[Suit] draft-ietf-suit-firmware-encryption: HPKE for COSE

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Mon, 02 August 2021 15:09 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CE043A08A6 for <suit@ietfa.amsl.com>; Mon, 2 Aug 2021 08:09:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=2FRLxFl7; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=2FRLxFl7
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kvMF30ODv7ZV for <suit@ietfa.amsl.com>; Mon, 2 Aug 2021 08:08:58 -0700 (PDT)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30072.outbound.protection.outlook.com [40.107.3.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 807D33A0896 for <suit@ietf.org>; Mon, 2 Aug 2021 08:08:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uBA8uPhIJzC4FBx/xSRRqtwIc7yc5ZXeu00k3Ye5dM4=; b=2FRLxFl7bxObBocd8nHdhLELukQW0yH/Qbt1ETq+Q+W5GqsfkM7Y0bImXE4QzBctdu+6Aq3lGI1XoWXl8z2hsZ1Rk01sjMtseAUZYWI6ReJQM5zWQGlY2DSIKaCdrxgR4YXPBBc1YxTcupOGAWqdg96QHnvrRrOzAX4VnpEUalk=
Received: from AM6P191CA0105.EURP191.PROD.OUTLOOK.COM (2603:10a6:209:8a::46) by VE1PR08MB4893.eurprd08.prod.outlook.com (2603:10a6:802:aa::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.21; Mon, 2 Aug 2021 15:08:52 +0000
Received: from VE1EUR03FT063.eop-EUR03.prod.protection.outlook.com (2603:10a6:209:8a:cafe::2a) by AM6P191CA0105.outlook.office365.com (2603:10a6:209:8a::46) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.17 via Frontend Transport; Mon, 2 Aug 2021 15:08:52 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT063.mail.protection.outlook.com (10.152.18.236) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.18 via Frontend Transport; Mon, 2 Aug 2021 15:08:52 +0000
Received: ("Tessian outbound 8529ae990a93:v101"); Mon, 02 Aug 2021 15:08:51 +0000
X-CR-MTA-TID: 64aa7808
Received: from 6e8603622d32.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 7921F660-D741-4BDC-A654-3388FD1F0BB2.1; Mon, 02 Aug 2021 15:08:45 +0000
Received: from EUR05-DB8-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 6e8603622d32.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 02 Aug 2021 15:08:45 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bDNf7WXDDJybxJBFQiknMy9sDdg2qMNCcQBiICBzIdMgGSaQRxnGvuHK7BPn6K2YBTbtnkVfMC9cKYXl1CptbqSfFW+4p+uMwFgz5Y5xPRmvhFZysVMutwVn1oG16Bg2+XajqzLOaYtvbnxj2jWTHpfN+K1b6+Id9ukaLHeMZEhdBxWCrS2trXugvYkT1/0XXaJFipTySE8OqfTWkinrMmrkCIvdtGYzAtz0Ga7+IZpIA34YP0W+cyX9YH/5J8A5KdM93DbavnktuLwO/hfdZi6OXhEM6QVawit8JRQe8HjLrOcc0JRIuCu/kc0ia8Kfa25dNjlGjGoAzSV2+gdMjA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uBA8uPhIJzC4FBx/xSRRqtwIc7yc5ZXeu00k3Ye5dM4=; b=RZErPRBLQcCTGCk+V9oJc/6CKbJYW7bsFjB5UeWf3h6c6jTQ7QSgv2ZTvPiAFlrYixVHmhEEsx5vNSI5JXAIhnxm3/SWiByT7B4PGw/jLrHRhnfnHejEDiaDs7vTDIJUg8zltq5EUoSMOXVKYDJ+4g8rBEL0WQ0Pac+3E1dMVMqBP8Wg9Cl4IJqWZJ90I5JofdYF3y1QMqpCIomKsPoTFJaowv8aT2dfKhZc4UseBjW9dr1crA3AdnDVYUZmphazqqanS+lY7SyfkMMSlMcTJTxtF/XYxXLqceyuW+cBCMNzWVDXzjX9cPppBt2MvqT4qv2k16balpGXhC9STpHhRQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uBA8uPhIJzC4FBx/xSRRqtwIc7yc5ZXeu00k3Ye5dM4=; b=2FRLxFl7bxObBocd8nHdhLELukQW0yH/Qbt1ETq+Q+W5GqsfkM7Y0bImXE4QzBctdu+6Aq3lGI1XoWXl8z2hsZ1Rk01sjMtseAUZYWI6ReJQM5zWQGlY2DSIKaCdrxgR4YXPBBc1YxTcupOGAWqdg96QHnvrRrOzAX4VnpEUalk=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DB7PR08MB3578.eurprd08.prod.outlook.com (2603:10a6:10:50::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.26; Mon, 2 Aug 2021 15:08:45 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::55c7:8f34:351:9518]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::55c7:8f34:351:9518%3]) with mapi id 15.20.4373.026; Mon, 2 Aug 2021 15:08:45 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "suit@ietf.org" <suit@ietf.org>
Thread-Topic: draft-ietf-suit-firmware-encryption: HPKE for COSE
Thread-Index: AdeHpCDoNCOdNbhWSi+aN/5EDvIIAQ==
Date: Mon, 02 Aug 2021 15:08:44 +0000
Message-ID: <DBBPR08MB5915A2D3ED245147B68AF7ABFAEF9@DBBPR08MB5915.eurprd08.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 472714F5C4AACB4BA1EB58C5ED61301F.0
x-checkrecipientchecked: true
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 953b8fe3-6bd6-4623-048f-08d955c77074
x-ms-traffictypediagnostic: DB7PR08MB3578:|VE1PR08MB4893:
X-Microsoft-Antispam-PRVS: <VE1PR08MB48930661D05B337B46F42ADDFAEF9@VE1PR08MB4893.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: kdQsd5GCSU/3ijHjPh4zw2i5GXzOhp3UzJZeFO67ZtK89+g1MMOHr+wMDc2Aq5/hHjSNywsW0n50ZI7CEnLHnO+NA5cc8BbqtYuE9HFpNnlltCoXdwP2ghbBzuaCltvWbQyMG9h0cM7g+CUYlx2ISmhCBEloNjvs15dqFlHx8SSyoNJql9QRaR193C+/jgl3ZvvkDw859XnJmiRLzU6vq4iEJ2f7MKXg+lmjVM1irZP00OE1E+7a1XQtxcSxaTQpCwftKsZy6N320kwPQm663KOaJcDrf3LjQV34Bbz59rnNkdlRwpSIbaz28p8TYlbvEPLHjD40nHpjxFzCYue3eqfIpNRTA9M8xY4AEyy/hqenSmHAwYkjAsVhSdLudauZ59m1nRT0lgJV4St9clWy9Tij4r2gc7O8Mk3tSLlgdplrdd0uL2NRZetv3sNRKxzf1miNgUc3L8Ag9LZmQyxoKvrosOQ6y62eJSGCO13v7pbMrrokMxaGRaaTNWY9/Ch3JIggRsYSiKr2wRyfDjU8bdw2rGhS4lYoRdi+zBhjcSSkgUy0kCNEz/NzuBL9VqsvD1V+d2mTiLTXxwANULmnCVo8JZCNRiNXs97qGVDBaTD5jBkmZ9DFjT6PzLR5mrrkwVTLqw1nQvZ6ew1d8oLEqCnfeGqpqKvEyvhIRKA9gHfRW40JIGXW2RMBcNoEsKihofOMF8iH29YxcMbbyuSpDQ==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(136003)(39860400002)(396003)(366004)(346002)(376002)(4744005)(5660300002)(26005)(33656002)(6506007)(7696005)(83380400001)(86362001)(8676002)(8936002)(76116006)(478600001)(9686003)(71200400001)(66946007)(186003)(66476007)(64756008)(66556008)(52536014)(66446008)(55016002)(38100700002)(6916009)(2906002)(316002)(122000001)(38070700005); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: FTKe6d5DUjWlNquJl8f1ko1g/dSq36e6pUh3tR2eW9PyZEJ54c/zbBTQYDYves5rgJvmeR0DjT+L2kULjDw7BDA9fmmKFc17ypmcgNNnMWX3vnWOV/2ftvuRDSBFuPmzsVbAOtwY0i7ScnVlHphsEwvfl6B6mZinK3IDO9TvOOlZQy/kpEuGTcK1S3D3dDWysdMmesRdZyNRrh1jUG/iVhbcr37bIsdOCS3odB42gqfYYUFyDEJ3DP8pdsqgqw26Az8xCT6bH5woIxosjsPYA0hs6I0o9wJXxVnAfi+acFVWdWId8G0dOVInwOAMWxDG8Pg9GrhoOYxcF1cDG1wYgBcACKDcPorJ8CV6WKnkJ9FSf5GgzMN4ylCwnor7ZNqwKY4kKmmBsJ4YTNFpsGrPfe5OvxBJiwlGGLekHMXHiYuSp99xNH9+NaYUtXFkCIAX21jB4bLtNoywR4fYhlV0L2Dy84KSV2RBQhMbNEnQO7XRLqeiRZznLXbSWtN35E1645w8aFIWtONH06vsGeVcaa0cagtQE3TNwmyGbV370BJej1/834v7yyH1idrw/wCVAK7HVk99ktMnsuaCMSMgPwVtfq/PC3jB85FZ1nvcfOVwl2vYZKkLEH5sO5a8p+IMLrF5DglAgb5L/08fdZCNkBzHICOI5hjCEZGRXQx4ELFibIJL74UgfIIRkVvxZR5JaG1SY5IAyKtAaP4U7nW/YxTkf6icQRKf6LePtzRDQx5EZYc8wkB/AlnBd8c+mgMpnyI3qcivNS6rNrfyHaLdn22yms4l/xcJRJfTaXIJaACgIo274+Sft1DVu8nSkbYhSQBpgAa5KNiSxCv9bQCL5BbIn2rc8tljXB1WPHDqnWU34MantoTgMD6Aqr4OPKAacLL8kBGy2vTDl36ihwdIXrac3N+rIsJJa7uRtpGX0IqoWw5fwWKgPmQq5OUoLykUqE7MbP6nGxrxemYeRe+RAakdtb69JbTZnheN/xjo0lgrUuh+ubDCNXFT22/Xw3exSLajz9MwzRqrJHhrL+u6SkRW/52WwCVydMn+cCY7sU8ftjd7Ney7SRjKYas2s51CYRPlacOE3iaqIb4fA7vWOsEPRxGeUKe6q8l57kAC4EY+KK79pbjuFtjOaQJCO4mIUFYKBpY+n2l3pf6HlVyO9KBrLeG2vhxGJ4+hHGe6IKWh3lpvF5JRLd5qCZeUuDupZYDZ5oZ1+Sr2fEb7nT9KmufKAP1Y+IMbuTBOPeufGksdi1l7DVhSZBDXo0KY3Vv5ri014iJR574GyWvSjmuQst1uEmYV/JEJhiqTdwY3KjkueXen/vQ/m3I7piGszkHy
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_DBBPR08MB5915A2D3ED245147B68AF7ABFAEF9DBBPR08MB5915eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR08MB3578
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT063.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: fdbc100c-dbbd-4045-16df-08d955c76c1c
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: uZnEF2OcRgsRCjKstWYmFsEtgWVx3KeQCh9G+0DoV0j0hRGcQK/HlhfVjNOOnFBik5tE2LsQ2L7pVarP5NrdmJEL4redaI5g927IMShjnFfcmpvA6fnWwIhPF22mX9FCIAgivu7YM9IM+hdpUZCnqEkG4Hxhz4/RV0IJi3fV2KguvOn4p3pmWCwcQ3+CWilkfI1TNad0UEqGPzhxFCu0I2KMKVBzv475nAIcbuncvRsxjUU59wQcwmxXUUKD+MBfbNk8TAd+3pZSPjSdPvlPW8xXOcGVPvUQJtUmftukDHrY3AW9G/yP1DK9rBfyHzrI868tv/Vve+OP3UGj9U3GkzIS7Agpw2mo44Ept5qYbQcFGWwMQ5M6ktZNz+HlRCh19qIUyhfbGuaF+l7heg9W9Rc7W84FSbPKo8ujyKvjk13sxx8WBHcu6Q0wMBSWLOrXaha5NJEiAR9BPu2uG1E59dE/Vqs6nQJJoil8mGRnn3G4tytO6EYR5GwTqLppVzQOHkbhuUcO1XGTg5t80wVqkDe9W9X/kEmplspICS8TnxO3biNYoauoKztRmJB/QfPHUZgT1JAadsZJQ8CKVkXdjH5jXQAAjpcVIPwwrGnFQZH7MlD8O+RbGBYRn9zBzB7BQYgPPuGOL0k+PChlTJ/Yr8F+rlBjnaXXFjL+0APi9p/PCUiUXRooE05Egu8n9+BwlnBBYwvoRLXhTrThJbf47Q==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(136003)(376002)(39860400002)(396003)(346002)(46966006)(36840700001)(26005)(6506007)(70586007)(478600001)(82310400003)(6916009)(5660300002)(316002)(52536014)(2906002)(70206006)(7696005)(83380400001)(186003)(36860700001)(8936002)(336012)(55016002)(81166007)(82740400003)(356005)(33656002)(47076005)(8676002)(86362001)(9686003); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Aug 2021 15:08:52.1530 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 953b8fe3-6bd6-4623-048f-08d955c77074
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT063.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VE1PR08MB4893
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/SF_P7NfhlNhS_TLolyfZeUs57RE>
Subject: [Suit] draft-ietf-suit-firmware-encryption: HPKE for COSE
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Aug 2021 15:09:05 -0000

Hi all,

Currently we have newly introduced the use of HPKE for COSE in the firmware encryption draft.

HPKE could, however, be useful for other applications using COSE as well.

So, the question is: Should the HPKE functionality be defined separately for use with COSE or be defined specifically for use with firmware encryption only?

The answer to this question is a bit speculative because we have to guess whether HPKE will be useful for other applications using COSE. Currently, HPKE is used in various IETF protocols (MLS, TLS Encrypted ClientHello, Privacypass) but none of those applications utilize COSE.

Thoughts?

Ciao
Hannes

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.