Return-Path: <ietf@augustcellars.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id D4F47130E0F
 for <suit@ietfa.amsl.com>; Thu, 21 Jun 2018 13:15:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.09
X-Spam-Level: 
X-Spam-Status: No, score=0.09 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989,
 RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001]
 autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id Lm7sZIh8zFXe for <suit@ietfa.amsl.com>;
 Thu, 21 Jun 2018 13:14:59 -0700 (PDT)
Received: from mail2.augustcellars.com (augustcellars.com [50.45.239.150])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 5A133130E14
 for <suit@ietf.org>; Thu, 21 Jun 2018 13:14:58 -0700 (PDT)
Received: from Jude (50.252.25.182) by mail2.augustcellars.com (192.168.0.56)
 with Microsoft SMTP Server (TLS) id 15.0.1347.2;
 Thu, 21 Jun 2018 13:11:51 -0700
From: Jim Schaad <ietf@augustcellars.com>
To: 'Russ Housley' <housley@vigilsec.com>, 'Dave Thaler'
 <dthaler@microsoft.com>, 'Brendan Moran' <Brendan.Moran@arm.com>
CC: 'suit' <suit@ietf.org>
References: <31676.1528913351@localhost>
 <04f401d40349$33a58b10$9af0a130$@augustcellars.com>
 <0CDB8D05-0214-4749-9907-5A1B0B4A2191@arm.com>
 <697B1DC9-B1DE-48BA-ADC6-EF936208AFCE@vigilsec.com>
 <9906B2BC-BFC2-4F83-A0F6-FFCC81912237@arm.com>
 <DM5PR2101MB0805F9D2D2372C4AEE2C7E5BA3760@DM5PR2101MB0805.namprd21.prod.outlook.com>
 <AD7239DB-B6C4-4D3A-8DDE-ACA9CB430263@vigilsec.com>
In-Reply-To: <AD7239DB-B6C4-4D3A-8DDE-ACA9CB430263@vigilsec.com>
Date: Thu, 21 Jun 2018 13:14:47 -0700
Message-ID: <014901d4099c$82be6150$883b23f0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----=_NextPart_000_014A_01D40961.D6688A00"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQHwZWPvfC0oH/KJpPKzh2KFlMHiSQFvEQHtAbrOmkYA7bECGAHMf9bXAeyn/S8A68Uj4qPsiX3w
Content-Language: en-us
X-Originating-IP: [50.252.25.182]
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/wn20UI3DypU8ztI5UTrmZW8r-8M>
Subject: Re: [Suit] draft-housley-suit-cose-hash-sig
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>,
 <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>,
 <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Jun 2018 20:15:03 -0000

------=_NextPart_000_014A_01D40961.D6688A00
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

I have not looked in detail at the XMSS signature structure  and key =
structure and would want to do so before making any type of definitive =
statement.  However different drafts defining the different signature =
structures is what I would generally expect unless there is a huge =
overlap between them.  I would guess that the key structures are also =
different and thus would probably need to be identified differently.  =
This is based on the fact that a algorithm variant byte is placed at the =
start of both the key and signatures.

=20

Doing this separately when we know they are going to be used (or =
potentially used) makes more sense to me.

=20

Jim

=20

=20

From: Suit <suit-bounces@ietf.org> On Behalf Of Russ Housley
Sent: Thursday, June 21, 2018 12:44 PM
To: Dave Thaler <dthaler@microsoft.com>; Brendan Moran =
<Brendan.Moran@arm.com>
Cc: suit <suit@ietf.org>
Subject: Re: [Suit] draft-housley-suit-cose-hash-sig

=20

I am advocating LMS. I think it would be appropriate for an advocate for =
XMSS to write a similar draft for that algorithm.

=20

Russ

=20





On Jun 21, 2018, at 12:08 PM, Dave Thaler <dthaler@microsoft.com =
<mailto:dthaler@microsoft.com> > wrote:

=20

This is similar to a question I asked as well, whether the IETF only =
needs LMS or whether LMS is just an instance in a larger class that =
might be needed, and what the scope of the draft should be.

=20

If the draft is not SUIT-only (e.g., allowing use in OSCORE, etc.) then =
it sounds like we might need the ability to support more than LMS for =
some use cases.

=20

Dave

=20

From: Suit < <mailto:suit-bounces@ietf.org> suit-bounces@ietf.org> On =
Behalf Of Brendan Moran
Sent: Thursday, June 21, 2018 9:03 AM
To: Russ Housley < <mailto:housley@vigilsec.com> housley@vigilsec.com>
Cc: suit < <mailto:suit@ietf.org> suit@ietf.org>
Subject: Re: [Suit] draft-housley-suit-cose-hash-sig

=20

Hi Russ,=20

Thanks for the clarification. I agree that a larger signature is not =
what we need in SUIT. However, for the COSE draft, would it not make =
sense to provide for both LMS and XMSS? I don=E2=80=99t pretend to =
understand all COSE use cases.

=20

Thanks,

Brendan






On 21 Jun 2018, at 16:43, Russ Housley < <mailto:housley@vigilsec.com> =
housley@vigilsec.com> wrote:

=20

Brendan:=20

=20

Yes, there are two CFRG algorithms for hash-based signatures.  I prefer =
the one McGrew's document, mostly because it is more straightforward.  =
There is some speed improvement for the additional complexity in XMSS at =
the cost of a larger signature value.  To me, the speed improvement is =
not big enough to justify the larger signature size.  Your mileage may =
vary.

=20

This paper describes the difference between the two:

=20

 =
<https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Feprin=
t.iacr.org%2F2017%2F349.pdf&data=3D02%7C01%7Cdthaler%40microsoft..com%7C3=
02d0f10626b454a732308d5d7907359%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C=
0%7C636651937771383092&sdata=3DzDGqR2NskjJzyVVcCEg8suPo3Lt9b6xLI1lxaYlWrb=
Q%3D&reserved=3D0> https://eprint.iacr.org/2017/349.pdf

=20

Russ

=20






On Jun 21, 2018, at 11:11 AM, Brendan Moran < =
<mailto:Brendan.Moran@arm.com> Brendan.Moran@arm.com> wrote:

=20

I see that there are two current drafts for hash-based signatures:

 =
<https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Ftools=
.ietf.org%2Fhtml%2Fdraft-mcgrew-hash-sigs-11&data=3D02%7C01%7Cdthaler%40m=
icrosoft.com%7C302d0f10626b454a732308d5d7907359%7C72f988bf86f141af91ab2d7=
cd011db47%7C1%7C0%7C636651937771393097&sdata=3DCTRx3BW3duXIREYxP4CyR%2BQY=
63qYgi2vqjnUM9uKqQM%3D&reserved=3D0> =
https://tools.ietf.org/html/draft-mcgrew-hash-sigs-11

 =
<https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Ftools=
.ietf.org%2Fhtml%2Fdraft-irtf-cfrg-xmss-hash-based-signatures-12&data=3D0=
2%7C01%7Cdthaler%40microsoft.com%7C302d0f10626b454a732308d5d7907359%7C72f=
988bf86f141af91ab2d7cd011db47%7C1%7C0%7C636651937771393097&sdata=3Dpii%2B=
oa8SkTt7PLarq0P%2FKXL4WBVpNwLzGSIxEgZG5YU%3D&reserved=3D0> =
https://tools.ietf.org/html/draft-irtf-cfrg-xmss-hash-based-signatures-12=


=20

I see that you have referenced the mcgrew draft rather than the =
IRTF/CFRG draft. Could you please explain what the difference is between =
these two drafts and why the mcgrew draft was a better choice than XMSS?

=20

Thanks,

Brendan

=20






On 13 Jun 2018, at 20:03, Jim Schaad < <mailto:ietf@augustcellars.com> =
ietf@augustcellars.com> wrote:

=20







-----Original Message-----
From: Suit < <mailto:suit-bounces@ietf.org> suit-bounces@ietf.org> On =
Behalf Of Michael Richardson
Sent: Wednesday, June 13, 2018 11:09 AM
To: suit < <mailto:suit@ietf.org> suit@ietf.org>
Subject: [Suit] draft-housley-suit-cose-hash-sig


I have read the -01 draft today.
I have not read [HASHSIG] yet.
I thought I'd try reading this first, to see what questions I had.

I have implemented COSE Sign1 with ECDSA in Ruby, so I have a grasp of
what we are trying to plug hash-sig *into*.


Suggestions:
1) would the structure show in section 3 be easier if it was described =
by
  CDDL?  I'm rather unclear about this.


No - this are not CBOR structures they are pure binary strings






2) I din't understand section 4, where it says:
     o  If the 'key_ops' field is present, it MUST include 'sign' when
                creating a hash-based signature.

     o  If the 'key_ops' field is present, it MUST include 'verify'
                when verifying a hash-based signature.

Clearly this is not something that travels over the network.  Is this

somehow




indicating how to understand if one is dealing a public (verify) key or =
a

private




(sign) key?


The key_ops field can be considered to potentially be transported over a
network.  It is part of the COSE_Key object rather than part of the
COSE_Sign1 object.






3) the variations: LMS_SHA256_M32_H20, and LMOTS_SHA256_N32_W2,
etc. are
  listed, but I don't know if they need to be carried in the signature
  structure somehow.


See the [HASHSIG] draft.  It is encoded into the signature structure and =
the
key type is in the public key structure.






4) I thought that perhaps we'd need CBOR or COSE specific way to =
transport
  the signatures.  I guess I shall read HASHSIG to find out what the
  signatures look like.


We have that.  This is looking at a signature just like ECDSA would =
produce.
This is a different "ECDSA" replacement.






I understand draft-mcgrew-hash-sigs-11 is being advanced by CFRG.
I believe that SUIT should adopt this document, and should do so in the
current state.

I would like to have some examples in CBOR/COSE worked out with private
keys available in the appendices.


Always a good thing to have.

Jim






--
]               Never tell me the odds!                 | ipv6 mesh

networks [




]   Michael Richardson, Sandelman Software Works        | network

architect  [




]      <mailto:mcr@sandelman.ca> mcr@sandelman.ca   =
<https://na01.safelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2Fwww.sa=
ndelman.ca%2F&data=3D02%7C01%7Cdthaler%40microsoft.com%7C302d0f10626b454a=
732308d5d7907359%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C63665193777=
1403102&sdata=3DM7Tnkm9SzFy0ImJTiHRTBVDGfi3pR1vFixMCWskWmOo%3D&reserved=3D=
0> http://www.sandelman.ca/        |   ruby on rails

[





--
Michael Richardson < <mailto:mcr+IETF@sandelman.ca> =
mcr+IETF@sandelman.ca>, Sandelman Software Works
-=3D IPv6 IoT consulting =3D-






_______________________________________________
Suit mailing list
 <mailto:Suit@ietf.org> Suit@ietf.org
 =
<https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fwww.i=
etf.org%2Fmailman%2Flistinfo%2Fsuit&data=3D02%7C01%7Cdthaler%40microsoft.=
com%7C302d0f10626b454a732308d5d7907359%7C72f988bf86f141af91ab2d7cd011db47=
%7C1%7C0%7C636651937771403102&sdata=3DAKEzjOXtE%2FPSc%2FbwKUP0ctCmYNL4CLW=
NuF9hh7IzOxE%3D&reserved=3D0> https://www.ietf.org/mailman/listinfo/suit

=20

IMPORTANT NOTICE: The contents of this email and any attachments are =
confidential and may also be privileged. If you are not the intended =
recipient, please notify the sender immediately and do not disclose the =
contents to any other person, use it for any purpose, or store or copy =
the information in any medium. Thank you.

=20

=20

IMPORTANT NOTICE: The contents of this email and any attachments are =
confidential and may also be privileged. If you are not the intended =
recipient, please notify the sender immediately and do not disclose the =
contents to any other person, use it for any purpose, or store or copy =
the information in any medium. Thank you.

=20


------=_NextPart_000_014A_01D40961.D6688A00
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal>I have not =
looked in detail at the XMSS signature structure =C2=A0and key structure =
and would want to do so before making any type of definitive =
statement.=C2=A0 However different drafts defining the different =
signature structures is what I would generally expect unless there is a =
huge overlap between them.=C2=A0 I would guess that the key structures =
are also different and thus would probably need to be identified =
differently.=C2=A0 This is based on the fact that a algorithm variant =
byte is placed at the start of both the key and =
signatures.<o:p></o:p></p><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>Doing this separately when we know they are going to =
be used (or potentially used) makes more sense to me.<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal>Jim<o:p></o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #E1E1E1 =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b>From:</b> Suit =
&lt;suit-bounces@ietf.org&gt; <b>On Behalf Of </b>Russ =
Housley<br><b>Sent:</b> Thursday, June 21, 2018 12:44 PM<br><b>To:</b> =
Dave Thaler &lt;dthaler@microsoft.com&gt;; Brendan Moran =
&lt;Brendan.Moran@arm.com&gt;<br><b>Cc:</b> suit =
&lt;suit@ietf.org&gt;<br><b>Subject:</b> Re: [Suit] =
draft-housley-suit-cose-hash-sig<o:p></o:p></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>I am =
advocating LMS. I think it would be appropriate for an advocate for XMSS =
to write a similar draft for that algorithm.<o:p></o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>Russ<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p =
class=3DMsoNormal><br><br><o:p></o:p></p><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal>On Jun 21, 2018, at 12:08 PM, Dave Thaler &lt;<a =
href=3D"mailto:dthaler@microsoft.com">dthaler@microsoft.com</a>&gt; =
wrote:<o:p></o:p></p></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>This is similar to a =
question I asked as well, whether the IETF only needs LMS or whether LMS =
is just an instance in a larger class that might be needed, and what the =
scope of the draft should be.</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>If the draft is not =
SUIT-only (e.g., allowing use in OSCORE, etc.) then it sounds like we =
might need the ability to support more than LMS for some use =
cases.</span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Dave</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><div><div =
style=3D'border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in'><div><p class=3DMsoNormal><b>From:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Suit &lt;<a =
href=3D"mailto:suit-bounces@ietf.org"><span =
style=3D'color:purple'>suit-bounces@ietf.org</span></a>&gt;<span =
class=3Dapple-converted-space>&nbsp;</span><b>On Behalf Of<span =
class=3Dapple-converted-space>&nbsp;</span></b>Brendan =
Moran<br><b>Sent:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Thursday, June 21, 2018 9:03 =
AM<br><b>To:</b><span class=3Dapple-converted-space>&nbsp;</span>Russ =
Housley &lt;<a href=3D"mailto:housley@vigilsec.com"><span =
style=3D'color:purple'>housley@vigilsec.com</span></a>&gt;<br><b>Cc:</b><=
span class=3Dapple-converted-space>&nbsp;</span>suit &lt;<a =
href=3D"mailto:suit@ietf.org"><span =
style=3D'color:purple'>suit@ietf.org</span></a>&gt;<br><b>Subject:</b><sp=
an class=3Dapple-converted-space>&nbsp;</span>Re: [Suit] =
draft-housley-suit-cose-hash-sig<span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></div></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Hi Russ,<span =
class=3Dapple-converted-space>&nbsp;</span><o:p></o:p></span></p></div><d=
iv><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New Roman",serif'>Thanks =
for the clarification. I agree that a larger signature is not what we =
need in SUIT. However, for the COSE draft, would it not make sense to =
provide for both LMS and XMSS? I don=E2=80=99t pretend to understand all =
COSE use cases.<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Thanks,<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Brendan<o:p></o:p></span></p></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><br><br><br><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>On 21 Jun 2018, at 16:43, Russ Housley &lt;<a =
href=3D"mailto:housley@vigilsec.com"><span =
style=3D'color:purple'>housley@vigilsec.com</span></a>&gt; =
wrote:<o:p></o:p></span></p></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div><div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Brendan:<span =
class=3Dapple-converted-space>&nbsp;</span><o:p></o:p></span></p></div><d=
iv><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Yes, there are two CFRG algorithms for hash-based =
signatures. &nbsp;I prefer the one McGrew's document, mostly because it =
is more straightforward. &nbsp;There is some speed improvement for the =
additional complexity in XMSS at the cost of a larger signature value. =
&nbsp;To me, the speed improvement is not big enough to justify the =
larger signature size. &nbsp;Your mileage may =
vary.<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>This paper describes the difference between the =
two:<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><a =
href=3D"https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Feprint.iacr.org%2F2017%2F349.pdf&amp;data=3D02%7C01%7Cdthaler%40microso=
ft..com%7C302d0f10626b454a732308d5d7907359%7C72f988bf86f141af91ab2d7cd011=
db47%7C1%7C0%7C636651937771383092&amp;sdata=3DzDGqR2NskjJzyVVcCEg8suPo3Lt=
9b6xLI1lxaYlWrbQ%3D&amp;reserved=3D0"><span =
style=3D'color:purple'>https://eprint.iacr.org/2017/349.pdf</span></a><o:=
p></o:p></span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Russ<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><br><br><br><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>On Jun 21, 2018, at 11:11 AM, Brendan Moran &lt;<a =
href=3D"mailto:Brendan.Moran@arm.com"><span =
style=3D'color:purple'>Brendan.Moran@arm.com</span></a>&gt; =
wrote:<o:p></o:p></span></p></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div><div><div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>I see that there are two current drafts for hash-based =
signatures:<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><a =
href=3D"https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Ftools.ietf.org%2Fhtml%2Fdraft-mcgrew-hash-sigs-11&amp;data=3D02%7C01%7C=
dthaler%40microsoft.com%7C302d0f10626b454a732308d5d7907359%7C72f988bf86f1=
41af91ab2d7cd011db47%7C1%7C0%7C636651937771393097&amp;sdata=3DCTRx3BW3duX=
IREYxP4CyR%2BQY63qYgi2vqjnUM9uKqQM%3D&amp;reserved=3D0"><span =
style=3D'color:purple'>https://tools.ietf.org/html/draft-mcgrew-hash-sigs=
-11</span></a><o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><a =
href=3D"https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Ftools.ietf.org%2Fhtml%2Fdraft-irtf-cfrg-xmss-hash-based-signatures-12&a=
mp;data=3D02%7C01%7Cdthaler%40microsoft.com%7C302d0f10626b454a732308d5d79=
07359%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C636651937771393097&amp=
;sdata=3Dpii%2Boa8SkTt7PLarq0P%2FKXL4WBVpNwLzGSIxEgZG5YU%3D&amp;reserved=3D=
0"><span =
style=3D'color:purple'>https://tools.ietf.org/html/draft-irtf-cfrg-xmss-h=
ash-based-signatures-12</span></a><o:p></o:p></span></p></div></div><div>=
<div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>I see that you have referenced the mcgrew draft rather =
than the IRTF/CFRG draft. Could you please explain what the difference =
is between these two drafts and why the mcgrew draft was a better choice =
than XMSS?<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Thanks,<o:p></o:p></span></p></div></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>Brendan<o:p></o:p></span></p></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><div><div><div=
><p class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times =
New Roman",serif'><br><br><br><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>On 13 Jun 2018, at 20:03, Jim Schaad &lt;<a =
href=3D"mailto:ietf@augustcellars.com"><span =
style=3D'color:purple'>ietf@augustcellars.com</span></a>&gt; =
wrote:<o:p></o:p></span></p></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br><br><br>=
<br></span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>-----Origina=
l Message-----<br>From: Suit &lt;<a =
href=3D"mailto:suit-bounces@ietf.org"><span =
style=3D'color:purple'>suit-bounces@ietf.org</span></a>&gt; On Behalf Of =
Michael Richardson<br>Sent: Wednesday, June 13, 2018 11:09 AM<br>To: =
suit &lt;<a href=3D"mailto:suit@ietf.org"><span =
style=3D'color:purple'>suit@ietf.org</span></a>&gt;<br>Subject: [Suit] =
draft-housley-suit-cose-hash-sig<br><br><br>I have read the -01 draft =
today.<br>I have not read [HASHSIG] yet.<br>I thought I'd try reading =
this first, to see what questions I had.<br><br>I have implemented COSE =
Sign1 with ECDSA in Ruby, so I have a grasp of<br>what we are trying to =
plug hash-sig *into*.<br><br><br>Suggestions:<br>1) would the structure =
show in section 3 be easier if it was described by<br>&nbsp;&nbsp;CDDL? =
&nbsp;I'm rather unclear about this.</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>No - =
this are not CBOR structures they are pure binary =
strings<br><br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>2) I =
din't understand section 4, where it =
says:<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;o &nbsp;If the 'key_ops' field is =
present, it MUST include 'sign' =
when<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;creating a hash-based =
signature.<br><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;o &nbsp;If the 'key_ops' =
field is present, it MUST include =
'verify'<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;when verifying a hash-based =
signature.<br><br>Clearly this is not something that travels over the =
network. &nbsp;Is this</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>somehow<br><=
br><br></span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>indicating =
how to understand if one is dealing a public (verify) key or =
a</span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>private<br><=
br><br></span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>(sign) =
key?</span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>The =
key_ops field can be considered to potentially be transported over =
a<br>network. &nbsp;It is part of the COSE_Key object rather than part =
of the<br>COSE_Sign1 object.<br><br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>3) the =
variations: LMS_SHA256_M32_H20, and LMOTS_SHA256_N32_W2,<br>etc. =
are<br>&nbsp;&nbsp;listed, but I don't know if they need to be carried =
in the signature<br>&nbsp;&nbsp;structure somehow.</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>See the =
[HASHSIG] draft. &nbsp;It is encoded into the signature structure and =
the<br>key type is in the public key =
structure.<br><br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>4) I =
thought that perhaps we'd need CBOR or COSE specific way to =
transport<br>&nbsp;&nbsp;the signatures. &nbsp;I guess I shall read =
HASHSIG to find out what the<br>&nbsp;&nbsp;signatures look =
like.</span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>We have =
that. &nbsp;This is looking at a signature just like ECDSA would =
produce.<br>This is a different &quot;ECDSA&quot; =
replacement.<br><br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>I =
understand draft-mcgrew-hash-sigs-11 is being advanced by CFRG.<br>I =
believe that SUIT should adopt this document, and should do so in =
the<br>current state.<br><br>I would like to have some examples in =
CBOR/COSE worked out with private<br>keys available in the =
appendices.</span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>Always =
a good thing to have.<br><br>Jim<br><br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>--<br>] =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;Never tell me the odds! =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;| ipv6 mesh</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>networks =
[<br><br><br></span><span style=3D'font-size:12.0pt;font-family:"Times =
New Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>] =
&nbsp;&nbsp;Michael Richardson, Sandelman Software Works =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;| network</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>architect =
&nbsp;[<br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>] =
&nbsp;&nbsp;&nbsp;&nbsp;<a href=3D"mailto:mcr@sandelman.ca"><span =
style=3D'color:purple'>mcr@sandelman.ca</span></a><span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;<a =
href=3D"https://na01.safelinks.protection.outlook.com/?url=3Dhttp%3A%2F%2=
Fwww.sandelman.ca%2F&amp;data=3D02%7C01%7Cdthaler%40microsoft.com%7C302d0=
f10626b454a732308d5d7907359%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C=
636651937771403102&amp;sdata=3DM7Tnkm9SzFy0ImJTiHRTBVDGfi3pR1vFixMCWskWmO=
o%3D&amp;reserved=3D0"><span =
style=3D'color:purple'>http://www.sandelman.ca/</span></a><span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;| &nbsp;&nbsp;ruby on rails</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'>[<br><br><br=
></span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div><blockquote =
style=3D'margin-top:5.0pt;margin-bottom:5.0pt'><p class=3DMsoNormal =
style=3D'margin-bottom:12.0pt'><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br>--<br>Mi=
chael Richardson &lt;<a href=3D"mailto:mcr+IETF@sandelman.ca"><span =
style=3D'color:purple'>mcr+IETF@sandelman.ca</span></a>&gt;, Sandelman =
Software Works<br>-=3D IPv6 IoT consulting =3D-<br><br><br></span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></blockquote><div><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica",sans-serif'><br><br>____=
___________________________________________<br>Suit mailing list<br><a =
href=3D"mailto:Suit@ietf.org"><span =
style=3D'color:purple'>Suit@ietf.org</span></a><br><a =
href=3D"https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fsuit&amp;data=3D02%7C01%7Cdthaler%4=
0microsoft.com%7C302d0f10626b454a732308d5d7907359%7C72f988bf86f141af91ab2=
d7cd011db47%7C1%7C0%7C636651937771403102&amp;sdata=3DAKEzjOXtE%2FPSc%2Fbw=
KUP0ctCmYNL4CLWNuF9hh7IzOxE%3D&amp;reserved=3D0"><span =
style=3D'color:purple'>https://www.ietf.org/mailman/listinfo/suit</span><=
/a></span><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'><o:p></o:p></span></p></div></div></blockquote></div><div><=
p class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times =
New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div></div></div><div><p=
 class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times =
New Roman",serif'>IMPORTANT NOTICE: The contents of this email and any =
attachments are confidential and may also be privileged. If you are not =
the intended recipient, please notify the sender immediately and do not =
disclose the contents to any other person, use it for any purpose, or =
store or copy the information in any medium. Thank =
you.<o:p></o:p></span></p></div></div></div></blockquote></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div></div></div></block=
quote></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>&nbsp;<o:p></o:p></span></p></div></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman",serif'>IMPORTANT NOTICE: The contents of this email and any =
attachments are confidential and may also be privileged. If you are not =
the intended recipient, please notify the sender immediately and do not =
disclose the contents to any other person, use it for any purpose, or =
store or copy the information in any medium. Thank =
you.<o:p></o:p></span></p></div></div></blockquote></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div></div></body></html>
------=_NextPart_000_014A_01D40961.D6688A00--

