[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt

Quynh Dang <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <CAE3-qLRes0DjtQcC=XqjXek-9mp_1bkdzW2VOK38pTSy5jtwhw@mail.gmail.com>
On Tue, Oct 14, 2025 at 10:58 AM Simo Sorce <[email protected]> wrote:

> On Fri, 2025-10-10 at 12:12 -0400, Quynh Dang wrote:
>
> Hi Simo,
>
> On Fri, Oct 10, 2025 at 10:05 AM Simo Sorce <simo=
> [email protected]> wrote:
>
> On Fri, 2025-10-10 at 06:51 +0200, Falko Strenzke wrote:
> > After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like to
> initiate the discussion about the code points. The draft currently has
>
> > 5 for encryption:
> >
> > ML-KEM-512+ECDH-NIST-P-256    MAY
> > ML-KEM-768+ECDH-NIST-P-384    MAY
> > ML-KEM-1024+ECDH-NIST-P-384   MAY
> > ML-KEM-768+ECDH-brainpoolP256r1       MAY
> > ML-KEM-1024+ECDH-brainpoolP384r1      MAY
>
> Any reason why ML-KEM-768 is paired with a 384 bit curve for NIST
> curves, but a 256bit curve for Brainpool?
> It seem inconsistent.
>
>
> I can speak for the NIST algorithms only. ML-KEM-512+ECDH-NIST-P-256 is
> for level 1 security. ML-KEM-768+ECDH-NIST-P-384 is for level 3 security
> (not getting into the details of classical and pq security here). The
> reason for having P-384 instead of P521 in ML-KEM-1024+ECDH-NIST-P-384 is
> that P-521 is rarely supported as I have seen in various presentations and
> I prefer ML-KEM-1024 over ML-KEM-768 and ML-KEM-512.
>
>
> When you say "rarely supported" do you have a specific field of use in
> mind?
>

I meant less supported or rarely used from what I have seen in the past in
various presentations.  Another data point just came up in a TLS' thread
here: https://mailarchive.ietf.org/arch/msg/tls/c5gEMi7Lv6glU-8dKEulz_X9FbI/
which showed that the use of P521 was not found.

Regards,
Quynh.




>
> As far as I know most common crypto libraries either support all or none
> of the NIST Elliptic Curves, and in fact for a long time P-384 was less
> well supported than either P-256 or P-521 in at least a few well know
> libraries (no optimizations and/or side-channel issues).
>
> Eitherway unless there is a reall issue with Hardware Tokens this choice
> remains bizarre to me. And if HW tokens are the issue I am still confused
> given no HW token I know of supports ML-KEM-1024 anyway.
>
> HTH,
> Simo.
>
> --
>
> Simo Sorce
> Distinguished Engineer
> RHEL Crypto Team
> Red Hat, Inc
>
>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.