Re: [lamps] Do we have a FALCON draft yet?

"Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu> Sun, 20 November 2022 22:13 UTC

Return-Path: <prvs=9323809a5e=uri@ll.mit.edu>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 09425C14CE34; Sun, 20 Nov 2022 14:13:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.906
X-Spam-Level:
X-Spam-Status: No, score=-0.906 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, MIME_HTML_ONLY=0.1, MPART_ALT_DIFF=0.79, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BXNP1vn1oNKq; Sun, 20 Nov 2022 14:13:13 -0800 (PST)
Received: from MX3.LL.MIT.EDU (mx3.ll.mit.edu [129.55.12.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 521DDC14CE31; Sun, 20 Nov 2022 14:13:11 -0800 (PST)
Received: from LLEX2019-1.mitll.ad.local ([172.25.4.123]) by MX3.LL.MIT.EDU (8.17.1.5/8.17.1.5) with ESMTPS id 2AKMD32S197733 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL); Sun, 20 Nov 2022 17:13:07 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=dL1sSAHnNDg/suPEVX+fdFc055qAJ2vnIqQ9PRKVGLFvvHye6v73XP1U3Im3hxckNEK+SnYjrNXr+fqehosXf1g+82vkgIUG2gtv5yOVkpck/GSkfa7T0RJdArjWS7uNGSpNEpvPiyOAMFvpkNxLCNdwbNQMneELLKXuYRYIMfaOhCQLRAePR4XmlK2Njn1pJnwjqgKStS+3JCX1S7zMyOZem3cJ/xqRuW8PfOrApN+eQm2antBrPblAvdFyrkxQ6q4J8qBhaUtVazHFg/E7qz2Cv7zbHfXY0ki8Vznf3sNbRIk0VLfbt8j39LM+8yECV5fTUxI+v+JM58FZAcNDAw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ATwqDcco1xRiwgszfUWWpMkndmHfjxdlLBgTupvuJ0Q=; b=pZGYnfRwiUw7ZmcfAoG4xOTdtOHPulPpEBmxZstCUXU1CpUZ4Hx2okyjWmJahK6PXjKOefF+eeOieEXcyWeWaiHFmQVen6I05trlLVglEqn8MdZuyFK//AHOpxhusw1QI/3mM+cMQjxN4z5IUghc5aPolSiusVX+5jXL1DnH2H2HhUq3RPI1lXoVHtGW+x47aKtjW4fFrsUCxj+rIc30ucIMfu4EvNO5ZluQwUWh5UP/XHxp0Ud96kNqxLZDbf0RS3xTYqWCkXq2Kg61uPUJUIeF+RX+oGJw3F/VUFBv+i7v+POT9U7TyNtd59zYFEEjZdj8UVtUwzX0Zd0ex/Z1Gg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ll.mit.edu; dmarc=pass action=none header.from=ll.mit.edu; dkim=pass header.d=ll.mit.edu; arc=none
From: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
To: Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org>
CC: Mike Ounsworth <Mike.Ounsworth=40entrust.com@dmarc.ietf.org>, LAMPS <spasm@ietf.org>
Thread-Topic: [lamps] Do we have a FALCON draft yet?
Thread-Index: Adj8b9yJwGB8c3cTQXu3YWPDM4XH5gAAmgoAABnP+YAAFO1qAA==
Date: Sun, 20 Nov 2022 22:13:01 +0000
Message-ID: <F17215D0-255B-4DD5-8410-4F5FDA250658@ll.mit.edu>
References: <CAMjbhoUUKjuU1rMJ--21TDz4h6MxMdghGZPVVVJjGaSyCNAgLQ@mail.gmail.com>
In-Reply-To: <CAMjbhoUUKjuU1rMJ--21TDz4h6MxMdghGZPVVVJjGaSyCNAgLQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BN0P110MB1419:EE_|BN0P110MB1465:EE_
x-ms-office365-filtering-correlation-id: 0bbe5406-aefd-4d88-fcb7-08dacb4463de
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ogoS8KQ5IiiEII8X2H/zEyHnOxbE/FqGj/pQotrVhwf/B9uRvF98ztL3E8z6mH11nIYv46TsEkLUYbb27B2s9WsxGlglfDBnJoD518/Ugrh0+y2Q6IkfuDUg2jG8E7LNaFxryZNjx0sHlTphaO4/5f8vnkSvASfL2Ms160QiIFbopG05hhjuUYjZeWvnNWhPV9AzIhPTOHj8dxxzquzAaxFirrAljsUizoeyoXzlFe3uz3AOMiMVYhSIPBdlB6qfK/kwj6hjV5uHEkUjHUmucy2sOWESz8P4euPQGQ7QsPkFxnlT1GlmuOAPZjDrNKOhxPo+dtoxn7dbls3pXBqo1JUBALZRVsXVuGPeruVsRYlHG3oWcxzDEyRT8hErIWy5Vu8r/gE8yjlREdKl2d1WqsFQ/UTWK+5UsINbwSdK4UkHIX4sro8o2zfM+NblccsiJ2YWi3kyPWkl+bRS5+ZxOxAgdU95iGTcnFqWtonwGK5uhNbzyUt/PlgUwYMacFhqSoZGCe/IzGLNF57IrUDzt37WiTYOHD8l/HnvB8Mn/6B0r8hzQkXOsFf4PNjIk8GGG5PeWODMYLUdCwwITs4kkE74n6eUCbv+g0x60Ia8NzPKuXe+uk877I+n9ZaA8IC/KNhUuxCjjRx/qFjdgZHBe3dhRDtKsPMNyuJsjjIS0Uel48z//HBtkY7X53iArWdMp/lN8C911Yh7Hce1j1MTFENDIB7KNJEVxWlY9UiE5XD5mwtB+CrloJf+G2llh2u+
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230022)(366004)(451199015)(2906002)(83380400001)(75432002)(33656002)(186003)(66946007)(76116006)(2616005)(66556008)(86362001)(166002)(38070700005)(53546011)(6512007)(54906003)(6506007)(99936003)(122000001)(8936002)(5660300002)(8676002)(66446008)(66476007)(64756008)(4326008)(966005)(498600001)(6486002)(71200400001)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: nRewM1CrqVk0Ndbck52yHkpV1l8tR7GhEVIXqcvXtHxo6KbzBxldNy9s910lKk4cTUt6+3Yo/j46B/wj0gUr4s0pfiESKm6uwlRWh179/ALpopWjevMnCtpBd8CkLwGrfyvb7iHjjrCK7VPbejgMQzm8e6wpWY9Ms5RwcxXSgj7a9em7dw4TdHr2UbVYAJ0CLGppXHxSqrjD1w65/q71WWecSGQJZgQnRoOLNqivYWSPlSo5+8fljA+7i/kho7EgGpoIFky+Cg19jsw9HLtM7qFAd1mkhbh7m9TtAN+gAnViyeQCilAvEFEXfDTWH6srX/Q+qQx4+rmDvkL4cESgjfqqTQi5YcwsLn4deD9wXSDwSRnurM0fMnScHW/UezsDUKNP2+OFV4gPf/p/hDs+MIPByR5frdf8SwyrvESDfmjW0TP/hidYvkt+2GmmMBJge0SZ1shptefkOrTc7lMWG9DZ2iHt+AxKgo6xxhkW8Ij0cMX9zyfbjPyWgam/h3J8ni51bTHTYcXTuiBaQMgpmQwXXWrIEWigQL/YF60QxTiSQjkuJ9TC2lo88wL7Rqk1KTM18DLVmjk0Y5M8gW+W+xFuDcdQtEwk4P+CrBONM99dR4YZxSw+/Qbr9N/y3Q7MuFBBcbxlmsI/7NupByn1L7NnIgCbbzdsDjwARLkWMFK9dgNfXrgXms1xF6l4AXDAbCT49Upj9qULYI0AnnbpuULmg4jcobLskEaq5k9oAwKbtlED8MSmYbBoXGyMaCJGtnZbWaRaYQQeq8ubac1cY0qnT4G1h4qedUbt6+2zsurg6dbaYmLBhlmIicQGhcdcvs1HgWhWDjvD3wbwomUL38oKaH1GqbhaHczttyhEF5gdzvPQpe1czLT9itbcMdHrcOF7RLL5Bw2f1DqPi5oKMvRLhHgwvsfe5CnZ6NgGfRmUiX3pchHatyLXRfCMN/9WgqTx380+Le8CCrKsBZ71niYrUXkTBcRfWQJGzta4k6OFci/bSpdqOeeTxuA9njM/NUCwnV2/pYkKVlmAMrIfrv6UCF2kLUJUewzNFIgNxVfWNr8o+8FDT1PpnWNKopv9Vp0EBDgsVyBRha+EbwuzrtzFHAiOBRcDNajroAFl2h7ip/1Mp6jQotuqLgej/Fvil+B5U+t/JYKPMgxoTctP8ox2KD0G+QJ8tVPbzPXo7m95cKx8tTQwhGeSVsczVpiZNxZUEqwtb2djN/zcZAEJFuTGrFyRvvq77dt4K7DdKss7I8HhPOOqisRrtGa805/vgNPzr7ZgC/Duhx39t0B3uesCw3tEtLTAnEfEw8IPJfofvwhtaoBjF7/VfdURH63w5iTc68a96D2up788P7GkMs1eH104SZSv6O1GOE9Hbbg=
Content-Type: multipart/signed; boundary="Apple-Mail-3A30A94A-1F03-49F1-8831-ABDA5B8D8DB4"; protocol="application/pkcs7-signature"; micalg="sha-256"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 0bbe5406-aefd-4d88-fcb7-08dacb4463de
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Nov 2022 22:13:01.9494 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 83d1efe3-698e-4819-911b-0a8fbe79d01c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN0P110MB1465
X-Proofpoint-GUID: drSQxWQrWW20P2SU0UjvV8xTFqujioet
X-Proofpoint-ORIG-GUID: drSQxWQrWW20P2SU0UjvV8xTFqujioet
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.219,Aquarius:18.0.895,Hydra:6.0.545,FMLib:17.11.122.1 definitions=2022-11-20_13,2022-11-18_01,2022-06-22_01
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 mlxlogscore=999 malwarescore=0 phishscore=0 suspectscore=0 spamscore=0 mlxscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2210170000 definitions=main-2211200188
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/1w7oBs2yfGiy9UlqcGsjYyR-35c>
Subject: Re: [lamps] Do we have a FALCON draft yet?
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 20 Nov 2022 22:13:17 -0000

Completely agree with Bas.

Regards,
Uri

On Nov 20, 2022, at 07:14, Bas Westerbaan <bas=40cloudflare.com@dmarc.ietf.org> wrote:


Not that I know of. If someone picks this up, may I urge them to add a warning to the following effect in the earliest draft.

The Falcon signing procedure is difficult to implement in constant time because of its use of floating point arithmetic. By default, it should be assumed that the timing of the creation of the signature leaks the private key. Thus, without careful consideration, it should not be used when signatures are created on-the-fly such as for TLS handshakes. It is safe if floating-point emulation is used (which comes at a performance penalty) or a (custom) FPU with sufficient constant-time guarantees. Verification does not use floating-point arithmetic and does come with the same concerns.

Best,

 Bas



On Sun, Nov 20, 2022 at 12:56 AM Mike Ounsworth <Mike.Ounsworth=40entrust.com@dmarc.ietf.org> wrote:

For completeness, we also have Kyber [3].

 

[3]: https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certificates/" target="_blank" rel="nofollow"> https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certificates/

 

---

Mike Ounsworth

 

From: Spasm <spasm-bounces@ietf.org> On Behalf Of Mike Ounsworth
Sent: November 19, 2022 5:53 PM
To: 'LAMPS' <spasm@ietf.org>
Subject: [EXTERNAL] [lamps] Do we have a FALCON draft yet?

 

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.


Hi LAMPS,

 

We have drafts for SPHINCS+ [1] and Dilithium [2] in LAMPS.

 

Has anyone started one for FALCON yet? (I need something to cross-reference the composite draft against)

 

 

[1]: https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-ietf-lamps-cms-sphincs-plus/__;!!FJ-Y8qCqXTj2!fJ0iZFzue-XVZBbJ18itKI-6e6y12C3g-v1B6dzJyGsg9sgUnSr-uGDYsyjTI-fvpuSJoWVhNP0h3vCR5xxUkcbW4I-VqfjlT2DqrQ8jQA$" target="_blank" rel="nofollow"> https://datatracker.ietf.org/doc/draft-ietf-lamps-cms-sphincs-plus/

[2]: https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-massimo-lamps-pq-sig-certificates/__;!!FJ-Y8qCqXTj2!fJ0iZFzue-XVZBbJ18itKI-6e6y12C3g-v1B6dzJyGsg9sgUnSr-uGDYsyjTI-fvpuSJoWVhNP0h3vCR5xxUkcbW4I-VqfjlT2A2XHyKVQ$" target="_blank" rel="nofollow"> https://datatracker.ietf.org/doc/draft-massimo-lamps-pq-sig-certificates/

---
Mike Ounsworth
Software Security Architect, Entrust

 

Any email and files/attachments transmitted with it are confidential and are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.

_______________________________________________
Spasm mailing list
Spasm@ietf.org
https://www.ietf.org/mailman/listinfo/spasm" rel="noreferrer nofollow" target="_blank">https://www.ietf.org/mailman/listinfo/spasm
_______________________________________________
Spasm mailing list
Spasm@ietf.org
https://www.ietf.org/mailman/listinfo/spasm