[lamps] Re: [TLS] PQC Dialogue with Government Stakehold ers Side-Meeting at IETF 122 Bangkok

Rob Sayre <[email protected]> Thu, 27 Feb 2025 23:44:57 -0800
Newsgroups gmane.ietf.lamps,gmane.ietf.irtf.cfrg,gmane.ietf.tls,gmane.ietf.ipsec,gmane.ietf.woes
Message-ID <CAChr6Swa6LBmgcajwC2PgrWpDmMrfg7DZaV_5sBa0dxce4i3Yw@mail.gmail.com>
--===============8643686010774779442==
Content-Type: multipart/alternative; boundary="0000000000004cf3a0062f2efcf6"

--0000000000004cf3a0062f2efcf6
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

Isn't this off-topic? The IETF can't stop you from having a meeting, but
you're crossing the line by using IETF lists to advertise it.

thanks,
Rob


On Thu, Feb 27, 2025 at 11:08=E2=80=AFPM John Mattsson <john.mattsson=3D
[email protected]> wrote:

> Hi,
>
>
>
> There was significant interest from several countries to have a
> side-meeting on PQC at IETF 122 Bangkok, so Ericsson will organize such a
> meeting on Monday 17 March 15.15 - 16.45 Bangkok time in Meeting Room 2
> [40 seats] (overlapping with Monday Session III). It is possible to
> attend remotely.
>
> https://trello.com/c/nH9exeWo
>
>
>
> Potential discussion topics are listed below. There might be a few short
> presentations to foster discussion, but the plan is to focus on dialogue
> and discussion between people in the IETF and government stakeholders.
>
>
>
> Cheers,
>
> John Preu=C3=9F Mattsson
>
> Expert, Cryptographic Algorithms and Security Protocols, Ericsson
>
>
> Description
>
> *Time*: 15:15-16:45
> *Meeting Title:* PQC Dialogue with Government Stakeholders
> *IETF Webex:* https://ietf.webex.com/meet/ietfsidemeeting2
> *Meeting Organizer*: John Preu=C3=9F Matsson, Ericsson and Alexander Engs=
tr=C3=B6m,
> NDRE
> *Email address*: [email protected]
>
> *Meeting Description*: Potential discussion topics:
>
>    - Recommended PQC algorithms (KEMs and signatures)
>    o ML-KEM, ML-DSA, SLH-DSA, FN-DSA, Classic McEliece, FrodoKEM,
>    BIKE/HQC, XMSS/LMS, =E2=80=A6
>    o Security category 1,2,3,4,5? Does it depend on algorithm and use
>    case?
>    - Timelines for PQC migration
>    o When should migration begin? When will it be required?
>    o Does it depend on user, use case, protection lifetime, hardware vs
>    software, migration complexity, value of the protected node and data,
>    scheduled hardware replacement, etc.?
>    - Hybridization or standalone PQC
>    o Difference between KEMs and Signatures
>    o Differences between algorithms (e.g., lattice-based vs. hash-based)
>    o Differences between use cases (e.g., confidentiality vs.
>    authentication)
>    o Is hybridization a short-term necessity or a long-term strategy?
>    - Hybridization of PQC KEMs
>    o Single vs. multiple PQC algorithms? Role of symmetric keys?
>    o KEM combiners: general-purpose vs. optimized designs
>    o Which traditional curves? X25519/X448, NIST P-curves, Brainpool, =E2=
=80=A6
>    - Hybridization of signatures
>    o Role of symmetric keys?
>    o Signature combiners, general or optimized?
>    o Desired properties: SUF-CMA? Other security properties?
>    o Which traditional signatures? EdDSA, ECDSA, RSA?
>    - KDF and hash functions
>    o ML-KEM and ML-DSA mandate SHA-3.
>    o Time to move away from SHA-2/HMAC/HKDF/MGF?
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

--0000000000004cf3a0062f2efcf6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>Isn&#39;t this off-topic? The IETF =
can&#39;t stop you from having a meeting, but you&#39;re crossing the line =
by using IETF lists to advertise=C2=A0it.</div><div><br></div><div>thanks,<=
/div><div>Rob</div><div><br></div></div><br><div class=3D"gmail_quote gmail=
_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Feb 27, 202=
5 at 11:08=E2=80=AFPM John Mattsson &lt;john.mattsson=3D<a href=3D"mailto:4=
[email protected]">[email protected]</a>&gt; wrote:<=
br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8e=
x;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class=3D"ms=
g-2686816114191479631">





<div lang=3D"en-SE" style=3D"overflow-wrap: break-word;">
<div class=3D"m_-5282212944074330482WordSection1">
<div id=3D"m_-5282212944074330482mail-editor-reference-message-container">
<div>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)">H=
i,</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">=C2=A0</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">There was</span><span style=3D"font-size:12pt;color:rgb(33,33=
,33)">=C2=A0significant interest from several countries to have a side-meet=
ing on PQC at IETF 122 Bangkok, so<span class=3D"m_-5282212944074330482appl=
e-converted-space">=C2=A0</span></span><span lang=3D"EN-US" style=3D"font-s=
ize:12pt;color:rgb(33,33,33)">Ericsson</span><span class=3D"m_-528221294407=
4330482apple-converted-space"><span style=3D"font-size:12pt;color:rgb(33,33=
,33)">=C2=A0</span></span><span style=3D"font-size:12pt;color:rgb(33,33,33)=
">will
 organize such a meeting on Monday 17 March 15.15 - 16.45 Bangkok time</spa=
n><span lang=3D"EN-US" style=3D"font-size:12pt;color:rgb(33,33,33)"> in Mee=
ting Room 2 [40 seats] (overlapping with
</span><span style=3D"font-size:12pt">Monday Session III</span><span lang=
=3D"EN-US" style=3D"font-size:12pt">)</span><span style=3D"font-size:12pt;c=
olor:rgb(33,33,33)">.</span><span lang=3D"EN-US" style=3D"font-size:12pt;co=
lor:rgb(33,33,33)"> It is possible to attend remotely.</span><u></u><u></u>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)"><=
a href=3D"https://trello.com/c/nH9exeWo" title=3D"https://trello.com/c/nH9e=
xeWo" target=3D"_blank">https://trello.com/c/nH9exeWo</a></span><u></u><u><=
/u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">=C2=A0</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">Potential discussion topics are listed below. There might be =
a few short presentations to foster discussion, but the plan is to focus on=
 dialogue and discussion between people in
 the IETF and government stakeholders.</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">=C2=A0</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)">C=
heers,</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12pt;color:rgb(33,33,33)">J=
ohn</span><span class=3D"m_-5282212944074330482apple-converted-space"><span=
 lang=3D"EN-US" style=3D"font-size:12pt;color:rgb(33,33,33)">=C2=A0</span><=
/span><span lang=3D"EN-US" style=3D"font-size:12pt;color:rgb(33,33,33)">Pre=
u=C3=9F Mattsson</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">Expert, Cryptographic Algorithms and Security Protocols, Eric=
sson</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12pt;color:r=
gb(33,33,33)">=C2=A0</span><u></u><u></u></p>
<h3><span style=3D"font-size:12pt">Description</span><u></u><u></u></h3>
<p><strong><span style=3D"font-family:Aptos,sans-serif">Time</span></strong=
>: 15:15-16:45<br>
<strong><span style=3D"font-family:Aptos,sans-serif">Meeting Title:</span><=
/strong> PQC Dialogue with Government Stakeholders<br>
<strong><span style=3D"font-family:Aptos,sans-serif">IETF Webex:</span></st=
rong> <a href=3D"https://ietf.webex.com/meet/ietfsidemeeting2" title=3D"htt=
ps://ietf.webex.com/meet/ietfsidemeeting2" target=3D"_blank">
https://ietf.webex.com/meet/ietfsidemeeting2</a><br>
<strong><span style=3D"font-family:Aptos,sans-serif">Meeting Organizer</spa=
n></strong>: John Preu=C3=9F Matsson, Ericsson and Alexander Engstr=C3=B6m,=
 NDRE<br>
<strong><span style=3D"font-family:Aptos,sans-serif">Email address</span></=
strong>:
<a href=3D"mailto:[email protected]" title=3D"mailto:john.mattsson=
@ericsson.com" target=3D"_blank">
[email protected]</a><u></u><u></u></p>
<p><strong><span style=3D"font-family:Aptos,sans-serif">Meeting Description=
</span></strong>: Potential discussion topics:<u></u><u></u></p>
<ul type=3D"disc">
<li class=3D"MsoNormal">
<span style=3D"font-size:12pt">Recommended PQC algorithms (KEMs and signatu=
res)<br>
o ML-KEM, ML-DSA, SLH-DSA, FN-DSA, Classic McEliece, FrodoKEM, BIKE/HQC, XM=
SS/LMS, =E2=80=A6<br>
o Security category 1,2,3,4,5? Does it depend on algorithm and use case?<u>=
</u><u></u></span></li><li class=3D"MsoNormal">
<span style=3D"font-size:12pt">Timelines for PQC migration<br>
o When should migration begin? When will it be required?<br>
o Does it depend on user, use case, protection lifetime, hardware vs softwa=
re, migration complexity, value of the protected node and data, scheduled h=
ardware replacement, etc.?<u></u><u></u></span></li><li class=3D"MsoNormal"=
>
<span style=3D"font-size:12pt">Hybridization or standalone PQC<br>
o Difference between KEMs and Signatures<br>
o Differences between algorithms (e.g., lattice-based vs. hash-based)<br>
o Differences between use cases (e.g., confidentiality vs. authentication)<=
br>
o Is hybridization a short-term necessity or a long-term strategy?<u></u><u=
></u></span></li><li class=3D"MsoNormal">
<span style=3D"font-size:12pt">Hybridization of PQC KEMs<br>
o Single vs. multiple PQC algorithms? Role of symmetric keys?<br>
o KEM combiners: general-purpose vs. optimized designs<br>
o Which traditional curves? X25519/X448, NIST P-curves, Brainpool, =E2=80=
=A6<u></u><u></u></span></li><li class=3D"MsoNormal">
<span style=3D"font-size:12pt">Hybridization of signatures<br>
o Role of symmetric keys?<br>
o Signature combiners, general or optimized?<br>
o Desired properties: SUF-CMA? Other security properties?<br>
o Which traditional signatures? EdDSA, ECDSA, RSA?<u></u><u></u></span></li=
><li class=3D"MsoNormal">
<span style=3D"font-size:12pt">KDF and hash functions<br>
o ML-KEM and ML-DSA mandate SHA-3.<br>
o Time to move away from SHA-2/HMAC/HKDF/MGF?<u></u><u></u></span></li></ul=
>
</div>
</div>
</div>
</div>
</div>
</div>

_______________________________________________<br>
TLS mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">tls@i=
etf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" targe=
t=3D"_blank">[email protected]</a><br>
</div></blockquote></div>

--0000000000004cf3a0062f2efcf6--


--===============8643686010774779442==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KU3Bhc20gbWFp
bGluZyBsaXN0IC0tIHNwYXNtQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gc3Bhc20tbGVhdmVAaWV0Zi5vcmcK

--===============8643686010774779442==--