Re: [Suit] NIST selected PQM algorithms

Brendan Moran <Brendan.Moran@arm.com> Sun, 10 July 2022 20:37 UTC

Return-Path: <Brendan.Moran@arm.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4875FC157B35 for <suit@ietfa.amsl.com>; Sun, 10 Jul 2022 13:37:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=EEmKwpHz; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=EEmKwpHz
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VY6BBTO0YMPq for <suit@ietfa.amsl.com>; Sun, 10 Jul 2022 13:37:43 -0700 (PDT)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30063.outbound.protection.outlook.com [40.107.3.63]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B991C157B43 for <suit@ietf.org>; Sun, 10 Jul 2022 13:37:42 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass; b=GKEvStUVuG5/Dl1F2s4Co+vulH87zWGTmjZfbghFr5b+p4cxgyAAeCAwNOAwx9cucGVnQgLwv/mamqu9lryrPnSX4Ov07RkKjdVIgGu6LRPxapWQRD1nV5dVjiL4SvK8pZLzbIGB9xed78tV4eyYxwqIacUOpZU3zPENgcNrmrpqQQzgfyAwNUz/yUkD6osOvOuxRxxGHZh2xLfF2hnYK5rJk57nJCg/CuqKrwcsHEMumBEXOe2X4+D6RmYRjEq7Lh9XOvSReetD4jZAnuHyCd2OtcbXea1esIKnC4ANY1TgrO1oMkP/UKpzeYvF0YYnXjN2uPVcxH/5MK4l8FBJTQ==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=PE0dt8JgqK/Knq+nC0Cj5kH+cF27tiK0xahZnG05/nA=; b=ByZ5zIyRmz8sZSsRtc2LdmA44w0pnb0rZFklyB27TmcaFq838Aq7lfBxxq79dXzWSQfzYp58UtIYyP+rjFHWP347UuWNrGcZWxEB9xyZdHnhxkvPFJ1Z0dUtNjHs4C/8fCXlPbQaNDUSbWvXtr/IyLZ845Rklv7Ke63dDzBEr/RsGwStyH9bM5FZ6NJyemtVMBF36+EHDpMy1HzRO/f14jnEwUW4bd931aoB8C4wbnyPSHFy8AdBvtrDoxywqOlvyoBtb/KzZADfFRdXwRvYo8eloRuMkpkM5vQBMBq+mjxAK8aoNzXEJ5lp2k8RAyTK99FjNFfmA+xTT8y/aCjsWQ==
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 63.35.35.123) smtp.rcpttodomain=ietf.org smtp.mailfrom=arm.com; dmarc=pass (p=none sp=none pct=100) action=none header.from=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1 spf=[1,1,smtp.mailfrom=arm.com] dkim=[1,1,header.d=arm.com] dmarc=[1,1,header.from=arm.com])
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PE0dt8JgqK/Knq+nC0Cj5kH+cF27tiK0xahZnG05/nA=; b=EEmKwpHzZXaS1VeYktXoWmVhZJaEu5gyNTUlT/kiBle/U3+kcahTiw/tLZOQS6HGIwT2LWkQE6htHop5r/l6B7eZsPNReRKM3u5lPr52hpIcFSI7753Krb6vIGW90Vw5g+BSMDob/IK5aPKJ+MeF8W2+sSd4N/oVIXwAJ9m7MvE=
Received: from DB6PR0601CA0026.eurprd06.prod.outlook.com (2603:10a6:4:17::12) by PA4PR08MB6192.eurprd08.prod.outlook.com (2603:10a6:102:ea::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.20; Sun, 10 Jul 2022 20:37:36 +0000
Received: from DBAEUR03FT010.eop-EUR03.prod.protection.outlook.com (2603:10a6:4:17:cafe::f8) by DB6PR0601CA0026.outlook.office365.com (2603:10a6:4:17::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.15 via Frontend Transport; Sun, 10 Jul 2022 20:37:36 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com; pr=C
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by DBAEUR03FT010.mail.protection.outlook.com (100.127.142.78) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.15 via Frontend Transport; Sun, 10 Jul 2022 20:37:35 +0000
Received: ("Tessian outbound 190453a6d737:v122"); Sun, 10 Jul 2022 20:37:35 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 3a33d79d3563c264
X-CR-MTA-TID: 64aa7808
Received: from f7bb8d9a42ff.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id B4B4D794-2BAE-4801-8FF4-AE1D37472B13.1; Sun, 10 Jul 2022 20:37:29 +0000
Received: from EUR05-DB8-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id f7bb8d9a42ff.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Sun, 10 Jul 2022 20:37:29 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Sf+2EyjD7lOFVA9pWmvpGNqb6rEJPe1pV/AckOp/2atlDPZJHgILZz1NcC9d0HHoSX4fLZHEkpta0GLKjDdM7fbqQjumGxCcCyHOp353GBWzFMx+rR5PSa/BK1bAxaXXYCpQEP3YEcLhrsEm/gfYcxuRLdp8kNJfVyiH9MoqDtCdRkrMwdnU6nPzI8+KWMU6wL17p/GKj9Y51mNvhXoAbWgK+9Wjzph9+JqH+00RGifs3Q4mN060RevVgqSIopadE+fkjDJe4RA4B1fsMe2w1QY/wyert5y8WaKiuSNMfCrf39sMUQ6gqO/onWx0tsCrcFMDH8RhQcYLjEz+kyLBQA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=PE0dt8JgqK/Knq+nC0Cj5kH+cF27tiK0xahZnG05/nA=; b=D7xIVxARWuPx647n2T9M9ZXP86Rs/NzRGrgTR+vzH8cr9rH3mSIlJ0KmaeY4d+y12pAtoNrvxBUoMv8GhUgfgK55jGZTHT6HcOVcHLNvdL3B242n/KSz2sTGCSb6tfcl9zlRblmYnmrsD8bmY21mSFNoCvvpCF/6DjQy+mzlLqj4HsRHXbNz3uWrQkJUF9e1/PG3o+krCZyesXvB82Jcsm3snNWnM6SuYbc1C4pzDLPPwJxXxodYkpTmH9n14nMyKTUuMg5Yt/AuM7dlS9riC0EwIO2ovYS3eB2jgUoJZwAurboWC2z5ag4ufcK72d+diwVmbum7/M4dEjoj1OhlVw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PE0dt8JgqK/Knq+nC0Cj5kH+cF27tiK0xahZnG05/nA=; b=EEmKwpHzZXaS1VeYktXoWmVhZJaEu5gyNTUlT/kiBle/U3+kcahTiw/tLZOQS6HGIwT2LWkQE6htHop5r/l6B7eZsPNReRKM3u5lPr52hpIcFSI7753Krb6vIGW90Vw5g+BSMDob/IK5aPKJ+MeF8W2+sSd4N/oVIXwAJ9m7MvE=
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com (2603:10a6:10:1ae::11) by AM5PR0802MB2465.eurprd08.prod.outlook.com (2603:10a6:203:9f::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5417.15; Sun, 10 Jul 2022 20:37:28 +0000
Received: from DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::f109:f88a:5672:ce59]) by DBAPR08MB5576.eurprd08.prod.outlook.com ([fe80::f109:f88a:5672:ce59%9]) with mapi id 15.20.5417.025; Sun, 10 Jul 2022 20:37:27 +0000
From: Brendan Moran <Brendan.Moran@arm.com>
To: Russ Housley <housley@vigilsec.com>
CC: Koen Zandberg <koen.zandberg@inria.fr>, "suit@ietf.org" <suit@ietf.org>
Thread-Topic: [Suit] NIST selected PQM algorithms
Thread-Index: AQHYkr2P017V4aOW1kONSja7NbFN5q10n8gAgAN0dwA=
Date: Sun, 10 Jul 2022 20:37:27 +0000
Message-ID: <35BEE00D-AA5A-40CC-BBF1-867DDE21D597@arm.com>
References: <5ccdaef9-1e28-9d4e-8ab5-28179454b09f@inria.fr> <9EBE36DB-4E12-4849-ABA1-538330A778B2@vigilsec.com>
In-Reply-To: <9EBE36DB-4E12-4849-ABA1-538330A778B2@vigilsec.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3696.100.31)
Authentication-Results-Original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-MS-Office365-Filtering-Correlation-Id: 182cf8aa-ae1b-48b0-234f-08da62b405e9
x-ms-traffictypediagnostic: AM5PR0802MB2465:EE_|DBAEUR03FT010:EE_|PA4PR08MB6192:EE_
x-checkrecipientrouted: true
nodisclaimer: true
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: gSl9O2I8CBX6Xhz9pwqgommvsZ7FQ6JpDqM3g766vp4sqwbcafsqr1PNjYyjAS3CiGEb6j9JSgGCnAw02I4tvhWDU+E4wUJq1s90C5lPwGn6b1kTG3Kllz98ZQcrASh45wgcqIUg221WsmKwoy1ChNUyaNY7U3cjxEDMlTfHcuOC730RVNuZJY41j3YBswTj4s4p3d1m/kqV3Ub65Wu9vCeK7X/QpsW0CW03JNB3BI82Mtpz2wVAg67L1PN33UHTAfvYBa+ohqlKVfhp+FDJHKR6U/He1vCfB6D347PnhQG6x2uiaVRusSFJGbGvaMoPoF8km4dQq7+dlYNcR5BU3ampWZxT+jT4L9N8NIkw19ccQBKbmQRFaXSljStm6S4Y+jX3RZWc0Od7oCmNF79fO0LRiCW+tqveBPh1M6jdyiogsfapBeVf6hWxB+oiLulUroKuCzixBT/L070xBY5oSK/RaEccWXSSCs9F11YIRtmNJedDkJgKw+RIzX9e2BHBQm5gNhJYVnUkvlRi/gZgWUqHNiPpgrtSG5K8IIhEG+196bAmfu6lLQT+5XB+JEaHQWHQ0SMCKgcHg9kQpTqpHWuHeUX8sLYx0EL1lBK/15Sk+UYq/hQHKsH4Lsm/MCx4ILhWAEadcpm1tt4aU/kc9JHyBfJXS1w6UdOucnAAwe65L7wqrC5be23C8zSbB2uP5dl3i744iJEbLM0C0Sqo0XtlK9kJX7dqd/7NKza7hMUYYNlNo2qXzp/FPXrSoA8XWPGY1j3pDn+KhbNYJijI/11Zy4IMvOK7umKSTOcqT8WZq3/4lhnlTAvNePRtqqHXRKPs4EcCUMEEOBN77GYCMtQ9xg/lq4O/qsF2i/3gb23MlId3ksptX1bO+kQBI+E7
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBAPR08MB5576.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(136003)(39860400002)(346002)(376002)(366004)(396003)(41300700001)(6512007)(2906002)(55236004)(36756003)(86362001)(33656002)(6486002)(478600001)(26005)(6506007)(53546011)(966005)(71200400001)(316002)(91956017)(6916009)(54906003)(2616005)(38100700002)(122000001)(38070700005)(8936002)(5660300002)(64756008)(8676002)(66556008)(66446008)(66946007)(76116006)(66476007)(4326008)(83380400001)(186003)(45980500001); DIR:OUT; SFP:1101;
Content-Type: text/plain; charset="utf-8"
Content-ID: <50DC92AE62B96A4DB80ECFBAD4FFAE20@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5PR0802MB2465
Original-Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DBAEUR03FT010.eop-EUR03.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: f796dd80-9f44-4208-c3a6-08da62b400f6
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 5sbBJgxYrK5X64VGk7x9gE1Ufr9MRAcvhLyRZlnGeuw6i4Gta5Pzl0VIHaw5c/6QjeaikZgi3rLyqruURG/kzPRyRHz/5Jo887DMZeWEGTcVDYPDYA2ukotE+CTMoGNroTpMduCIgc1oFxdwx4Le7RbsVwrPEQ/5z4ommucR81bG1PRdKA5ChNe2Ee8D02tEmiCN2xz7MEz+CQ/EVnULoDK6F9hkiwCdnGkJg9oU8vbvsVMSFsbwOqW5CV5UkxSNk6FmkiytKATJSZy4XSD/YmZXYFyY5lrXAejSgjS92alCGY5iRSbrpRGrBmibgzkzTwJpqbYYTglWHgKAj8tkFqXmiXGytHdl2Kuq5844g7cEU3PaUkf26X9J1yuYPxZLv24J2AZq64sLlDqdUcLV9yXUfQxY9VwngEmG6DAmqc5woPL/P/Kj8AQ0vcwSJlsd/hweygJ+ZoYL52zSvWpgABPeQwzOv9E3IqYsX4993k/meTXvK4MGpLyri9bGfCHzK9BriztuZyFbaOPe8BrwQcLBWCMpfnbIIpj1ZX286uAjiDjvr+TptTt4I9zkNHFSGLBPnKn6fWBChZFBzppTCKrVJl9uyw8ybTLzJNTX1N5LOQTixcPfLw2BxPJdh9CZWvnQzN41GZ09V97Ii0NjFiCzbXklIzsthXIQ/J3PiiRykUpKI5PfQXEk60SoSuMcyZmdeJyzXt1ItdILlPG+JZFhhAywpelaPi6xkUuRvkmzsrIzpXC3n9vrN/RB28KQYU3RyUdJOZTeIEt2jxNN53Qoc5lyTz+SkxVQhqHYqSQYGiC9C4vJTzITYZn3Fscp
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(13230016)(4636009)(346002)(39860400002)(136003)(376002)(396003)(46966006)(36840700001)(40480700001)(82310400005)(8676002)(4326008)(36860700001)(70586007)(36756003)(82740400003)(81166007)(33656002)(356005)(478600001)(86362001)(47076005)(2616005)(83380400001)(5660300002)(336012)(6512007)(41300700001)(54906003)(6486002)(966005)(186003)(6506007)(53546011)(26005)(6862004)(8936002)(2906002)(316002)(70206006); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Jul 2022 20:37:35.8990 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 182cf8aa-ae1b-48b0-234f-08da62b405e9
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: DBAEUR03FT010.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA4PR08MB6192
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/iy53_lq0rASO4_PlpOL1V6ccJ9A>
Subject: Re: [Suit] NIST selected PQM algorithms
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Jul 2022 20:37:48 -0000

Hi Russ,

Are you opposed to Falcon for SUIT? If so, is it just the maturity of the algorithm? It seems to have an excellent set of tradeoffs. Bearing in mind that we are only looking at the verify operation, there shouldn’t be any concern about constant time implementations or side channels.

Best regards,
Brendan

> On 8 Jul 2022, at 16:51, Russ Housley <housley@vigilsec.com> wrote:
>
> I think SUIT needs to look at SPHINCS+ as an alternative to HSS/LMS for the hash-based signature algorithm, but the NIST standard for SPHINCS+ will probably not be available for a year.
>
> Russ
>
>
>> On Jul 8, 2022, at 7:25 AM, Koen Zandberg <koen.zandberg@inria.fr> wrote:
>>
>> Hi all,
>>
>> NIST announced the first four quantum resistant cryptographic algorithms a few days back. Matching the earlier discussions on this list, NIST also selected FALCON for the case where smaller signatures are required.
>>> From what I understand of the process there is still a document that
>> should be released soon(tm) with the exact parameters that should be used for the algorithms. In any case I think this is good news for us as one of the selected algorithms matches what was preferred from the SUIT side.
>>
>> To be complete, the other algorithms selected are Dilithium and SPHINCS+, where Dilithium has large signatures (2.5 KB) and SPHINCS+ has even larger signatures (17 KB).
>>
>> Best Regards,
>> Koen Zandberg
>>
>> [1]: https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms
>>
>
> _______________________________________________
> Suit mailing list
> Suit@ietf.org
> https://www.ietf.org/mailman/listinfo/suit

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.