[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt

Quynh Dang <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <CAE3-qLTdCvODRpEz3HzibZ-DbnnYdOxQchJda+i0E77vNzxacA@mail.gmail.com>
On Tue, Oct 14, 2025 at 1:30 PM Simo Sorce <[email protected]> wrote:

> On Tue, 2025-10-14 at 12:41 -0400, Quynh Dang wrote:
>
>
>
> On Tue, Oct 14, 2025 at 10:58 AM Simo Sorce <[email protected]> wrote:
>
> On Fri, 2025-10-10 at 12:12 -0400, Quynh Dang wrote:
>
> Hi Simo,
>
> On Fri, Oct 10, 2025 at 10:05 AM Simo Sorce <simo=
> [email protected]> wrote:
>
> On Fri, 2025-10-10 at 06:51 +0200, Falko Strenzke wrote:
> > After the adoption of draft-ietf-openpgp-nist-bp-comp, we would like to
> initiate the discussion about the code points. The draft currently has
>
> > 5 for encryption:
> >
> > ML-KEM-512+ECDH-NIST-P-256    MAY
> > ML-KEM-768+ECDH-NIST-P-384    MAY
> > ML-KEM-1024+ECDH-NIST-P-384   MAY
> > ML-KEM-768+ECDH-brainpoolP256r1       MAY
> > ML-KEM-1024+ECDH-brainpoolP384r1      MAY
>
> Any reason why ML-KEM-768 is paired with a 384 bit curve for NIST
> curves, but a 256bit curve for Brainpool?
> It seem inconsistent.
>
>
> I can speak for the NIST algorithms only. ML-KEM-512+ECDH-NIST-P-256 is
> for level 1 security. ML-KEM-768+ECDH-NIST-P-384 is for level 3 security
> (not getting into the details of classical and pq security here). The
> reason for having P-384 instead of P521 in ML-KEM-1024+ECDH-NIST-P-384 is
> that P-521 is rarely supported as I have seen in various presentations and
> I prefer ML-KEM-1024 over ML-KEM-768 and ML-KEM-512.
>
>
> When you say "rarely supported" do you have a specific field of use in
> mind?
>
>
> I meant less supported or rarely used from what I have seen in the past in
> various presentations.  Another data point just came up in a TLS' thread
> here:
> https://mailarchive.ietf.org/arch/msg/tls/c5gEMi7Lv6glU-8dKEulz_X9FbI/
> which showed that the use of P521 was not found.
>
>
> That's because it is more expensive and most commercial users are fine
> with the security provided by P256, In the same discussion there you can
> see that ML-KEM-1024 is almost unused compared to ML-KEM-768 (0.015% vs
> 99.96%)...
>
> Should strength choices be influence by biased popularity contests ?
>

I would have no objections if you or another member want to add ML-KEM-1024
with P521.

Regards,
Quynh.


>
> --
>
> Simo Sorce
> Distinguished Engineer
> RHEL Crypto Team
> Red Hat, Inc
>
>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.