[TLS] Re: Fwd: New Version Notification for draft-usama-tls-risks-of-mlkem-01.txt

Nathanael Ritz <nathanritz@gmail.com> Fri, 29 May 2026 21:08 UTC

Return-Path: <nathanritz@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4EBB1F7ACE6B for <tls@mail2.ietf.org>; Fri, 29 May 2026 14:08:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780088896; bh=WELn4U1HTpKVu7tT9AHEhq3/FlRgXBgXOSnPR8u99U0=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=atMvav7mZAmbnW8J5mQHVLVUYFsGjozrDuDUmHT9vJ1YZsxEDIHw92am1LLBf5xO2 70jitnh8/QREovvybsnooCiTzttB/F+PTWPtKhb+8iZ8Wn0sspxOneg4D9QQHjR0dX nM1+2m7qbYNcpfp5oPiZ4TbVK/taNBndIMQh6yzc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UH3WF-dZAaX6 for <tls@mail2.ietf.org>; Fri, 29 May 2026 14:08:15 -0700 (PDT)
Received: from mail-dl1-x1231.google.com (mail-dl1-x1231.google.com [IPv6:2607:f8b0:4864:20::1231]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 504F0F7ACD6F for <tls@ietf.org>; Fri, 29 May 2026 14:08:05 -0700 (PDT)
Received: by mail-dl1-x1231.google.com with SMTP id a92af1059eb24-137335bc3caso5958553c88.0 for <tls@ietf.org>; Fri, 29 May 2026 14:08:05 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1780088884; cv=none; d=google.com; s=arc-20240605; b=bQSGuLFjObiScxYjMWkDQRmHmhpBPsTLZ1CMS5+hOgUh5+qKyGDt4TvAi+oDfcdwMu rFZYV/aE1Aps/2O0Lclb3aSydD4YaR81K9TtfpfN/UeKuR+sMStX2ODPH/IxQpXNGeFZ I4GEAy/hoNZ+d7mct6pb2+H+Rfz1stV3L8jxNujbJQKjbpMRE0DZ3PdUX4kUkZhHdYKY PinJcSfeoQtuuCT/fWv/dq28nzp3mHfXfy+L1IJ0JxWdC/OvJ56y+TfZGngqpUKkgqtk 6mxrO8N5b5604UdSm2QA4nGgWjckppkrKhZzQ+Qln4VBZaM9jK8RMJcSy8aYi8qxubgH 3tcA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=/ZfmBXTg8T2q88v5WAAqkvAs+8+QDoJIXQ2BoMh6zY0=; fh=MA8GQ9ukvWBlZn8cwoTku8lUFnQQfk/OSTrJBqEFle4=; b=OOUmN8KOgWhYpP0/4cyHRq8CAzb72KWaA6bEGT+dY+TVVjg7SrtwAlXZPrNlaVFwHl FgxzgQZ1yPr7xCzK3nm09sOoEpqo5LBrmmhVs5DmiKCQY6TZ8zRujV3LWoRTwkvxJhMj 5iupSUw+V3R5VuillHRx8iCyHyqu6jUu9SdFjIRuqc+Gye+w0hSW8oI3pr6rWfnlv8xL AIfyVzJ7GO2DtOp/8U9HLVp6Nz/LZYM80CC1mGbxEh8XVFT1R0BciBvs9MWogvnrirp5 LXhA6J+psV91Shr1OuNq6yaUzlkitOQ+nFyhzHGyuic9xa29CixSfQ+QahwgD6j2fGJa /KLQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780088884; x=1780693684; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=/ZfmBXTg8T2q88v5WAAqkvAs+8+QDoJIXQ2BoMh6zY0=; b=FN6Rf0sYdVGyajcj1wjG9mAqvDO4oEGNm8vSMW8NRg7rtNmLVopmu30WRvZZ3jqS7M tXruJLSNsX51tHXb53WYliVvIgs56LfSKsImWHKDDBDNsdHemq59Yxl1l2gZdfDizyxr N0DQH/WKHqiwSD82nJLViwYNO03LKOyqSsU9pIxT1Z+nV8V+VPQVPADtB3NMMme5MKQX 7n3hfrG8WC1UUXGEL/mHaCqw6DlsnLUKy36AEqh+22sE7aL3YfPAHS6r9A7fRrtMCmtP 7QgiqNVz5OuXGTVJBrMCBzv0b+ukGOiFej9L9Xozl01IqS8iE2+v/j4o01AuIa1Y3NMz NrEg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780088884; x=1780693684; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=/ZfmBXTg8T2q88v5WAAqkvAs+8+QDoJIXQ2BoMh6zY0=; b=hVagBY7Pf+0u2kQQUShhFTpLCbN26ORK91wp0FcRUTAKtkDLpoU3PdF77daz+KeQgv AmPyvpbHfQmIPY4+Ee3+YKVDhCXh65n2jS2Cqyy7kSn7KzRospsdAInYgu2X/sj4kC6U dAeKjr+MkpRJhm4HUcAxz1N8WQEiP8QNlAAAVF8FSaVWEtVHhG9PPJD4BNzwjrHwaw8I gy06M+m2QX1gaAZ13/kfIhT35kdT79B4Vkgbl318S+tBoTDidMhVDT6Q9NIUYHDEK7NH v7so6s+mAUR7Sz7TeMm52BgxY81R99JWy2QmRrePqpHD3WE5EFjSAbbPWjKJ+5jK/D8u ZlLA==
X-Gm-Message-State: AOJu0YwNcvLaiVNjffnrty0SQsTG1BbNkVkfB4wtDWf4/+xEb2Ei3kUx nbFiTamtsyxJ1PlrPU9QCWElhkhlFsm/oYWKs2cIyMU4UgQzPbQ2lX7e5NCtc3caDE9VI7tg2uA sb8su1H7jkivPAUzocbMq0S2IFakavPA=
X-Gm-Gg: Acq92OHeY8H/2IFW/ECilHDSIZZ5mm5o7Wm47TJ6cgy4d+zQXpIM5ftAH5j+oI5woZE Bi5OdPnY+lC6x/+786SKLvbCKGlVobXAU2voyaKNk7KRGrZzmjUC3hy5wcIVHBsnvZo0cJfOHG1 325b/RmZiRcgKOGnGj7okqt9XDd+ymlXwSFTZRSgjFv6alAI2jXQah62t3bjfC/pnQ6ITmNJWbq ZDNZV17PB/oM6Cyqkjcp3fzZ8rS0rrfNgu+3Tjlfg/wqaiqejehomAA4X6wbZDT/O9zqm2A/bte Sj8jsunoqeRE/pwQsA==
X-Received: by 2002:a05:7022:e24:b0:135:dd7c:7 with SMTP id a92af1059eb24-137d4294ec9mr685397c88.38.1780088884108; Fri, 29 May 2026 14:08:04 -0700 (PDT)
MIME-Version: 1.0
References: <178004897406.1571084.15428249207754239073@dt-datatracker-5b4c8598b5-4ztf9> <b9a8212d-cfe0-402b-9a8a-f63c1712d1db@tu-dresden.de> <AS4PR07MB8825B2ED5C1F97F575CF643289162@AS4PR07MB8825.eurprd07.prod.outlook.com> <d296d34a-0bb6-4a4d-aa42-3186c1f7457c@tu-dresden.de>
In-Reply-To: <d296d34a-0bb6-4a4d-aa42-3186c1f7457c@tu-dresden.de>
From: Nathanael Ritz <nathanritz@gmail.com>
Date: Fri, 29 May 2026 15:07:52 -0600
X-Gm-Features: AVHnY4IF-a2DSTtQGxlvuAj1I0XcpKw1ZRfjPnAcqYYxWCUw4eRirObdpLRQ4rU
Message-ID: <CAHxYnaMYhk=W1O2XZfKSeYm_UhmBVsY5vqTfEu+H35NwPciMxA@mail.gmail.com>
To: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
Content-Type: multipart/alternative; boundary="0000000000009b20690652fb3d9e"
Message-ID-Hash: 6KLUU3MD365SN2VLHJS2Q37EEKKWFO47
X-Message-ID-Hash: 6KLUU3MD365SN2VLHJS2Q37EEKKWFO47
X-MailFrom: nathanritz@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Fwd: New Version Notification for draft-usama-tls-risks-of-mlkem-01.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/EJLe6whsJNGPE6zEPVzQQcP9cX8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Usama,

On Fri, 29 May 2026 at 14:54, Muhammad Usama Sardar <
muhammad_usama.sardar@tu-dresden.de> wrote:

> Thanks all for the comments. Some thoughts inline:
>
> [snip]
>
> Based on the results of the idealized KEM model variant (that I remain
> open to collaborate further on), I found nothing from the verification
> output that gives me any reason for concern compared to the DH model
> evaluating the same properties.
>
> FWIW, from a quick look, ISTM that it simply replaces ideal DHKE by ideal
> ML-KEM but IMHO we instead need to focus on the more security-critical
> questions about integration, as Nadim has mentioned. I'll submit a thorough
> review of nits later off-list but a few high-level observations to consider
> for security considerations of draft-ietf-tls-mlkem:
>
>
>    1. ISTM that Yaakov's point quoted below does not seem to be addressed
>    because client and server are assigned static roles in the model. When it
>    will be modeled as non-static, I would be interested to see whether the
>    asymmetry issue becomes visible in at least a couple of properties. I
>    consider it very critical for security considerations of
>    draft-ietf-tls-mlkem and this is the key point of my draft.
>
>    So, you are not really using the fact that either side could have initiated the TLS [...]
>
>    2. ISTM that the failure modes proposed by Yaakov and Nadim are also
>    not modeled.
>    3. A large part of the problem is the careful investigation of what to
>    model, under what threat model, under what system model, under what
>    implementation scenarios etc. I believe all of that needs to be clearly
>    fleshed out in the repo. I think some of this is important for security
>    considerations of draft-ietf-tls-mlkem. I was not able to find much about
>    any of those in readme of repo.
>    4. I would have liked to see some analysis about any subtle cases
>    where hybrid ML-KEM in TLS is *not better* than standalone ML-KEM in
>    TLS. My understanding is that some participants would like to see some
>    statement.
>    5. I believe brainstorming about some robustness (vs. security)
>    properties would also be useful. Even if the security properties hold, does
>    it make side-channel leakage easier?
>
>

The chairs made it clear [0] that we are to take such "detailed discussion"
off the TLSWG list. I suggest and welcome your engagement on the UFMRG list
[1] if you would like to collaborate on the model with me and others.

Thank you,

Nathanael

[0] https://mailarchive.ietf.org/arch/msg/tls/SG10yIg7zjl5dJP06p6LlK-slQ0/
[1] https://mailarchive.ietf.org/arch/msg/ufmrg/xu1V-kSxZM_CC2keFFzwiO_oGZ4/