[lamps] Re: [TLS] PQC Dialogue with Government Stakehold ers Side-Meeting at IETF 122 Bangkok
Rob Sayre <[email protected]> Thu, 27 Feb 2025 23:44:57 -0800
| Newsgroups | gmane.ietf.lamps,gmane.ietf.irtf.cfrg,gmane.ietf.tls,gmane.ietf.ipsec,gmane.ietf.woes |
|---|---|
| Message-ID | <CAChr6Swa6LBmgcajwC2PgrWpDmMrfg7DZaV_5sBa0dxce4i3Yw@mail.gmail.com> |
--===============8643686010774779442== Content-Type: multipart/alternative; boundary="0000000000004cf3a0062f2efcf6" --0000000000004cf3a0062f2efcf6 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi, Isn't this off-topic? The IETF can't stop you from having a meeting, but you're crossing the line by using IETF lists to advertise it. thanks, Rob On Thu, Feb 27, 2025 at 11:08=E2=80=AFPM John Mattsson <john.mattsson=3D [email protected]> wrote: > Hi, > > > > There was significant interest from several countries to have a > side-meeting on PQC at IETF 122 Bangkok, so Ericsson will organize such a > meeting on Monday 17 March 15.15 - 16.45 Bangkok time in Meeting Room 2 > [40 seats] (overlapping with Monday Session III). It is possible to > attend remotely. > > https://trello.com/c/nH9exeWo > > > > Potential discussion topics are listed below. There might be a few short > presentations to foster discussion, but the plan is to focus on dialogue > and discussion between people in the IETF and government stakeholders. > > > > Cheers, > > John Preu=C3=9F Mattsson > > Expert, Cryptographic Algorithms and Security Protocols, Ericsson > > > Description > > *Time*: 15:15-16:45 > *Meeting Title:* PQC Dialogue with Government Stakeholders > *IETF Webex:* https://ietf.webex.com/meet/ietfsidemeeting2 > *Meeting Organizer*: John Preu=C3=9F Matsson, Ericsson and Alexander Engs= tr=C3=B6m, > NDRE > *Email address*: [email protected] > > *Meeting Description*: Potential discussion topics: > > - Recommended PQC algorithms (KEMs and signatures) > o ML-KEM, ML-DSA, SLH-DSA, FN-DSA, Classic McEliece, FrodoKEM, > BIKE/HQC, XMSS/LMS, =E2=80=A6 > o Security category 1,2,3,4,5? Does it depend on algorithm and use > case? > - Timelines for PQC migration > o When should migration begin? When will it be required? > o Does it depend on user, use case, protection lifetime, hardware vs > software, migration complexity, value of the protected node and data, > scheduled hardware replacement, etc.? > - Hybridization or standalone PQC > o Difference between KEMs and Signatures > o Differences between algorithms (e.g., lattice-based vs. hash-based) > o Differences between use cases (e.g., confidentiality vs. > authentication) > o Is hybridization a short-term necessity or a long-term strategy? > - Hybridization of PQC KEMs > o Single vs. multiple PQC algorithms? Role of symmetric keys? > o KEM combiners: general-purpose vs. optimized designs > o Which traditional curves? X25519/X448, NIST P-curves, Brainpool, =E2= =80=A6 > - Hybridization of signatures > o Role of symmetric keys? > o Signature combiners, general or optimized? > o Desired properties: SUF-CMA? Other security properties? > o Which traditional signatures? EdDSA, ECDSA, RSA? > - KDF and hash functions > o ML-KEM and ML-DSA mandate SHA-3. > o Time to move away from SHA-2/HMAC/HKDF/MGF? > > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] > --0000000000004cf3a0062f2efcf6 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hi,<div><br></div><div>Isn't this off-topic? The IETF = can't stop you from having a meeting, but you're crossing the line = by using IETF lists to advertise=C2=A0it.</div><div><br></div><div>thanks,<= /div><div>Rob</div><div><br></div></div><br><div class=3D"gmail_quote gmail= _quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Feb 27, 202= 5 at 11:08=E2=80=AFPM John Mattsson <john.mattsson=3D<a href=3D"mailto:4= [email protected]">[email protected]</a>> wrote:<= br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8e= x;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class=3D"ms= g-2686816114191479631"> <div lang=3D"en-SE" style=3D"overflow-wrap: break-word;"> <div class=3D"m_-5282212944074330482WordSection1"> <div id=3D"m_-5282212944074330482mail-editor-reference-message-container"> <div> <div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)">H= i,</span><u></u><u></u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">=C2=A0</span><u></u><u></u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">There was</span><span style=3D"font-size:12pt;color:rgb(33,33= ,33)">=C2=A0significant interest from several countries to have a side-meet= ing on PQC at IETF 122 Bangkok, so<span class=3D"m_-5282212944074330482appl= e-converted-space">=C2=A0</span></span><span lang=3D"EN-US" style=3D"font-s= ize:12pt;color:rgb(33,33,33)">Ericsson</span><span class=3D"m_-528221294407= 4330482apple-converted-space"><span style=3D"font-size:12pt;color:rgb(33,33= ,33)">=C2=A0</span></span><span style=3D"font-size:12pt;color:rgb(33,33,33)= ">will organize such a meeting on Monday 17 March 15.15 - 16.45 Bangkok time</spa= n><span lang=3D"EN-US" style=3D"font-size:12pt;color:rgb(33,33,33)"> in Mee= ting Room 2 [40 seats] (overlapping with </span><span style=3D"font-size:12pt">Monday Session III</span><span lang= =3D"EN-US" style=3D"font-size:12pt">)</span><span style=3D"font-size:12pt;c= olor:rgb(33,33,33)">.</span><span lang=3D"EN-US" style=3D"font-size:12pt;co= lor:rgb(33,33,33)"> It is possible to attend remotely.</span><u></u><u></u>= </p> <p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)"><= a href=3D"https://trello.com/c/nH9exeWo" title=3D"https://trello.com/c/nH9e= xeWo" target=3D"_blank">https://trello.com/c/nH9exeWo</a></span><u></u><u><= /u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">=C2=A0</span><u></u><u></u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">Potential discussion topics are listed below. There might be = a few short presentations to foster discussion, but the plan is to focus on= dialogue and discussion between people in the IETF and government stakeholders.</span><u></u><u></u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">=C2=A0</span><u></u><u></u></p> <p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)">C= heers,</span><u></u><u></u></p> <p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)">J= ohn</span><span class=3D"m_-5282212944074330482apple-converted-space"><span= lang=3D"EN-US" style=3D"font-size:12pt;color:rgb(33,33,33)">=C2=A0</span><= /span><span lang=3D"EN-US" style=3D"font-size:12pt;color:rgb(33,33,33)">Pre= u=C3=9F Mattsson</span><u></u><u></u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">Expert, Cryptographic Algorithms and Security Protocols, Eric= sson</span><u></u><u></u></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r= gb(33,33,33)">=C2=A0</span><u></u><u></u></p> <h3><span style=3D"font-size:12pt">Description</span><u></u><u></u></h3> <p><strong><span style=3D"font-family:Aptos,sans-serif">Time</span></strong= >: 15:15-16:45<br> <strong><span style=3D"font-family:Aptos,sans-serif">Meeting Title:</span><= /strong> PQC Dialogue with Government Stakeholders<br> <strong><span style=3D"font-family:Aptos,sans-serif">IETF Webex:</span></st= rong> <a href=3D"https://ietf.webex.com/meet/ietfsidemeeting2" title=3D"htt= ps://ietf.webex.com/meet/ietfsidemeeting2" target=3D"_blank"> https://ietf.webex.com/meet/ietfsidemeeting2</a><br> <strong><span style=3D"font-family:Aptos,sans-serif">Meeting Organizer</spa= n></strong>: John Preu=C3=9F Matsson, Ericsson and Alexander Engstr=C3=B6m,= NDRE<br> <strong><span style=3D"font-family:Aptos,sans-serif">Email address</span></= strong>: <a href=3D"mailto:[email protected]" title=3D"mailto:john.mattsson= @ericsson.com" target=3D"_blank"> [email protected]</a><u></u><u></u></p> <p><strong><span style=3D"font-family:Aptos,sans-serif">Meeting Description= </span></strong>: Potential discussion topics:<u></u><u></u></p> <ul type=3D"disc"> <li class=3D"MsoNormal"> <span style=3D"font-size:12pt">Recommended PQC algorithms (KEMs and signatu= res)<br> o ML-KEM, ML-DSA, SLH-DSA, FN-DSA, Classic McEliece, FrodoKEM, BIKE/HQC, XM= SS/LMS, =E2=80=A6<br> o Security category 1,2,3,4,5? Does it depend on algorithm and use case?<u>= </u><u></u></span></li><li class=3D"MsoNormal"> <span style=3D"font-size:12pt">Timelines for PQC migration<br> o When should migration begin? When will it be required?<br> o Does it depend on user, use case, protection lifetime, hardware vs softwa= re, migration complexity, value of the protected node and data, scheduled h= ardware replacement, etc.?<u></u><u></u></span></li><li class=3D"MsoNormal"= > <span style=3D"font-size:12pt">Hybridization or standalone PQC<br> o Difference between KEMs and Signatures<br> o Differences between algorithms (e.g., lattice-based vs. hash-based)<br> o Differences between use cases (e.g., confidentiality vs. authentication)<= br> o Is hybridization a short-term necessity or a long-term strategy?<u></u><u= ></u></span></li><li class=3D"MsoNormal"> <span style=3D"font-size:12pt">Hybridization of PQC KEMs<br> o Single vs. multiple PQC algorithms? Role of symmetric keys?<br> o KEM combiners: general-purpose vs. optimized designs<br> o Which traditional curves? X25519/X448, NIST P-curves, Brainpool, =E2=80= =A6<u></u><u></u></span></li><li class=3D"MsoNormal"> <span style=3D"font-size:12pt">Hybridization of signatures<br> o Role of symmetric keys?<br> o Signature combiners, general or optimized?<br> o Desired properties: SUF-CMA? Other security properties?<br> o Which traditional signatures? EdDSA, ECDSA, RSA?<u></u><u></u></span></li= ><li class=3D"MsoNormal"> <span style=3D"font-size:12pt">KDF and hash functions<br> o ML-KEM and ML-DSA mandate SHA-3.<br> o Time to move away from SHA-2/HMAC/HKDF/MGF?<u></u><u></u></span></li></ul= > </div> </div> </div> </div> </div> </div> _______________________________________________<br> TLS mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">tls@i= etf.org</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" targe= t=3D"_blank">[email protected]</a><br> </div></blockquote></div> --0000000000004cf3a0062f2efcf6-- --===============8643686010774779442== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KU3Bhc20gbWFp bGluZyBsaXN0IC0tIHNwYXNtQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gc3Bhc20tbGVhdmVAaWV0Zi5vcmcK --===============8643686010774779442==--