Re: Specification for Kyber in GnuPG

Simon Josefsson via Gnupg-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.devel
Message-ID <[email protected]>
Werner Koch <[email protected]> writes:

> On Mon,  6 May 2024 17:06, Simon Josefsson said:
>
>> Thank you!  As far as I can tell this doesn't strongly bind eccPublicKey
>> and mlkemPublicKey to the KEK which may complicate a security proof.
>
> Can you give a reason for this?  The fingerprint binds the two public
> keys and it is an input to the key combiner.

I haven't chaised the entire chain -- does it bind to the master key
fingerprint only, or to the Ecc+Kyber subkey too?

Including the public key in the KEK binding has been discussed before,
some references:

https://mailarchive.ietf.org/arch/msg/cfrg/84TUdtD0w12qFSNPpdV5ArS4-IE/

I'm not saying it is critical for security for the entire ECC+Kyber in
LibrePGP (I can't fit all of it in my head), but it makes it easier to
reason about security properties of the combiner on its own.

/Simon

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc (application/pgp-signature, 255 B)
-----BEGIN PGP SIGNATURE-----

iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCZjj2FhQcc2ltb25Aam9z
ZWZzc29uLm9yZwAKCRBRcisI/kdFosbIAQD80in0mxkEep+tiAAy/m1zkMTRCTip
cOFn5DfyhoNJ8QEA2QtPw1Y9ARGEUL9RTRkDDfaMDXuEYR6qWa0zf19ZOAw=
=hRQ3
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.