OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

pkcs11 message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [pkcs11] Groups - Post Quantum Signatures uploaded


On 2/14/23 7:19 AM, Dieter Bong wrote:

Hi Bob,

Â

I noticed the following when reviewing your proposal:

That only true on the keygen case, not the import case (it's not supplied because it's provided by the public key template.
I thought about that and decided it was a multiplier on the parameter sets, so I recommended that it be a separate parameter. I'd be OK with including it in the parameter set if that makes sense to everyone else.
No, that would be an error.

Â

My general topic for discussion is: how do we proceed from here?

That's a good question. I think it might be good to define everything now, but include parameters for the experimental specs. When the final specs come out, we could include the final spec parameter sets.

Â

Best regards,

Dieter

Â

From: pkcs11@lists.oasis-open.org <pkcs11@lists.oasis-open.org> On Behalf Of Robert Relyea
Sent: Wednesday, February 8, 2023 2:40 AM
To: pkcs11@lists.oasis-open.org
Subject: [pkcs11] Groups - Post Quantum Signatures uploaded

Â

Submitter's message
Notes for Hash algorithms.

Like Kyber, I used CKA_PARAMETER_SET to select a preselected set of parameters. Like Kyber we can define experimental Parameter sets based on the Round 3 spec until the full NIST spec is released.

I defined a base single shot function and a combined hash version. We may want to rethink this because all the post quantum algorithms appear to expect Message to be the full signed message, and processes it through it's own hashing function with some preface values. If that's the case, then the base mechanism should be defined as a multi-part and single part and all the hash and sign mechanisms should be dropped.

SPHINCS+ defines the underlying hash separate from the other parameters (like HSS and XMSS). That underlying hash is a fixed characteristic of the underlying key, so like Parameters I've included it as an attribute on the key. It might be NIST will just pick one (actually likely), so we may not necessarily need it. Each security level of SPHINC+ has two variants - fast and slow. They affect the parameter set definitions, so I made it part of the parameter set (thus 6 parameters sets instead of 3).
-- Mr. Robert Relyea

Document Name: Post Quantum Signatures


Description
This defines the new mechanisms to support the new NIST post quantum
signature algorithms
Download Latest Revision
Public Download Link


Submitter: Mr. Robert Relyea
Group: OASIS PKCS 11 TC
Folder: Working Drafts
Date submitted: 2023-02-07 17:40:23

Â




Utimaco IS GmbH
Germanusstr. 4, D.52080 Aachen, Germany, Tel: +49-241-1696-0, www.utimaco.com
Seat: Aachen â Registergericht Aachen HRB 18922
VAT ID No.: DE 815 496 496
Managementboard: Stefan Auerbach, Martin Stamm

This communication is confidential. If you are not the intended recipient, any use, interference with, disclosure or copying of this material is unauthorised and prohibited. Please inform us immediately and destroy the email.




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]