[TLS] Re: Fwd: New Version Notification for draft-usama-tls-risks-of-mlkem-01.txt
David Stainton <dstainton415@gmail.com> Mon, 01 June 2026 16:57 UTC
Return-Path: <dstainton415@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3DCB9F8C5CAB for <tls@mail2.ietf.org>; Mon, 1 Jun 2026 09:57:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780333038; bh=1pA09zBhzM/i0Ku8tssv2R65aiPvIcirM71lgU+3e68=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=o9SGdmPtMrsVstBZs4YbBF/c7ntrxnNjJ0u89MUTw6L8XR1fSWnlwElfehZoQ177Y V0q1PMc5W1u8lFywC1Vq3/eehi/fQOmBMQhPm01xfDpy1aPErFWmkVFRgfa2yH1EVA 9XvIj6Er+WQonM14SUeq3DAVTc60MOqlqX+3AA9M=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9EZkjzNEAcyf for <tls@mail2.ietf.org>; Mon, 1 Jun 2026 09:57:17 -0700 (PDT)
Received: from mail-lf1-x12c.google.com (mail-lf1-x12c.google.com [IPv6:2a00:1450:4864:20::12c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 6EDDAF8C5CA4 for <tls@ietf.org>; Mon, 1 Jun 2026 09:57:17 -0700 (PDT)
Received: by mail-lf1-x12c.google.com with SMTP id 2adb3069b0e04-5aa653221d1so2330801e87.0 for <tls@ietf.org>; Mon, 01 Jun 2026 09:57:17 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1780333030; cv=none; d=google.com; s=arc-20240605; b=iiNcJ3XXdov9aBabHq89nFhIYF4HtqHq/nfcj7rbZVkQpvPJWla16KmDUFBgKdmh6i B7SMi5ZkBBkHU8tOegsX4IHyBhfefkLYPQSmUtP8XWQ4hf0uXxatrETtOBWzqlMTScsT hhvqXQg3N7dxbtHUDH7FDRhpSX6FTUkq6ZgSqZXBRdhtUnqjga8HXZtcjHO4HcgiqAOA u4TZzcx1yOLkxLQRdng8E8Ml8Zzgc6h+WH7VlY7ImRd/uEDWjY5rqMwwNxA1LIAm6X9m kjUSQEa4Iro6HoD7nC6/epZ3gWefsEQgyssW2U4NooGpvnoowP0Gah5KfdzeeOpCoEad xQdQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=iDwQmHvnhyNUV90b8F3DoEUFK5YLON7fpxqB2E9t52Y=; fh=Nfywt+u4eYGHS3Qdx6l5W9/r7UF53US4qvEB+2tMvRg=; b=ilnWvMDtG8MmrzV8cTo4+FELHl/6eh+jawAMtiDusC9hzU+k08rDxbpV2EI2tEgvP5 4d96QpQ5OUwLPjs+DZ2Ma+9aFV+4QASO9YpILf5wG/qBqRZiLIVKA8QC+fzPadiwgTEK rMwee+KNMs6Vd386zyCF/OvOpYddc2ydIXNuTZSOaGbmezUXu0mFhohZgZOGLKfloLv7 WxVrDDYTS/i8d/4+qS3tPIbDDPxBXYD/8DtvQvQYVb2DC4rd8VkN/Cri5/Km0K08Q3kB 22voe/dveiIdYv4/FUth9SFD3aZAmXQqZBQOhhCZZuJMMxA3Joz3yiw+hCTLwm7+1tvu AsSg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780333030; x=1780937830; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=iDwQmHvnhyNUV90b8F3DoEUFK5YLON7fpxqB2E9t52Y=; b=OfCXzJ7SMbkOkiVbSOCpdCmfFEwnom2T3p+NJYM/ej8triLM0eZ1eVO1oL5vrE2RLj HsCp1akNKQSN5x75vQuVkBz0qRmqJVBmkXCrMCz/ovZaqMgBpTlJF/DhlKKv0xgSxN2K KDtB+gWvkGMczNuTQ27bXgzwMPElxWpBW/Bc6EDj7QIzIN24F9ThsUF+m8H+hBjY80Yd ODvKcsI2F2BW2FmbevnIRJPGZ3PJZze95Ygu/Gh935JLxmb9j1kGJujdSLLal8qHMP4p ghi8/Qh5BG/Z7Ui2cwWqg5TYtEds7/T6M349utwXGj2nfD4+8ENvlRqb1E5uRtV9lRJS Ld2Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780333030; x=1780937830; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=iDwQmHvnhyNUV90b8F3DoEUFK5YLON7fpxqB2E9t52Y=; b=Aq0k5jYwKGzIWK1fPKZYiae3MozgJUGwv6cuAv7/kpuGU0wKc5R3Iufq4nPZG2iGN+ hh8nD5u+dPrK5Q0Y8u6aln/qMH74N8a7+sniAtORKkhmHb8wGCQwn9hnI8ZHxNrxqMRK Sl/HU3s9sBwLduWKeQu/di2sfKijOXikbTtwCArBiTZEqhUBfdYqs542L6/ZJcP+g72f d7RzOgu21EV+B1VPspdbtaz+lYxUnicq9f3PaOlrB5BREFNpwRy6vXyNvYZnwaJn+Rnz zPuKitSGZdEJJjUAGKtdHyf8Ynzfjamx+nUSwI3BE3bgLUnFB+WJ5L1z4EURRdKmhlVH mOFA==
X-Forwarded-Encrypted: i=1; AFNElJ9gXd6OpCbc2MVwWQxnpUUa1aGmul4PjD9QADdoEpUmv/DY5H0gN3sd5DNbJxC2vZN/X+I=@ietf.org
X-Gm-Message-State: AOJu0YypTriuJS0MQ529YudH6UNitAKTB8zyvOvAc9KPZsduDvB929VR TodFFx3LP+wp1Ve3nmss+XnZFKY8PEbQGfMY8tES9zTlkC2pkT6fTg/v0DZVc7UyJ9tZX/qQh4R BTfb+sqUng1xwqQfuACiha4b4hUkbO7A=
X-Gm-Gg: Acq92OF+5XkG3AQzfBBjCqEb0wqp37XnNrm1gzWNIMJJrUVdIGVWv4p1PpKOy6QgfFH CHznaFNsN/z1eZwe17xUZDovv9J3KNg/JTbaAD/sms5X0JT1vybEQNEk3RsY83PkczJzbY/3HXq rQSqKeDWFH59BbTa1+h7YLOdcuxKdBd4m8nqTt2eWO08W1F635ajSO3GC3xuhue/RBshutbxmAP BkyLz+pElmQ3R+PJ033u54ynXcNZrarG6pGJfgKM2WRPyZP0d8iFXlljxZDghBMasIUPGR4u2t/ xXU5qN4kr+CqKILfg9DsZQb26I3WuOjLwsVwfxLLUP3nShdxvNuj1w5FkuU/mbiXz0EmXTfUPEB RnZWb
X-Received: by 2002:a05:6512:1318:b0:5aa:6a11:3a29 with SMTP id 2adb3069b0e04-5aa753b95f1mr89051e87.3.1780333029495; Mon, 01 Jun 2026 09:57:09 -0700 (PDT)
MIME-Version: 1.0
References: <178004897406.1571084.15428249207754239073@dt-datatracker-5b4c8598b5-4ztf9> <b9a8212d-cfe0-402b-9a8a-f63c1712d1db@tu-dresden.de> <CAHxYnaNC8it-gRHZPc4n-tgqwmBp06gfhy18sO77wSEJGjSmaw@mail.gmail.com>
In-Reply-To: <CAHxYnaNC8it-gRHZPc4n-tgqwmBp06gfhy18sO77wSEJGjSmaw@mail.gmail.com>
From: David Stainton <dstainton415@gmail.com>
Date: Mon, 01 Jun 2026 18:56:57 +0200
X-Gm-Features: AVHnY4LHQnVLQL9hP5_7j1ZtXL9TihoD_qEp12fYaMLWYV3mhuk5UJ27W22MYi0
Message-ID: <CAFN1edrFmOGkrNWg6yXMC5XiOBHOHeJdkHXu=Fh1HQD-+rF1RA@mail.gmail.com>
To: Nathanael Ritz <nathanritz@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000ce157d0653341578"
Message-ID-Hash: GXCGQESXY7BDRCEOW3HAHQ4Y3AF7HFQT
X-Message-ID-Hash: GXCGQESXY7BDRCEOW3HAHQ4Y3AF7HFQT
X-MailFrom: dstainton415@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Fwd: New Version Notification for draft-usama-tls-risks-of-mlkem-01.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/B-O8I348KPRr7_unQLy2e_OpGeQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
I support initiating the FATT process here, and I support the work Usama is doing to use symbolic models to better understand the protocol's security properties. Even where existing proofs give us confidence, having an explicit symbolic analysis of the standalone-KEM case is the kind of thing that's worth doing rather than assuming, and there are clearly participants willing to do it. +1 from me. David On Sun, May 31, 2026 at 1:15 AM Nathanael Ritz <nathanritz@gmail.com> wrote: > Hi Usama, > > I have some feedback re: "Justification based on FATT Process" (sect. 4) > for the -01 draft [0]. > > In sect. 4-6.2.1 you highlight "3 public forks". E.g., > > - jupenur/formal-spec-id-crisis > - nathanaelritz/formal-spec-id-crisis [1] > - telephonicrobotics/formal-id-crisis-spec [2] > > I wanted to clarify that I control both repos, `telephonicrobotics` and > `nathanaelritz`. I.e., `telephonicrobotics` is my GH username and I use > `nathanaelritz` for my more front-stage work. Additionally, it appears both > links point directly to the original init commit #a25631b [3], [4] instead > of hyperlinking to the main branch for either repository -- although that > could just be a GH artifact. > > Truth be told, the cloned repo at > `telephonicrobotics/formal-id-crisis-spec` is more of an artifact than > anything actively developed. As it's presented, I'm afraid this may cause > some readers to accidentally perceive my substantive contributions to this > code base as larger than they currently are. > > Therefore, for the -02 revision of your draft, I propose dropping the > citation for `telephonicrobotics/formal-id-crisis-spec` altogether and > hyperlinking directly to the main branch of my main fork at > `nathanaelritz/formal-spec-id-crisis` [5] for maximum clarity. > > Thanks, > Nathanael > > [0] > https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.html#name-justification-based-on-fatt > [1] > https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.html#section-4-6.2.2.2.1 > [2] > https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.html#section-4-6.2.2.3.1 > [3] > https://github.com/nathanaelritz/formal-spec-id-crisis/blob/a028cec823b7d9bf13dd5a1dd71ab14c75b1a83d/TLS-a/fix/tls-lib-simple.pvl#L38-L41 > [4] > https://github.com/telephonicrobotics/formal-id-crisis-spec/blob/c1953127ce004e51b888250591ec9971ad50e98c/TLS-a/fix/tls-lib-simple.pvl#L38-L41 > [5] https://github.com/nathanaelritz/formal-spec-id-crisis/tree/main > > > On Fri, 29 May 2026 at 04:38, Muhammad Usama Sardar < > muhammad_usama.sardar@tu-dresden.de> wrote: > >> Dear Joe and Sean, >> >> I believe I have collected sufficient attestations from the WG that a new >> proof is required for draft-ietf-tls-mlkem. >> >> As I understand, apart from me, there are at least 2 other WG >> participants (Nadim [0] and Nathanael [1]) who are *already* doing or >> have *volunteered* to do independent formal analysis in ProVerif. I take >> that as a strong attestation that there is enough WG energy to do the work. >> >> So with these attestations, I would like to request the initiation of the >> FATT process for draft-ietf-tls-mlkem. I believe it would be good to have >> FATT's evaluation of the artifacts that would be eventually developed by >> these efforts. Thank you for your kind consideration. >> >> In addition, I believe all concerns have been addressed in this version. >> Summary of major changes is: >> >> - Added justification based on the FATT process: Section 4 >> - Reorganization, specially in motivation (Section 1.1) >> - Added some common arguments: Section 6 >> - Comparison with hybrid ML-KEM in Section 4.1 >> - Clarification of what "breaking" means in Section 3 >> >> For those who haven't had a chance to check the draft yet, more feedback >> on Sec. 3 and 4 is very welcome. For discussion of details of modeling, >> please contact me off-list. >> >> Best regards, >> >> -Usama >> >> [0] >> https://mailarchive.ietf.org/arch/msg/tls/pZe6luYQeT4GhbOc1FE1xi-Lmzc/ >> >> [1] >> https://mailarchive.ietf.org/arch/msg/tls/S5QioGFa3T3AFWIAjsNg8BFy5Co/ >> >> >> >> -------- Forwarded Message -------- >> Subject: New Version Notification for >> draft-usama-tls-risks-of-mlkem-01.txt >> Date: Fri, 29 May 2026 03:02:54 -0700 >> From: internet-drafts@ietf.org >> To: Muhammad Sardar <muhammad_usama.sardar@tu-dresden.de> >> <muhammad_usama.sardar@tu-dresden.de>, Muhammad Usama Sardar >> <muhammad_usama.sardar@tu-dresden.de> >> <muhammad_usama.sardar@tu-dresden.de> >> >> A new version of Internet-Draft draft-usama-tls-risks-of-mlkem-01.txt has >> been >> successfully submitted by Muhammad Usama Sardar and posted to the >> IETF repository. >> >> Name: draft-usama-tls-risks-of-mlkem >> Revision: 01 >> Title: Potential Risks of Standalone ML-KEM in TLS 1.3 >> Date: 2026-05-29 >> Group: Individual Submission >> Pages: 16 >> URL: >> https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.txt >> Status: https://datatracker.ietf.org/doc/draft-usama-tls-risks-of-mlkem/ >> HTML: >> https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.html >> HTMLized: >> https://datatracker.ietf.org/doc/html/draft-usama-tls-risks-of-mlkem >> Diff: >> https://author-tools.ietf.org/iddiff?url2=draft-usama-tls-risks-of-mlkem-01 >> >> Abstract: >> >> We attest that standalone ML-KEM in TLS 1.3 breaks the existing >> formal proofs of TLS in state-of-the-art symbolic security analysis >> tool, ProVerif. In this draft, we show *exactly* where the ProVerif >> proofs break, namely transition from symmetric DHKE to asymmetric >> KEM. More specifically, the existing proofs of TLS in ProVerif are >> based on commutativity property, whereas commutativity does not apply >> to standalone ML-KEM in TLS. >> >> We also attest that from a formal analysis perspective, this is a >> much bigger change than RFC8773bis, which indeed went for FATT review >> (cf. [TLS-FATT]). We, therefore, formally request the chairs to >> initiate the FATT review of standalone ML-KEM in TLS. A few WG >> participants have already volunteered to do formal analysis in >> ProVerif. >> >> This draft also offers some preliminary discussion to help the >> developers and policy makers make informed choices. Finally, the >> draft also aims to reduce the endless repitition of arguments from >> both sides presented on several lists by documenting these arguments >> so they can simply be referred to. >> >> >> >> The IETF Secretariat >> >> >> _______________________________________________ >> TLS mailing list -- tls@ietf.org >> To unsubscribe send an email to tls-leave@ietf.org >> > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org >
- [TLS] Fwd: New Version Notification for draft-usa… Muhammad Usama Sardar
- [TLS] Re: Fwd: New Version Notification for draft… John Mattsson
- [TLS] Re: Fwd: New Version Notification for draft… Muhammad Usama Sardar
- [TLS] Re: Fwd: New Version Notification for draft… Nathanael Ritz
- [TLS] Re: New Version Notification for draft-usam… Nadim Kobeissi
- [TLS] Re: Fwd: New Version Notification for draft… Nathanael Ritz
- [TLS] Re: Fwd: New Version Notification for draft… Salz, Rich
- [TLS] Re: Fwd: New Version Notification for draft… Nathanael Ritz
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: Fwd: New Version Notification for draft… Salz, Rich
- [TLS] Re: Fwd: New Version Notification for draft… David Stainton
- [TLS] Re: Fwd: New Version Notification for draft… Jacob Appelbaum
- [TLS] Re: Fwd: New Version Notification for draft… Simon Josefsson
- [TLS] Re: Fwd: New Version Notification for draft… Ilari Liusvaara
- [TLS] Re: Fwd: New Version Notification for draft… Muhammad Usama Sardar
- [TLS] Re: Fwd: New Version Notification for draft… Peter C