[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt

Stavros Kousidis <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Dear Simon, dear Simo,

I'll try to address all your points in one message.

We aligned the combiner a while ago in draft-ietf-openpgp-pqc-07 (see 
changelog) to match the one defined for the composite KEMs in LAMPS.

In view of draft-irtf-cfrg-hybrid-kems, the OpenPGP combiner is QSF from 
with an OpenPGP-specific label and KDF = SHA3-256 (though we do not 
strictly meet the unified expandDecapsulationKey() interface there, but 
IMO this is neither essential nor necessary).

To make the curve choices more transparent, I think we will have to 
recall the development over time:

Before the split into draft-ietf-openpgp-pqc and 
draft-ietf-openpgp-nist-bp-comp, we had the following in one draft:

- ML-KEM-768 matched with X25519, NIST-P-256, and brainpoolP256r1
- ML-KEM-1024 matched with X448, NIST-P-384, and brainpoolP384r1
- ML-DSA-65 matched with Ed25519, NIST-P-256, and brainpoolP256r1
- ML-DSA-87 matched with Ed448, NIST-P-384, and brainpoolP384r1

The intention was to have a consistent security level for the EC part. 
As CNSA 2.0 recommends 384-bit curves for all classification levels, we 
didn't see a need for NIST-P-521 or brainpoolP512r1 and put X448, 
NIST-P-384, and brainpoolP384r1 in one pot. Those compositions seemed to 
be reasonable choices and to give a minimal set.

During the split, we didn't modify the original brainpoolP choices. As 
for the alteration of the NIST-P compositions, see Quynh’s reply 
(https://mailarchive.ietf.org/arch/msg/openpgp/34145F3_wy67JcazHZe3PqRdWn8 
<https://mailarchive.ietf.org/arch/msg/openpgp/34145F3_wy67JcazHZe3PqRdWn8/>/)<https://mailarchive.ietf.org/arch/msg/openpgp/34145F3_wy67JcazHZe3PqRdWn8/>

Best
Stavros


On 10/11/25 13:23, Simon Josefsson wrote:
> I like that this document moves NIST/BSI curves out from the main
> document, and also that they target the MAY level, so +1 since I think
> we need more PQ hyrid options around.  I wish that PGP would use a
> CFRG-aligned PQ/T combiner, but I also believe CFRG has proven itself
> not worthy to wait for guidance on this matter.  While I prefer the
> Chempat combiner I think it is reasonable to proceed with a custom
> PGP-specific combiner here.  I also found alignment of MLKEM768 with
> P384 and brainpoolP256 surprising, but I don't care strongly about that.
>
> /Simon
>
> Falko Strenzke<[email protected]> writes:
>
>> After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like
>> to initiate the discussion about the code points. The draft currently
>> has
>>
>> 5 for encryption:
>>
>> ML-KEM-512+ECDH-NIST-P-256 	MAY
>> ML-KEM-768+ECDH-NIST-P-384 	MAY
>> ML-KEM-1024+ECDH-NIST-P-384 	MAY
>> ML-KEM-768+ECDH-brainpoolP256r1 	MAY
>> ML-KEM-1024+ECDH-brainpoolP384r1 	MAY
>>
>> 5 for signature:
>>
>> ML-DSA-44+ECDSA-NIST-P-256 	MAY
>> ML-DSA-65+ECDSA-NIST-P-384 	MAY
>> ML-DSA-87+ECDSA-NIST-P-384 	MAY
>> ML-DSA-65+ECDSA-brainpoolP256r1 	MAY
>> ML-DSA-87+ECDSA-brainpoolP384r1 	MAY
>>
>> Please respond on the list whether you agree or disagree with these
>> sets. Questions or discussions about the motivations etc. are of
>> course also welcome.
>>
>> @Chairs: Can we plan a slot at the end of the interim next week to
>> discuss the code points?
>>
>> That being said, I also encourage the WG to read the draft in
>> general. Since it is fully aligned with draft-ietf-openpgp-pqc, the
>> potential for discussions is probably low. The code points are
>> presumably the main discussion point. Once the code points have been
>> agreed on, the draft can probably progress quickly.
>>
>> If you want to review the draft, I suggest to wait until version 01,
>> as we are currently in the process of applying the latest relevant
>> editorial changes that have been made to draft-ietf-openpgp-pqc.
>>
>> Falko
>>
>> Am 09.10.25 um 16:18 [email protected]:
>>> Internet-Draft draft-ietf-openpgp-nist-bp-comp-00.txt is now available. It is
>>> a work item of the Open Specification for Pretty Good Privacy (OPENPGP) WG of
>>> the IETF.
>>>
>>>      Title:   PQ/T Composite Schemes for OpenPGP using NIST and Brainpool Elliptic Curve Domain Parameters
>>>      Authors: Quynh Dang
>>>               Stephan Ehlen
>>>               Stavros Kousidis
>>>               Johannes Roth
>>>               Falko Strenzke
>>>      Name:    draft-ietf-openpgp-nist-bp-comp-00.txt
>>>      Pages:   29
>>>      Dates:   2025-10-09
>>>
>>> Abstract:
>>>
>>>      This document defines PQ/T composite schemes based on ML-KEM and ML-
>>>      DSA combined with ECDH and ECDSA algorithms using the NIST and
>>>      Brainpool domain parameters for the OpenPGP protocol.
>>>
>>> The IETF datatracker status page for this Internet-Draft is:
>>> https://datatracker.ietf.org/doc/draft-ietf-openpgp-nist-bp-comp/
>>>
>>> There is also an HTML version available at:
>>> https://www.ietf.org/archive/id/draft-ietf-openpgp-nist-bp-comp-00.html
>>>
>>> Internet-Drafts are also available by rsync at:
>>> rsync.ietf.org::internet-drafts
>>>
>>>
>>> _______________________________________________
>>> openpgp mailing list [email protected]
>>> To unsubscribe send an [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.