[TLS] Re: Fwd: New Version Notification for draft-usama-tls-risks-of-mlkem-01.txt

Nathanael Ritz <nathanritz@gmail.com> Fri, 29 May 2026 14:16 UTC

Return-Path: <nathanritz@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 25818F76E252 for <tls@mail2.ietf.org>; Fri, 29 May 2026 07:16:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780064203; bh=zMZz3JibSeSzpc3z9tso7YrXCLbA2bK7jgiHlSUMEw0=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=ivab3abd86dMSUnO34bBV8nFbFjGt3FBZH7KMu7DI3Rp3qKcx3nyeeBnLWm0S6C5m U05eYVD2bKb2k7esB7ZokVd1eJCMLbhAKH9D84Wtm92N7jNiCC+t5RSxKFbR3OwPUS h7N/tkbemUuuG7VoP7YARvj6ELSzKYEuXfrOrQFU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7WvBj_k7FUvw for <tls@mail2.ietf.org>; Fri, 29 May 2026 07:16:42 -0700 (PDT)
Received: from mail-dl1-x122f.google.com (mail-dl1-x122f.google.com [IPv6:2607:f8b0:4864:20::122f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3FAACF76E1CD for <tls@ietf.org>; Fri, 29 May 2026 07:16:30 -0700 (PDT)
Received: by mail-dl1-x122f.google.com with SMTP id a92af1059eb24-1334825de43so12510263c88.0 for <tls@ietf.org>; Fri, 29 May 2026 07:16:30 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1780064189; cv=none; d=google.com; s=arc-20240605; b=Xotx89NdIEeJxJHEbtNBGGL53Em9Q2KWMvBdkwdUfPmnNpxXpTC8dtYqs5He9tW2jl esq1rKJIt6BnfR6QzhYUiaFBBwOpkAjNi63kfqQ2FZkjr4Hh9KSq3tyMvgyxGdwIP0oX 8yjTFxPZiuroJwT8hsoLP9OiJ65gTDzlHYb6BRONRNjib5+ZRUt4+cbG88PqCiBbJkZI 8K3o1H3mMIcYaYhydEypyVt6osPJ5Ds9hPv5x/tZh0kwSpD/v5gy9HGwezxLM2jqomuO 5L3XXfU62OnYzbc/UsyOmf8c2MR/98Rhc39DJhcEXvKXBu1Xhd2LQepYvxck+nx+o8CO kWfA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=bYVVSs+e3I/jt0763lsB0aF/CnsnPKu7RBeFDN/dg5k=; fh=e3t2D0fOZOIVnG/z6FlOE5QWpuh2luSgGWmWzadr0r0=; b=Ep+gbk/7H8WBf6Q+OHDFnVZx8vl6yAWqxxj2FGybwNgV3t/QPIa/o38539vxZKFidH XFr/YW8Bv2XR/tCs5iX4rvrWv0MLprDasBUvCKzrAtcjZa/YSnZpwAGc6mMl1wwVXP2D WJYXnCAQZcQRHS3T/trnfVWHZAwC2r6zwMboUaxXm9qwIhHrKQf3iFWwsAQaD0aGi/hq ZJiud9kmyAJvYF2n/0wftf7rSIwxVdvGmdmZMt/fpiHRecFylNBtsSlLfVeNeOjbiZvj 4ayS7mnT6TIkOYSnZKwaWdPxNLitMgJShGQN2jypiAubawNTSzF4dbGtk2nsZIJBf2+8 2YTA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780064189; x=1780668989; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=bYVVSs+e3I/jt0763lsB0aF/CnsnPKu7RBeFDN/dg5k=; b=Ppu74LXTQ1mArAOuhl6gOasO1As0UJNd+IL/JlVgJVy5u0BiXTzQ1cGuuGiTCF0Tof 6Rypc+5WF5y42CML9gvXdu+gjoMPRPevOqkZlrCGXj/tm5e3IeHLl5ajhHCLd63KgWrR WlctcwDt333BzLiGDbpNj1HSXvSFUXtNj7Iov5baIa8jbauvo5ij3Lef8XGvOsRad8De vE1kDa5vlERbQqLzm8lAuUUu5KdNJJlBGgn2ohuIR9RkTYjklbOxxwAQAP3L/K9YFlrQ uDIL15egOPvfWLI8nnuS6c1Cbe5R4Mvw5n0/L8grMikbTz+Y+HfmgncAVAUBm/Z51whk 9aSA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780064189; x=1780668989; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=bYVVSs+e3I/jt0763lsB0aF/CnsnPKu7RBeFDN/dg5k=; b=mW6KMeeF0uiS7N8yFSSa52Wr3KeHBOItnhmOnv8JzRhvraCcC17m3S6mxpmWYjb6he ykk0eNspo7urSO3wduKgoiDGdCjBVyPNECILMEpvxz/bh6xeVBIkP3gI1jjpWnLOv2DP G4OKxyQHzLgt/gOJeq6bxHBVWYfB7mFD20A4Oqae5uXRZHSyUYcCSON9DtKimCNp4agZ owHs9rMCcjoIkJns07Eod+d5kaBvl2BPZ+wi6YZzk3D8cI6Dk2nm+Hd6NBGAaUKqJaig MpJbE0331iK7gG3RC0OkX3GKvN+zgJXc7nDTj4w8wXqhMfNCnpeHIGDtS5Wd8vd5CTs9 3zcQ==
X-Gm-Message-State: AOJu0YwXI/XrzskvrVa6fhVlrM/3MGF+o4R74BopLV4VUQLBoKJfo44o Q+kPvVAyTuka1x0AdngotA8yVzhaZtVTDgO9u+4p+spoRZ45F7DA2hQ6QAaRPhoDeuzdRtwjVhG 5JehnJLdBL+GN8YpNx6FoJD9JY8RURyYBGdZZ9zI=
X-Gm-Gg: Acq92OHj3c15tCbvkZMevtbQCbNWNeZb3T9LsKTBgCkFI9cJysA4d6xlI6WJujiX2oE CQWonQF2o7DETgYnkScWMAhTPMQ9pkPt+SuH5Uy+2FlqjL9gZWTvy1PSRJ01kEQVMYHKEMYS51u CAEWMYsvIopjyfdqJAtDLreUMP5Q7YYCcRqdF67cbYvgHve98Q07kcEJfQS385ERJjq+xi56BTo wacwF9uBUvcYv+MCnoetrh+iQmJyU8mwUM1fLRepOJAfDbD8Tb92oq7AwymTTkB7dF4Kp7166tx cI0rH/ac5j/Y4cMUdFm1zAOlQte7
X-Received: by 2002:a05:7022:426:b0:134:fea9:f107 with SMTP id a92af1059eb24-137aeef31eemr1144576c88.33.1780064188983; Fri, 29 May 2026 07:16:28 -0700 (PDT)
MIME-Version: 1.0
References: <178004897406.1571084.15428249207754239073@dt-datatracker-5b4c8598b5-4ztf9> <b9a8212d-cfe0-402b-9a8a-f63c1712d1db@tu-dresden.de>
In-Reply-To: <b9a8212d-cfe0-402b-9a8a-f63c1712d1db@tu-dresden.de>
From: Nathanael Ritz <nathanritz@gmail.com>
Date: Fri, 29 May 2026 08:16:17 -0600
X-Gm-Features: AVHnY4LcSYlODsuC6UuCk-1LRtZ2iFOnGkoktOcml_v1amgkQEYBRw4C-UpwEjg
Message-ID: <CAHxYnaPqHkaU-ECZyL7hOzg=rWm5iTUEZjpnRk3=AofCzXHm0Q@mail.gmail.com>
To: "TLS@ietf.org" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a96db20652f57d77"
Message-ID-Hash: 2NPJKMLV25ZIEC6FHLGYJG5H5NJM5BIZ
X-Message-ID-Hash: 2NPJKMLV25ZIEC6FHLGYJG5H5NJM5BIZ
X-MailFrom: nathanritz@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Fwd: New Version Notification for draft-usama-tls-risks-of-mlkem-01.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/YzaVoTbtBNPfZdnRlr2enrtsixA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi,

Comments below with [NR]

On Fri, May 29, 2026 at 4:38 AM Muhammad Usama Sardar <
muhammad_usama.sardar@tu-dresden.de> wrote:
>  Dear Joe and Sean,
> I believe I have collected sufficient attestations from the WG that a new
proof is required for draft-ietf-tls-mlkem.
> As I understand, apart from me, there are at least 2 other WG
participants (Nadim [0] and Nathanael [1]) who are already doing or have
volunteered to do independent formal analysis in ProVerif. I take that as a
strong attestation that there is enough WG energy to do the work.

[NR] I stated clearly that “I am interested in collaborating on new
ProVerif models that explore PQ crypto as well.” I did not share any
opinion on whether a proof was required for anything.

Based on the results of the idealized KEM model variant (that I remain open
to collaborate further on), I found nothing from the verification output
that gives me any reason for concern compared to the DH model evaluating
the same properties. Of course, critical feedback on my model construction
and evaluated properties is welcome off List.

Since there appears to be an opening for some misunderstanding, please do
not misconstrue my contribution as an implied mandate or imposition against
the trajectory and current work of the TLSWG by me.

Sincerely,

Nathanael

On Fri, 29 May 2026 at 04:38, Muhammad Usama Sardar <
muhammad_usama.sardar@tu-dresden.de> wrote:

> Dear Joe and Sean,
>
> I believe I have collected sufficient attestations from the WG that a new
> proof is required for draft-ietf-tls-mlkem.
>
> As I understand, apart from me, there are at least 2 other WG participants
> (Nadim [0] and Nathanael [1]) who are *already* doing or have
> *volunteered* to do independent formal analysis in ProVerif. I take that
> as a strong attestation that there is enough WG energy to do the work.
>
> So with these attestations, I would like to request the initiation of the
> FATT process for draft-ietf-tls-mlkem. I believe it would be good to have
> FATT's evaluation of the artifacts that would be eventually developed by
> these efforts. Thank you for your kind consideration.
>
> In addition, I believe all concerns have been addressed in this version.
> Summary of major changes is:
>
>    - Added justification based on the FATT process: Section 4
>    - Reorganization, specially in motivation (Section 1.1)
>    - Added some common arguments: Section 6
>    - Comparison with hybrid ML-KEM in Section 4.1
>    - Clarification of what "breaking" means in Section 3
>
> For those who haven't had a chance to check the draft yet, more feedback
> on Sec. 3 and 4 is very welcome. For discussion of details of modeling,
> please contact me off-list.
>
> Best regards,
>
> -Usama
>
> [0] https://mailarchive.ietf.org/arch/msg/tls/pZe6luYQeT4GhbOc1FE1xi-Lmzc/
>
> [1] https://mailarchive.ietf.org/arch/msg/tls/S5QioGFa3T3AFWIAjsNg8BFy5Co/
>
>
>
> -------- Forwarded Message --------
> Subject: New Version Notification for
> draft-usama-tls-risks-of-mlkem-01.txt
> Date: Fri, 29 May 2026 03:02:54 -0700
> From: internet-drafts@ietf.org
> To: Muhammad Sardar <muhammad_usama.sardar@tu-dresden.de>
> <muhammad_usama.sardar@tu-dresden.de>, Muhammad Usama Sardar
> <muhammad_usama.sardar@tu-dresden.de>
> <muhammad_usama.sardar@tu-dresden.de>
>
> A new version of Internet-Draft draft-usama-tls-risks-of-mlkem-01.txt has
> been
> successfully submitted by Muhammad Usama Sardar and posted to the
> IETF repository.
>
> Name: draft-usama-tls-risks-of-mlkem
> Revision: 01
> Title: Potential Risks of Standalone ML-KEM in TLS 1.3
> Date: 2026-05-29
> Group: Individual Submission
> Pages: 16
> URL: https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.txt
> Status: https://datatracker.ietf.org/doc/draft-usama-tls-risks-of-mlkem/
> HTML:
> https://www.ietf.org/archive/id/draft-usama-tls-risks-of-mlkem-01.html
> HTMLized:
> https://datatracker.ietf.org/doc/html/draft-usama-tls-risks-of-mlkem
> Diff:
> https://author-tools.ietf.org/iddiff?url2=draft-usama-tls-risks-of-mlkem-01
>
> Abstract:
>
> We attest that standalone ML-KEM in TLS 1.3 breaks the existing
> formal proofs of TLS in state-of-the-art symbolic security analysis
> tool, ProVerif. In this draft, we show *exactly* where the ProVerif
> proofs break, namely transition from symmetric DHKE to asymmetric
> KEM. More specifically, the existing proofs of TLS in ProVerif are
> based on commutativity property, whereas commutativity does not apply
> to standalone ML-KEM in TLS.
>
> We also attest that from a formal analysis perspective, this is a
> much bigger change than RFC8773bis, which indeed went for FATT review
> (cf. [TLS-FATT]). We, therefore, formally request the chairs to
> initiate the FATT review of standalone ML-KEM in TLS. A few WG
> participants have already volunteered to do formal analysis in
> ProVerif.
>
> This draft also offers some preliminary discussion to help the
> developers and policy makers make informed choices. Finally, the
> draft also aims to reduce the endless repitition of arguments from
> both sides presented on several lists by documenting these arguments
> so they can simply be referred to.
>
>
>
> The IETF Secretariat
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>