[secdir] [new-work] WG Review: HPKE Publication, Kept Efficient (hpke)

The IESG <iesg@ietf.org> Fri, 25 April 2025 16:05 UTC

Return-Path: <forwardingalgorithm@ietf.org>
X-Original-To: secdir@mail2.ietf.org
Delivered-To: secdir@mail2.ietf.org
Received: from mail2.ietf.org (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C4D642139A0E for <secdir@mail2.ietf.org>; Fri, 25 Apr 2025 09:05:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1745597123; bh=GRgZujvji4yaW1tRgaipDVOyUySLTGzCs/rfYNq9Cic=; h=From:To:Date:Reply-To:Subject:List-Id:List-Archive:List-Help: List-Owner:List-Post:List-Subscribe:List-Unsubscribe; b=y1I3F9u0Kk0R1AeQSe1u/r58XJJOQPcuW+wV4ojGllLL6suFDYRWHhug9SYFlwFpV fQMLoo+aM/pxHHAR+dhmuhDlyG5WE/BP+jBW5ipn24gVkMq+73swxu99PgzJr2k6Pa ZgU5Qe7wS0IFCi/bjV+7T4n5yZ7RU65UmuR5vdFM=
X-Mailbox-Line: From new-work-bounces+secdir=ietf.org@ietf.org Fri Apr 25 09:05:23 2025
Received: from mail2.ietf.org (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 932EE21399FE for <secdir@ietf.org>; Fri, 25 Apr 2025 09:05:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1745597123; bh=GRgZujvji4yaW1tRgaipDVOyUySLTGzCs/rfYNq9Cic=; h=From:To:Date:Reply-To:Subject:List-Id:List-Archive:List-Help: List-Owner:List-Post:List-Subscribe:List-Unsubscribe; b=y1I3F9u0Kk0R1AeQSe1u/r58XJJOQPcuW+wV4ojGllLL6suFDYRWHhug9SYFlwFpV fQMLoo+aM/pxHHAR+dhmuhDlyG5WE/BP+jBW5ipn24gVkMq+73swxu99PgzJr2k6Pa ZgU5Qe7wS0IFCi/bjV+7T4n5yZ7RU65UmuR5vdFM=
X-Original-To: new-work@ietf.org
Delivered-To: new-work@mail2.ietf.org
Received: from [10.244.8.147] (unknown [104.131.183.230]) by mail2.ietf.org (Postfix) with ESMTP id B842321398CE for <new-work@ietf.org>; Fri, 25 Apr 2025 09:05:13 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
From: The IESG <iesg@ietf.org>
To: new-work@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.39.0
Auto-Submitted: auto-generated
Precedence: bulk
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Reply_to: <iesg@ietf.org>
Message-ID: <174559711361.134203.14317459247652880198@dt-datatracker-7bd7b9d5d5-79vfh>
Date: Fri, 25 Apr 2025 09:05:13 -0700
X-MailFrom: iesg@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-new-work.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Content-Transfer-Encoding: base64
Message-ID-Hash: YHUIFDXUW5A2NKT675RKZRIROO5YDFAJ
X-Message-ID-Hash: YHUIFDXUW5A2NKT675RKZRIROO5YDFAJ
X-MailFrom: forwardingalgorithm@ietf.org
X-Mailman-Rule-Hits: nonmember-moderation
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdir.ietf.org-0
Reply-To: iesg@ietf.org
Subject: [secdir] [new-work] WG Review: HPKE Publication, Kept Efficient (hpke)
List-Id: Security Area Directorate <secdir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/g97w0kqaZAmetznOpciTkC3m8pg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Owner: <mailto:secdir-owner@ietf.org>
List-Post: <mailto:secdir@ietf.org>
List-Subscribe: <mailto:secdir-join@ietf.org>
List-Unsubscribe: <mailto:secdir-leave@ietf.org>

A new IETF WG has been proposed in the Security Area. The IESG has not made
any determination yet. The following draft charter was submitted, and is
provided for informational purposes only. Please send your comments to the
IESG mailing list (iesg@ietf.org) by 2025-05-05.

HPKE Publication, Kept Efficient (hpke)
-----------------------------------------------------------------------
Current status: Proposed WG

Chairs:
  Martin Thomson <mt@lowentropy.net>
  Yaroslav Rosomakho <yaroslavros@gmail.com>

Assigned Area Director:
  Deb Cooley <debcooley1@gmail.com>

Security Area Directors:
  Paul Wouters <paul.wouters@aiven.io>
  Deb Cooley <debcooley1@gmail.com>

Mailing list:
  Address: hpke@ietf.org
  To subscribe: https://mailman3.ietf.org/mailman3/lists/hpke.ietf.org/
  Archive: https://mailarchive.ietf.org/arch/browse/hpke

Group page: https://datatracker.ietf.org/group/hpke/

Charter: https://datatracker.ietf.org/doc/charter-ietf-hpke/

Hybrid Public Key Exchange (HPKE) [RFC 9180] defines an authenticated
encryption encapsulation format that combines a semi-static asymmetric key
exchange with a symmetric cipher. This format is used in several IETF
protocols, such as MLS [RFC 9420] and TLS Encrypted ClientHello
[draft-ietf-tls-esni]. The fact that HPKE is defined in an Informational
document on the IRTF stream, however, has caused some confusion as to its
usability, especially with other standards organizations. Also, there are
currently no “post-quantum” (PQ) Key Encapsulation Mechanisms (KEMs) defined
for HPKE, in the sense of algorithms that are resilient to attack by a
quantum computer.

The hpke Working Group is tasked with two responsibilities:

   1. Re-publish the HPKE specification as a Standards Track document of the
   IETF, with targeted changes based on experience with its use:
       * The working group may decide to apply any validated errata filed on
       RFC 9180 (Verified or Hold for Document Update). * The working group
       may decide to remove functionality that is not widely used. * The
       working group may define how Key Derivation Functions (KDFs) that are
       not two-step might be used with HPKE.

   2. Define PQ algorithms for HPKE from among the following:
       * New KEMs based on hybrid combinations of ML-KEM and ECDH (ML-KEM-768
       with X25519, ML-KEM-768 with P-256, and ML-KEM-1024 with P-384) and
       standalone ML-KEM (ML-KEM-768 and ML-KEM-1024). * New KDFs
       incorporating SHA3

Differences between the Standards Track version of HPKE and the Informational
version (RFC9180) documents should be minimized, in order to minimize impact
on existing deployments. The Standards Track and Informational versions must
have identical behavior for any functionality that they both specify.

The group might select a number of cipher suites that address different use
cases, security levels, and attacker threat models.

Milestones:

  Jun 2025 - HPKE specification to the IESG as Proposed Standard

  Jul 2025 - New post-quantum and post-quantum/traditional hybrid cipher
  suites for HPKE to the IESG as Proposed Standard



_______________________________________________
new-work mailing list -- new-work@ietf.org
To unsubscribe send an email to new-work-leave@ietf.org