Re: [PATCH 09/10] kyber: use strong random for encapsulation coins

Werner Koch via Gcrypt-devel <[email protected]> Mon, 03 Aug 2026 14:50:49 +0200
Newsgroups gmane.comp.encryption.gpg.libgcrypt.devel
Message-ID <[email protected]>
--===============5475854079677592150==
Content-Type: multipart/signed; boundary="=Foot_and_Mouth_Influenza_KGB_MARTA_Suspicious_package_JANET_Mole_Clo";
	micalg=pgp-sha512; protocol="application/pgp-signature"

--=Foot_and_Mouth_Influenza_KGB_MARTA_Suspicious_package_JANET_Mole_Clo
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Sun,  2 Aug 2026 12:55, Jussi Kivilinna said:
> 'randombytes' used GCRY_VERY_STRONG_RANDOM for both key generation and
> encapsulation. Encapsulation coins are per message ephemeral value, same
> as ECDH ephemeral secret in 'ecc-ecdh.c' and as coins for sntrup761 and

That is a good idea.

BTW, we also need to do some internal changes to the Kyber
implementation so that we can get the seed value back using the
gcry_pk_genkey inteface.  Although not yet NSA^WNIST approved, using the
seed as private key is what IETF and other specifications prefer.


Salam-Shalom,

   Werner

=2D-=20
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

--=Foot_and_Mouth_Influenza_KGB_MARTA_Suspicious_package_JANET_Mole_Clo
Content-Type: application/pgp-signature; name="openpgp-digital-signature.asc"

-----BEGIN PGP SIGNATURE-----

iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCanCOqRsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQemubAP93
Od4dijXkv4o1Erj3zAwXAfJFFHoX7tw6xI9M3KRtaAD+JjjJB4DP95PoQF5OJ1td
V4ThFWMmad7O15G5dHCaMQc=
=IsDZ
-----END PGP SIGNATURE-----
--=Foot_and_Mouth_Influenza_KGB_MARTA_Suspicious_package_JANET_Mole_Clo--



--===============5475854079677592150==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gcrypt-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gcrypt-devel

--===============5475854079677592150==--