[openpgp] Re: pure vs. pre-hash in FIPS 204 and 205

Justus Winter <justus@sequoia-pgp.org> Mon, 26 August 2024 09:44 UTC

Return-Path: <justus@sequoia-pgp.org>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B540FC1519BB for <openpgp@ietfa.amsl.com>; Mon, 26 Aug 2024 02:44:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (4096-bit key) header.d=sequoia-pgp.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QDWgNbUxBcxq for <openpgp@ietfa.amsl.com>; Mon, 26 Aug 2024 02:44:49 -0700 (PDT)
Received: from harrington.uberspace.de (harrington.uberspace.de [185.26.156.85]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DAF9CC14F696 for <openpgp@ietf.org>; Mon, 26 Aug 2024 02:44:47 -0700 (PDT)
Received: (qmail 21409 invoked by uid 500); 26 Aug 2024 09:44:45 -0000
Authentication-Results: harrington.uberspace.de; auth=pass (plain)
Received: from unknown (HELO unkown) (::1) by harrington.uberspace.de (Haraka/3.0.1) with ESMTPSA; Mon, 26 Aug 2024 11:44:45 +0200
From: Justus Winter <justus@sequoia-pgp.org>
To: Falko Strenzke <falko.strenzke@mtg.de>, "openpgp@ietf.org" <openpgp@ietf.org>
In-Reply-To: <fb9f748b-2024-4de1-849a-e52880c9a241@mtg.de>
References: <fb9f748b-2024-4de1-849a-e52880c9a241@mtg.de>
Date: Mon, 26 Aug 2024 11:44:44 +0200
Message-ID: <87plpvwrcj.fsf@europ.lan>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
X-Rspamd-Bar: -----
X-Rspamd-Report: BAYES_HAM(-2.963991) SIGNED_PGP(-2) MIME_GOOD(-0.2)
X-Rspamd-Score: -5.163991
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=sequoia-pgp.org; s=uberspace; h=from:to:subject:date; bh=Y/9yJRJnu6gG8aHEGGpG0ea8aJ8QZ2XmqnvJcF7s0jo=; b=EJNHIvqV03C78RyZKhTZSPM65swIxb3d+vJhqQFQLV3MdoC/BA5isSREiUFsc8o2eoezNdsrqT 2MQ6UQEnaIwR6CCxvD0myS7EGvR7rYiPgBoWzUh/lWOJD8842WIzyKpva9kZOwn7X2inm3bChh35 mO2RfXMG7UENcBb/H8VK+ncaLXl3zHHRpJj/IyhpRmeLmDZgULWKmqJHFHPHOUc9ZWNiUTbjRYkR 7uoCGs4sVDuyVad6Wcj6cIALd7fC77rdfynSiztFCnXrqSG/M1nrwl/H6NRVY6xysK++hLhH0/EW 7dcPHcxn0Kttj02C8qXHxfpSVi+XYGXP5+ngG97OwMibTMvatWl1VZvmqOznnIDABFXsSae0AC9Z bjI7tbfQO7/3dCZ5xyz/xTl/ZNj0DiJbNSInCKEtUgwg3Hnced2ppYwueM3/kiwd9DijyMs0BnSn XckFaw6DcmOMOiROxqF5dxGlsAcL3wHeN95uYTDlKEa1QiaNYPKFa012+i3UnIfCSZl5fCH8GCfN 2tri6BM2pexFkX8sTYjaqgGPQj1edkLUUvbPHIGp6ealILlr+HMgBB6XksPHdGXXhzwSTQROnBYp SQzLgCso+ThJfSdVnJOqN2MBboPOay+/4k0Ch90gvCFy+lui+faxwlXDOcTH1Muja5LaVhjmf/EO s=
Message-ID-Hash: Z4TD6E4356DJJRHILVTXFA7ZCHWHBARW
X-Message-ID-Hash: Z4TD6E4356DJJRHILVTXFA7ZCHWHBARW
X-MailFrom: justus@sequoia-pgp.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: pure vs. pre-hash in FIPS 204 and 205
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/kgBzNK723Pj1wR1b_9cYVMzLQIw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>

Hi Falko :)

Falko Strenzke <falko.strenzke@mtg.de> writes:

> I attribute this at least in part to a misunderstanding about the
> variants “pure” vs. “pre-hash” in RFC 8032 (EdDSA) as well as FIPS 204
> and 205. The idea is to use the pre-hash variant whenever the message
> is first hashed and then input to the signature algorithm. As I had
> mentioned on this list as well, this is done – formally – wrong in RFC
> 9580, which specifies to use the pure variant of EdDSA to sign the
> hash of the message.

I continue to be puzzled by this assertion, but I want to make another
effort to understand it.

RFC8032 defines two variants: PureEdDSA and HashEdDSA.  They differ in
the prehash parameter:

   11.  A "prehash" function PH.  PureEdDSA means EdDSA where PH is the
        identity function, i.e., PH(M) = M.  HashEdDSA means EdDSA where
        PH generates a short output, no matter how long the message is;
        for example, PH(M) = SHA-512(M).

I'm convinced that OpenPGP uses the PureEdDSA variant, i.e.:

  sig = PureEdDSA(Hash(OpenPGP_Hash_Stream))
                  ^ This happens in OpenPGP

The evidence I have gathered for that is:

- Sequoia uses https://docs.rs/nettle/latest/nettle/ed25519/fn.sign.html
- This primitive is tested against the test vectors from
  https://datatracker.ietf.org/doc/html/rfc8032#ref-ED25519-TEST-VECTORS
- These test vectors are part of the test vectors for "Ed25519"
  https://datatracker.ietf.org/doc/html/rfc8032#section-7.1
- Ed25519 is EdDSA instantiated with: [...]
  |   PH(x)   | x (i.e., the identity function)                       |
  https://datatracker.ietf.org/doc/html/rfc8032#section-5.1
-> "Ed25519" is PureEdDSA
-> Sequoia uses PureEdDSA
- Sequoia's v6 implementation agrees with all the other v6
  implementations when using Ed25519-based binding signatures and data
  signatures
  https://tests.sequoia-pgp.org/v6.html#Detached_Sign-Verify_roundtrip_with_minimal_key_from_RFC9580
-> OpenPGP as specified in RFC9580 uses PureEdDSA

On the other hand, if OpenPGP were to use the HashEdDSA variant, we'd
compute:

  sig = PureEdDSA(PH(Hash(OpenPGP_Hash_Stream)))
                     ^ This happens in OpenPGP
                  ^ This is the prehash in HashEdDSA

Which seems not ideal.

Concluding, I'm pretty sure that OpenPGP uses PureEdDSA.  Since there is
obviously some confusion, maybe it is not about what we are doing but
what we are calling it.

- Are you saying since arguably OpenPGP does pre-hashing, the overall
  construction looks more like HashEdDSA, and therefore we should have
  called it that?

- There is no "pre-hash" variant defined in RFC8032, so maybe that is a
  FIPS term and the confusion arises because of that?


Best,
Justus