIV)" <britta.hale@nps.edu>
To: Falko Strenzke <falko.strenzke@mtg.de>, "openpgp@ietf.org" <openpgp@ietf.org>
Thread-Topic: [openpgp] call for adoption of draft-ehlen-openpgp-nist-bp-comp?
Thread-Index: AQHa+UmJGahA1klOfk27YSrvn0ztz7I8o8IA
Date: Wed, 28 Aug 2024 17:07:01 +0000
Message-ID: <D753AC29-A81C-49D8-B9A0-7FF0E443D3B8@nps.edu>
References: <563556e4-6a57-41e5-a8da-ae1ff27c08c6@mtg.de>
In-Reply-To: <563556e4-6a57-41e5-a8da-ae1ff27c08c6@mtg.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.87.24072822
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nps.edu;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BY5PR13MB3348:EE_|MN2PR13MB3710:EE_
x-ms-office365-filtering-correlation-id: 381e94eb-fac6-45c8-9edc-08dcc783d531
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|376014|38070700018;
x-microsoft-antispam-message-info: H+87s5w4YUSXCIHKlHg25rC+oEuHI3CKCZXgGkrRCoabIVAFz4CEQmSOYeJo01UbzPLvVZZCPEAbh9TATdBz0iKZVBLTW6aQ8FoPT1giKYr6T8TlPuAnD+TDInweISFXaNsy2douaGrr6oQsbWzTXe7h4Eg1vkNQdy7uGHH7nxWfrRGSf1JOZTjLMQCbOUvc49aBZmeqRsrzfMIohcaJ8D0R4yF1l5fpIc8anu8JYRbPbSqLUMjJywyKbYVk5Nui4nz+HITUJ8pBXUXeQhd8TZucYdKiWy09luxmP3x15Pd8s9D2X44tS+ayydDvlHD1PDqGF2bUSWVMnQm1Dc8x/kPyhcyt8b4MS3MmlXUP9zeLlZiKQyvfb7lPKA69es4aghWDbJEWfLY4VuutUuVDXWmVJ/0deuKABtS9njaLa0FRz7bbIH2t6NdUyGwotMPEXMqDqwN5nDjyU6xgiKsiKIDPU8Wuy++c2KPwEXPCEnakj1JmbjqgmQdw3xQHWdtgHBB+d7gwkyVm21sbI74a0uasE25GNJWMsbJ0GCl59kAmsiifZ6n437hFjLuu/boJRsAokfJISbGR4wiIbVzYLf/DpbN8ItKW/com7GqomDKCpoZoOwUkoh6zABZMF5Yk3SBLB/JFDhqoZa049Ie3dWUD7krDduIonNy5Ai0BKX56qFOUZxxAuKm0F2QiWrDVropi2vwbXR8HOKSf8wHPLFMDt7znY9lBFo5c/7K0wH6DFnxFgAN3Vcfy6zM7+H8lBtzhoBbXual+j9KC6qkoPAOsU4Jsw1lu0tZP3CAwM9FpJDrAWiwOCxz0COgQppOCVaNPXAXca24LwB0Nl57EbWrgezYFwAm/2AICmFpybIh8g0fW4tnbhrdZKz+8+PFStDgquveSSd/Nmzfl63/5XcT6M8UajDbo5UFFwmfwaICDbpLAC7fwSp+n0WZk/V35iNr9RBw6DsXvTU2NAmBv5SQLi/L6jxfd7NBTaEciuF9ijSDlV/2LzAr4wR21hlTmyaXEnJy/Uork2Sty6Cx6JrKbYjP7qmMU7v07np1hs07udNC2jvu15JRK4eF0TRSh4rxO5d+aB511ggSlMWAfKG0bMUY7T0Egca7F/oN5/mDPuyf0XcoRCLZiQGCrTl0osgtw2gWy2K5AwseE51eHiQO8Y7zEF82y9f/H/n2/SxMzcG0ReNepJRVACRPPTXCcE2msG+EK2dB15FBThpMIVWEjCADuOR144fajVamhNH/MTle+I3sE9vsrWX6eD0RyeZ9G+c4EeuoqBVnr+k4Kv2xB6/jghSSWZz3XdpdBFH8RdnF53I6IxMJCM4/lO5Uf3hppsmbDRnR+q6ZWKfpu9vWqtZAyXzAnplces2Dzhf8=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BY5PR13MB3348.namprd13.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: VPnmXY/35acpXdRTbhuZqwoXtNd+IeL+kywR/LKgyfm3+fgBpuvypIBwRGhuWbuf03UZ+FNWHcWInZ0QYt+fAIL82n//t3n0JekYHtwRaJ4rDQuZdzsYPiBpaYOiUjRs9CFbZthXcEAASKISKFqJ93WW4tGCtA9SP1E6Ai3LwW9SA18c3JoGp+fxC6QHimRVWVPOgwlIZsdSsBuuKovMQemq2RiU9br4KRjBCSwuwq256QJY3WFks60FqOPqrOCp3OB4E2LM6/M6KfisL4JpjZdBRfIlnAy+fLZWVHx6Q40mL/oU3IOYLMYSvLFCz18uPxEia4NiygeJgULncjJn6EF789ITrxWrsQ/6D1ZfjA1TMGGyeFWZLztdZotmdHSfQhiHfJ0ycvDhjL4O4FkUjr0kQUZq2ITUNFqYCpAT4iB1RjYqZAVAUJ7RdOp2PVLYcKzW1K/JTOhsiMCARw9EHxzcZ1PQ8wjPT0bxHM8MUgnR00/h97wzdarZzUq5TSBLdBQ9PfV3fKubCVyuQgekA9MRMLWjXefBss+bK7Y4G1luB9GKq+r1r1mHW2Fmjnim6KWhUm5wFvY2sbnI/BtQCaI9r25b0BRj19w/zFzJb+PmDUrJRF4g6b0Ou/mHcB4LqTzFlWx6pLcibFtp7Sq50vtfJU11wUcVCa4VUyGcrpTQMJ9C/Eh1k320kFVXOIkWPwzNg+HVeYuNvkZUiWTlsuXCXSFXN10GeYHymPPUHRTcljLyChD49m8CIBNGQLBhCMSi7QPiD+zOYCp3W/fG649hz2pfafhzUFea2oUYBG4+nfTURb+Nyev6zRIqgXKJKFZRoV1VFnQzXZFT/txXETTtR2PVdGAzCzdsOUgrLiG04C8Lej6htkJ5i9AsIY7eQuT4dJKQ1uh6tN7wJwpH6OXzAGM2biJCC2bWiLaDWMaseGYMv1QzktTVqwpDuMGMYNCR/bwldj/Agd2XGY3pjv+VSnp7Zh0SvacZ2AwSnDJ0QXTK7PgYuoan+KwodesSeOICMM6LGv1r+Ndl29GKWzbO/ihC3vihuLgxrgzRvQj89Ov80ymmPOOL1TzbNv+rxODEX4VvCfuOVlTTJRGPSs9JXOl0CH9WdF9fBpLqsft5Y1k2W4I14DNFPYnFZsfSeFNrjaCehsDAx/R1wpWP48mv5tOZn+TiJpk6Pg5Mwe5bsI6Stu7MxHrkZpmADp5jZaJwH0OU+heyd10x/gtNnZzLFP8Q9GbGzMw5fOOE4edw3C7q5rxiv/1OnqxmwkbjwrMbSkS5RpzxTAvpG8kT1Da0o9XAm+d2w1mpYRMC3lxlypU2+ItNAl4uAe9HJOr7Wgvf9WbsDS0yrl3rZ1p386OZ9iM4X0hLvcL4qOwjCpc9vB0NFMnIa1xQLjiGbwLa8SYH5USxVV3OLG07WiqN8cwjzG2B/gjL1TzjIqKRqfEE9SC7w3fnoi/AQTHdSY+PegInyqAh+HO5qjYFDJzcOHD7FpNvLzMfURmySMS9W1RBWB0kYDOEytkEvohPKbLggWnHhqQysmAnHQBNtKKLHpYlZ6hoQFlPJVZmMeTaj0bC5XyNhXMdbjKmRLS+s2rKlOHvnYq2RbG+lZp+IkLSEA==
Content-Type: multipart/alternative; boundary="_000_D753AC29A81C49D8B9A07FF0E443D3B8npsedu_"
MIME-Version: 1.0
X-OriginatorOrg: nps.edu
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BY5PR13MB3348.namprd13.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 381e94eb-fac6-45c8-9edc-08dcc783d531
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Aug 2024 17:07:01.1182 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 6d936231-a517-40ea-9199-f7578963378e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LfptabcrGGKGLFXwzcx9jvVGQ/mWkqiNf8vg72aVGtPNhdUpfIF9lutCBo+CoDJe0vFULKaGJhm3F3dsIL8AgQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR13MB3710
X-MS-Exchange-CrossPremises-AuthAs: Internal
X-MS-Exchange-CrossPremises-AuthMechanism: 04
X-MS-Exchange-CrossPremises-AuthSource: BY5PR13MB3348.namprd13.prod.outlook.com
X-MS-Exchange-CrossPremises-TransportTrafficType: Email
X-MS-Exchange-CrossPremises-SCL: 1
X-MS-Exchange-CrossPremises-messagesource: StoreDriver
X-MS-Exchange-CrossPremises-BCC:
X-MS-Exchange-CrossPremises-originalclientipaddress: 205.155.65.226
X-MS-Exchange-CrossPremises-transporttraffictype: Email
X-MS-Exchange-CrossPremises-antispam-scancontext: DIR:Originating;SFV:NSPM;SKIP:0;
X-MS-Exchange-CrossPremises-processed-by-journaling: Journal Agent
X-OrganizationHeadersPreserved: MN2PR13MB3710.namprd13.prod.outlook.com
Message-ID-Hash: 72YBESJNRAMEFZ2PRJX3U2L7PSJ6PILU
X-Message-ID-Hash: 72YBESJNRAMEFZ2PRJX3U2L7PSJ6PILU
X-MailFrom: britta.hale@nps.edu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: call for adoption of draft-ehlen-openpgp-nist-bp-comp?
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/WdGEx2sTfZ9fTiUNsDpjD35JRdU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>

All,

I have several concerns about this draft:

1) WG appropriateness.
There is very little in this draft that is unique to OpenPGP. While I applaud the early leaders in pushing PQ standards in the IETF for their efforts, in whatever working group would take initiative, now that things have come to a more mature standing and the first NIST standards are out, being systematic would be wise, so that the right WGs are reviewing and correlating these. Otherwise we risk a mayhem of individual standards draft spread across the IETF all offering their own versions of ‘ML-KEM’ or ‘ML-KEM’ hybrid unique to the different WGs.

Traditionally, the CFRG is the WG to set the guidelines for algorithms (which algorithm combiners still are). In my opinion, PQUIP for general coordination and the CFRG for specific algorithm drafts are the right places for this. It is not reasonable to assume that everyone in OpenPGP is tracking PQUIP or the CFRG, which can also be seen in the dearth of comments on the OpenPGP mailinglists. As a consequence, few here may pick up on the fact that the terminology in this draft differs from several documents already tracked by PQUIP, and the overlap with existing KEM and signature combiners is not made clear here. Such clarity would be well handled in CFRG if we do not break from the norm of algorithms going to them. Other combiners presented in PQUIP have been similarly sent to CFRG, so it would be concerning if a given non-CFRG WG presses ahead on a solo versions.

Note that this is equally important on substantive cryptographic drafts and non-substantive (i.e., regardless of how cryptographically invasive a combiner is or is not, or even whether or not there is a combiner at all). We need clarity and consistency in IETF algorithms, vs. 20 different “ML-KEM combiner” standards for 20 different WGs, and it requires responsibility by all WGs to ensure that does not happen. After all, we do not currently have 20 different standards for AES, so it is best to avoid incurring the ensuant complexity when going into post-quantum efforts. If this draft is sufficiently different from others in CFRG, then the clarity of different security or use goals, etc. will be handled there with guidance on ensuring the right language in the draft to make that clear.

2) Goal ambiguity.
The goals of this draft mix of KEM combiners and signatures. These are very separate algorithm types. We (the IETF, NIST standards, ISO, etc.) do not historically mix those into a single draft. This is even more important as the relative security goals aimed for each combiner in the draft are different: the KEM aims to achieve strong non-separability, whereas the signature combiner does not even aim to achieve weak non-separability. It would seem appropriate to break these into distinct drafts.

3) Overlap with other efforts.
There are multiple efforts in the CFRG and PQUIP for KEM combiners, signature combiners, etc. This draft does not reference any of those and I note overlaps in the proposed efforts. If the draft was routed through the correct WGs (e.g., CRFG and PQUIP) it could likely achieve deduplication and also consistency in terminology and presentation. Only protocol-specific draft (i.e., protocol combiners, not algorithm combiners) seem appropriate for other WGs – this goes back to item (1).

3) Lack of formalism and security goals clarity.
There is also a lack of clarity in formalism in this draft:  the signature combiners listed are a ‘parallel’ approach but their security is not stated as such (esp. see PQUIP drafts on this). Also, the signatures are listed as “composite” but are not according to the PQUIP terminology draft (they are hybrid only). The goals for doing combiners are frequently security goals, so precision on those is very important in order to assess whether or not the draft is even achieving its own intent.


Given all of the above, I recommend that the draft be moved instead to CFRG. If the combiner is an approved algorithm, then OpenPGP will be able use the code points for that and there is the added bonus that if it has wider applicability other WGs can also use them. If further protocol customization for *how* OpenPGP applies an algorithm is needed, that can be achieved in a separate draft, and does not seem to be a goal of this draft anyway.


Britta



From: Falko Strenzke <falko.strenzke@mtg.de>
Organization: MTG AG
Date: Wednesday, August 28, 2024 at 5:55 AM
To: "openpgp@ietf.org" <openpgp@ietf.org>
Subject: [openpgp] call for adoption of draft-ehlen-openpgp-nist-bp-comp?

NPS WARNING: *external sender* verify before acting.


Dear OpenPGP Chairs,

at IETF 120 we presented our draft introducing the PQ/T composites with NIST and Brainpool curves https://github.com/openpgp-pqc/draft-ehlen-openpgp-nist-bp-comp.

In the meeting Stephen said the working group would be given some time to read the draft and then a call for adoption would be issued. Given that the content of the draft is not substantially new but is more or less the content that was branched off from the already adopted draft-ietf-openpgp-pqc, it seems to me that the six weeks that have since passed should be enough time. Are the chairs ready to issue the call for adoption any time soon?

Best regards,
Falko
--


MTG AG
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: falko.strenzke@mtg.de<mailto:falko.strenzke@mtg.de>
Web: mtg.de<https://www.mtg.de/>

________________________________

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted.

Data protection information: Privacy policy<https://www.mtg.de/en/privacy-policy>