Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

KEM Combiner Option 2a #160

Closed
fluppe2 opened this issue Nov 28, 2024 · 0 comments · Fixed by #161
Closed

KEM Combiner Option 2a #160

fluppe2 opened this issue Nov 28, 2024 · 0 comments · Fixed by #161

Comments

@fluppe2
Copy link
Collaborator

fluppe2 commented Nov 28, 2024

Prepare a proposal for Option 2a from https://mailarchive.ietf.org/arch/msg/openpgp/NMTCy707LICtxIhP3Xt1U5C8MF0/ with the additions that

i.e.

KDF ( mlkemSS || tradSS || tradCT || tradPK || mlkemCT || mlkemPK || algid || "OpenPGP" )

At the same time propose to drop the final hashing step (introduced for CCA conversion) in the encap/decap of X25519 and X448 and adopt the corresponding reasoning in https://eprint.iacr.org/2024/039 in the security considerations. This further aligns with https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/.

@fluppe2 fluppe2 linked a pull request Nov 28, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant