[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt

Simo Sorce <[email protected]>
Newsgroups gmane.ietf.openpgp
Organization Red Hat
Message-ID <[email protected]>
On Tue, 2025-10-14 at 12:41 -0400, Quynh Dang wrote:
> 
> 
> On Tue, Oct 14, 2025 at 10:58 AM Simo Sorce <[email protected]> wrote:
> > On Fri, 2025-10-10 at 12:12 -0400, Quynh Dang wrote:
> > > Hi Simo, 
> > > 
> > > On Fri, Oct 10, 2025 at 10:05 AM Simo Sorce
> > > <[email protected]> wrote:
> > > > On Fri, 2025-10-10 at 06:51 +0200, Falko Strenzke wrote:
> > > > > After the adoption of draft-ietf-openpgp-nist-bp-comp, we
> > > > would like to initiate the discussion about the code points.
> > > > The draft currently has
> > > > 
> > > > > 5 for encryption:
> > > > > 
> > > > > ML-KEM-512+ECDH-NIST-P-256    MAY
> > > > > ML-KEM-768+ECDH-NIST-P-384    MAY
> > > > > ML-KEM-1024+ECDH-NIST-P-384   MAY
> > > > > ML-KEM-768+ECDH-brainpoolP256r1       MAY
> > > > > ML-KEM-1024+ECDH-brainpoolP384r1      MAY
> > > > 
> > > > Any reason why ML-KEM-768 is paired with a 384 bit curve for
> > > > NIST
> > > > curves, but a 256bit curve for Brainpool?
> > > > It seem inconsistent.
> > > > 
> > > 
> > > 
> > > I can speak for the NIST algorithms only. ML-KEM-512+ECDH-NIST-P-
> > > 256 is for level 1 security. ML-KEM-768+ECDH-NIST-P-384 is for
> > > level 3 security (not getting into the details of classical and
> > > pq security here). The reason for having P-384 instead of P521 in
> > > ML-KEM-1024+ECDH-NIST-P-384 is that P-521 is rarely supported as
> > > I have seen in various presentations and I prefer ML-KEM-1024
> > > over ML-KEM-768 and ML-KEM-512. 
> > 
> > 
> > When you say "rarely supported" do you have a specific field of use
> > in mind?
> > 
> 
> 
> I meant less supported or rarely used from what I have seen in the
> past in various presentations.  Another data point just came up in a
> TLS' thread
> here: https://mailarchive.ietf.org/arch/msg/tls/c5gEMi7Lv6glU-8dKEulz_X9FbI/
>   which showed that the use of P521 was not found.  

That's because it is more expensive and most commercial users are fine
with the security provided by P256, In the same discussion there you
can see that ML-KEM-1024 is almost unused compared to ML-KEM-768
(0.015% vs 99.96%)...

Should strength choices be influence by biased popularity contests ?

-- 
Simo Sorce
Distinguished Engineer
RHEL Crypto Team
Red Hat, Inc

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.