Re: [Suit] NIST selected PQM algorithms

Brendan Moran <Brendan.Moran@arm.com> Mon, 11 July 2022 21:26 UTC

Return-Path: <Brendan.Moran@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9ED3AC188724 for <suit@ietfa.amsl.com>; Mon, 11 Jul 2022 14:26:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.906
X-Spam-Level:
X-Spam-Status: No, score=-1.906 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=CoBXWMYm; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=CoBXWMYm
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C7C5wH1EPxkz for <suit@ietfa.amsl.com>; Mon, 11 Jul 2022 14:26:53 -0700 (PDT)
Received: from EUR02-AM5-obe.outbound.protection.outlook.com (mail-eopbgr00040.outbound.protection.outlook.com [40.107.0.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7D3A8C188730 for <suit@ietf.org>; Mon, 11 Jul 2022 14:26:17 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass; b=gx6NGIky7RMvBsAgekV5PrLKD3tMvxaCP/tffov07kA3glBKymX+uYawSAg+UPZOX2b1zVq0O/sWmZZ9rN1zZmciQF7P86x6vlzO0XH5foKIhxh4clrTeHvQ2CrUsCBjfmcEr9t09kHUP5iHoVXB8hSFHlCGawhrBnz6BI1N6TFodqvfwCaSQFac0X57gUM6m6jLFj5EEn7Mg8bnC/m7XT2JNsRiRRGkFzPHjFXha+qlOMaNl7m4xbnFggBBLCru3FI34d3NikZKuFHchEiC6ZVaKtyFSaTTUv9/upLIRpmBLyJMXyiBGH6Q4g7cCXylA/IiqaRNRXmzr9UW49rSSg==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=o/YQD7jz986CeCan2gxrDOYSKoErkCxB8aR4g4kWlBY=; b=KulbO3bm15hWB4BUQMDfGo0KYr7JJg/7fG6ozqRHquFuWaXwd1eUiMofXfa7ANw21SX5v6ipvpO7vgZict4pJYYuzOm72rutr9Mc9bBl3+nmXAeCUsQSOvEjEpqAg4JyJLEekfryVmh1P6hHXp6NSzCiG2I616ZagsJ71Zy5zmVzd/uP2SwKZZmoKWTdSl7S0BUwiS8TYmCY4nka+ntm5eDpR5wFa4pB9qf/7bMboV2IU9KBVRMIw1k3sARWsFJAdMpRmExVdnJsq6MwgFhdtaC1YQ6Pl/BBdvBhdLNq9T/zt2jLPARoFBXHGXnmg1PWBT3XyAC/nztrq0aNVk6FDg==
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 63.35.35.123) smtp.rcpttodomain=ietf.org smtp.mailfrom=arm.com; dmarc=pass (p=none sp=none pct=100) action=none header.from=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1 spf=[1,1,smtp.mailfrom=arm.com] dkim=[1,1,header.d=arm.com] dmarc=[1,1,header.from=arm.com])
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=o/YQD7jz986CeCan2gxrDOYSKoErkCxB8aR4g4kWlBY=; b=CoBXWMYmv9vtRtyBr6rZ164gS6a1v0NwG7oTdkQ0rykw7OWPJKHUqHOmDtbJvKTr9wECt7GjZ9KQexPH/FZlpjQhjlNpLQ5ReOAHNSwqWrvato2r8xTReBdqWKlFmUJCnS7qvgW8M8chBq7ekzksZuQNKVKQ1eSXwUND3jjkB+s=
Received: from FR3P281CA0050.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4a::19) by AM5PR0801MB1779.eurprd08.prod.outlook.com (2603:10a6:203:2f::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.15; Mon, 11 Jul 2022 21:26:03 +0000
Received: from VE1EUR03FT006.eop-EUR03.prod.protection.outlook.com (2603:10a6:d10:4a:cafe::1f) by FR3P281CA0050.outlook.office365.com (2603:10a6:d10:4a::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5438.5 via Frontend Transport; Mon, 11 Jul 2022 21:26:02 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com; pr=C
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT006.mail.protection.outlook.com (10.152.18.116) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.15 via Frontend Transport; Mon, 11 Jul 2022 21:26:02 +0000
Received: ("Tessian outbound 8e3d5168572a:v122"); Mon, 11 Jul 2022 21:26:01 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: abeeeaf4b4e1b398
X-CR-MTA-TID: 64aa7808
Received: from 125ecbf64039.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 3C7340BB-F23F-4780-9330-9898DA2074CF.1; Mon, 11 Jul 2022 21:25:54 +0000
Received: from EUR05-DB8-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 125ecbf64039.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 11 Jul 2022 21:25:54 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NQ5C+GVtCZY6YROf3kS2NzgQ33nRrqtwR94BQ7DEmOOQQdhn7xakQ0CDpyn8FQQDB/AAskw9s3tURNP9BF01Ho7kQ+CeQ42ATIvv6cfObAI2J95co4UCXUwoKYyQwVJMg24z4ENKtu/LyFd5gn1mwW9Wfha8scpePxp/bS1iFD0uuPG++0dmdWpI06qE3QRCpQ7Oj/0lVSdSGaNDupLIEuC0S1nSHLz4wTig8U5c2+dqae9HbRcxtTnNp+2ptpJG97AAkgPYXhbz7zFHuZNE37yWDn39wskOn2GZjW4yDxzi0+3juvo+I0dZS935LMhsyasArd0Q874h4CoQSTCtnQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=o/YQD7jz986CeCan2gxrDOYSKoErkCxB8aR4g4kWlBY=; b=QWxhcTsSSdDvAGinAAbv+fbNipi0u3KoJNL2+Tcf5CtWGiCx9ELh5R5F7s5A9NQWTfg2J4p1oi1o03Nb5MFOq/8ZHpHzy680+11kEc486iqxi5ZpKe6xMGIES0XqberDjhQI5A8vqTssmZbjm8Bhfl0u7qYY4stlegiNMUcPRm+G2f2aQO92yqcuKbwzZkja8l3Wr2ISdALl23QQhJojkHkf8m/nu47rytV9v3tPKgzLCbzAzBM5CTP9hMcqTgjLklv5LLik25cGHJPe4xqbWCXsUCPrG6yG6+0I9QJ6hRHCkybNQbCno9KF0hlKLtQwTbEZtD5ra4n7d12cw7veZQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=o/YQD7jz986CeCan2gxrDOYSKoErkCxB8aR4g4kWlBY=; b=CoBXWMYmv9vtRtyBr6rZ164gS6a1v0NwG7oTdkQ0rykw7OWPJKHUqHOmDtbJvKTr9wECt7GjZ9KQexPH/FZlpjQhjlNpLQ5ReOAHNSwqWrvato2r8xTReBdqWKlFmUJCnS7qvgW8M8chBq7ekzksZuQNKVKQ1eSXwUND3jjkB+s=
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com (2603:10a6:10:1ae::11) by VI1PR08MB3711.eurprd08.prod.outlook.com (2603:10a6:803:bc::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.15; Mon, 11 Jul 2022 21:25:51 +0000
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::f109:f88a:5672:ce59]) by DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::f109:f88a:5672:ce59%9]) with mapi id 15.20.5417.026; Mon, 11 Jul 2022 21:25:51 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: Russ Housley <housley@vigilsec.com>
CC: Koen Zandberg <koen.zandberg@inria.fr>, "suit@ietf.org" <suit@ietf.org>
Thread-Topic: [Suit] NIST selected PQM algorithms
Thread-Index: AQHYkr2P017V4aOW1kONSja7NbFN5q10n8gAgAN0dwCAASm7gIAARuyAgAAk3gCAAApVgA==
Date: Mon, 11 Jul 2022 21:25:50 +0000
Message-ID: <548CEB7A-28D9-4001-9C9D-A0DF1F89291D@arm.com>
References: <5ccdaef9-1e28-9d4e-8ab5-28179454b09f@inria.fr> <9EBE36DB-4E12-4849-ABA1-538330A778B2@vigilsec.com> <35BEE00D-AA5A-40CC-BBF1-867DDE21D597@arm.com> <219AA8B1-AEBB-49CC-BF1A-2FA670FFC5C5@vigilsec.com> <ED134EF2-86CC-474E-8970-F7AE04063358@arm.com> <6756AF00-6A54-4317-9732-829FA5F42B93@vigilsec.com>
In-Reply-To: <6756AF00-6A54-4317-9732-829FA5F42B93@vigilsec.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3696.100.31)
Authentication-Results-Original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-MS-Office365-Filtering-Correlation-Id: 8af0c293-60f8-4942-4570-08da6383f4ad
x-ms-traffictypediagnostic: VI1PR08MB3711:EE_|VE1EUR03FT006:EE_|AM5PR0801MB1779:EE_
x-checkrecipientrouted: true
nodisclaimer: true
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: V5XPjHposCUkFXJuDvAxoDoqxPEiQnBelOrCOfKw3DsgA3VaBcsYT14hB2o8/any9InfIXAAPYkwgClo4odScadNJrt5fNx70mDm0OnuvMrl9XH/BLqcIBS5m+YpMRqRNRfCEj3rAOaMQ776q4it01YeLeT6KzlmkNItxKnYmvu5F0u0+g7nu6IlNRvDF1AEygTiRNt+QTJ9k2tmK3ioxg9RqYDbTOJEqmDLHNC7an58+HK+GzHLxO32gM/6ux8zzOo/7Gnd5Ie7B5nbcb38VwN+VqavtxY7r318QCy0HJGpZU4PurmRNrckQ7Nu/j+5dTvnxj95C6ogGIB0VkjHv+uF23ruUXl+nLRpmaH1HjaPLxVMP7F7J1PNFnSIJ+SK+M0v6VmNKuPhT7PLe8OEo906SQSo3TkvanzM+149ybQAJuhdBTwrFO8aPZEv4V8ZRNnehYhfKRz6h85rJCF24vL/5+2/Q+780u2elrO00tNgtMr3A/rLsSggS9B6VVkFM45k27GJ7bWotJL05S4fmov2hini7TwIONgzuZzxzgARkenGW/VLqRzWRmmUtItVYlGPmzN34zFJG7/AFTRMF4H0YsI6N0wNRejd2F/zi+XwzKHH+JxBOkrAQGgiiFEYF+0bZdlBEVBfcRDO6q9WbEGi2b4HV/0FhB4CU1Faf7klJG2mQMu7b9cMEZT35AAqQ9zkCgeuM84hZC0mj+fwza2r65zQJUzgIJ0/5Pa/WcNusk1FEggsMTXyJvR6u1JzFJJbHffBCilRbrOfXpBf6QmCKyrtzTLDHTAMZHJmYFFpk6FpfLko34chM9UOFXB0V7ulx9MuOvpDq2I7Woq3KhjItsNEIjT4AOZLDJzsxtaZiauwyGOf1D7u7zk3nz5VbsBd3dkKy+bwO2/xElOcH6DYlLKrpGVFUIdCWNWG5X0=
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBAPR08MB5576.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(366004)(346002)(396003)(376002)(39860400002)(136003)(6512007)(41300700001)(8936002)(2906002)(478600001)(64756008)(66556008)(53546011)(966005)(26005)(8676002)(55236004)(6486002)(6506007)(2616005)(86362001)(33656002)(38070700005)(66446008)(66476007)(5660300002)(38100700002)(122000001)(66946007)(6916009)(54906003)(316002)(186003)(71200400001)(91956017)(76116006)(4326008)(83380400001)(36756003)(45980500001); DIR:OUT; SFP:1101;
Content-Type: text/plain; charset="utf-8"
Content-ID: <2B8DD076F5EECA439FFE09F8083D2655@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB3711
Original-Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT006.eop-EUR03.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: e7975875-c5f0-4615-2cb4-08da6383ed7f
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: jZrWU9rTyqmxj/RDx7YO6fcsPR0+C5Hz8LLOsGUBmV+jT10Fbn9WJxJhBUgqNjAUj77F4LM295Io4MWU37hjEzz8yNQ3nKw0FjZDq3e704hj92tIXq/rL1kyDy4nsTjT28QQrn4Jd9c5MXMubB55LXMALzzzxhV4Dg2jHuJL09kOJBFm/B1mIDslYwduJtpc0LjnKMTsZE/0xzaYCL5Auy1XqhdeWFGc/G9o2B8ie7ecAvs+YE9AFeBKAeNDVvd97YspKVSMxWm+3btkPYsy8GKd0zUyuxmRHTFnQ76tYc00dn0qJ87qFlaXGISssXSd07Hm/6n9HUsuboalmvTLThGCiUWkG6Fz4o1qDq7sUG33UqX5jfNjqUiWyYWDFEnPbhKFhCFOFf+qKarpNhd7zfA3PggyZDQ2ubr0mXRI6fwf1isdWUB1mdbCa/0ZXlKoijADz0pRrzUkQqv0C96OY/YgjQowsrB4Xa1vTh7nRhBdqxdawFXdI83pK0H8+gpBvCzzxfZF6iRPUb02nsNzrV9eOGq+/IODNe0CCO1zMtaCNzwuTt6iJ1/6/epd/WAVEMugA+w8+Ug934l9WFMTrXxBsoy/2IQWPt6DnCEJqP/ThY46ktzbzJYb0FQt4nU3CTt2UP+qi6gOVwE56G/1g6WRUvEJoX2bpFPsRd8WENX9EVyEJdyH7iNexl0DtHSl+Am6LsnpKWvpgpNTlVpyGxsSuazIN1rqR7n6zr9apsAJ6aazMmYU2ctUOMfO380/602O9ECGSY3mIoCULh4cnrrXwxzW8WgwNDfHiJ68wREfcaxql+0N1qdO/CEUfoNDsXcuCXp8Z4pzlDMYCKzF4S6K3TDX8sUFKWFXu+ibndy2AzCV3YHpGQhtCRYmJA7M
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(13230016)(4636009)(39860400002)(346002)(376002)(396003)(136003)(46966006)(36840700001)(40470700004)(5660300002)(2906002)(33656002)(40480700001)(36756003)(8676002)(966005)(6862004)(70206006)(82310400005)(70586007)(86362001)(8936002)(316002)(6486002)(36860700001)(4326008)(54906003)(40460700003)(26005)(336012)(186003)(6512007)(2616005)(47076005)(6506007)(356005)(82740400003)(81166007)(83380400001)(53546011)(41300700001)(478600001); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Jul 2022 21:26:02.1645 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 8af0c293-60f8-4942-4570-08da6383f4ad
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT006.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5PR0801MB1779
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/FICCbsUzpwrJX0TUwqUONJadgyg>
Subject: Re: [Suit] NIST selected PQM algorithms
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Jul 2022 21:26:57 -0000

What about the other parameters of SPHINCS+? Do you know if it is suitable for constrained networks and constrained nodes? For example, it would be good to understand the signature, public, RAM, and code sizes, and how expensive is verification in cycles.

Brendan

> On 11 Jul 2022, at 21:48, Russ Housley <housley@vigilsec.com> wrote:
>
> I like the lack of state needed for the SPHINCS+ hash-based signature.  This is preferable over the stageful HSS/LMS hash-based signature that we have been discussing.
>
> Russ
>
>> On Jul 11, 2022, at 2:36 PM, Brendan Moran <Brendan.Moran@arm.com> wrote:
>>
>> Hi Russ,
>>
>> Thank you for clarifying. I thought you were expressing a specific preference for SPHINCS+ above other Round 3 winners and I was hoping to get some insight as to why that was.
>>
>> Best Regards,
>> Brendan
>>
>>
>>> On 11 Jul 2022, at 15:23, Russ Housley <housley@vigilsec.com> wrote:
>>>
>>> I am not opposed to any of the NIST Round 3 Signature winners, but I gather it will be another year before there will be NIST standards.
>>>
>>> Russ
>>>
>>>
>>>> On Jul 10, 2022, at 4:37 PM, Brendan Moran <Brendan.Moran@arm.com> wrote:
>>>>
>>>> Hi Russ,
>>>>
>>>> Are you opposed to Falcon for SUIT? If so, is it just the maturity of the algorithm? It seems to have an excellent set of tradeoffs. Bearing in mind that we are only looking at the verify operation, there shouldn’t be any concern about constant time implementations or side channels.
>>>>
>>>> Best regards,
>>>> Brendan
>>>>
>>>>> On 8 Jul 2022, at 16:51, Russ Housley <housley@vigilsec.com> wrote:
>>>>>
>>>>> I think SUIT needs to look at SPHINCS+ as an alternative to HSS/LMS for the hash-based signature algorithm, but the NIST standard for SPHINCS+ will probably not be available for a year.
>>>>>
>>>>> Russ
>>>>>
>>>>>
>>>>>> On Jul 8, 2022, at 7:25 AM, Koen Zandberg <koen.zandberg@inria.fr> wrote:
>>>>>>
>>>>>> Hi all,
>>>>>>
>>>>>> NIST announced the first four quantum resistant cryptographic algorithms a few days back. Matching the earlier discussions on this list, NIST also selected FALCON for the case where smaller signatures are required.
>>>>>>> From what I understand of the process there is still a document that
>>>>>> should be released soon(tm) with the exact parameters that should be used for the algorithms. In any case I think this is good news for us as one of the selected algorithms matches what was preferred from the SUIT side.
>>>>>>
>>>>>> To be complete, the other algorithms selected are Dilithium and SPHINCS+, where Dilithium has large signatures (2.5 KB) and SPHINCS+ has even larger signatures (17 KB).
>>>>>>
>>>>>> Best Regards,
>>>>>> Koen Zandberg
>>>>>>
>>>>>> [1]: https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms
>>>>>>
>>>>>
>>>>> _______________________________________________
>>>>> Suit mailing list
>>>>> Suit@ietf.org
>>>>> https://www.ietf.org/mailman/listinfo/suit
>>>>
>>>> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
>>>> _______________________________________________
>>>> Suit mailing list
>>>> Suit@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/suit
>>>
>>> _______________________________________________
>>> Suit mailing list
>>> Suit@ietf.org
>>> https://www.ietf.org/mailman/listinfo/suit
>>
>> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
>> _______________________________________________
>> Suit mailing list
>> Suit@ietf.org
>> https://www.ietf.org/mailman/listinfo/suit
>

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.