[prev in list] [next in list] [prev in thread] [next in thread] 

List:       cfrg
Subject:    [CFRG] =?utf-8?b?562U5aSNOiAgSS1EIEFjdGlvbjogZHJhZnQtaXJ0Zi1j?= =?utf-8?q?frg-det-sigs-with-noise-03
From:       Niu Danny <dannyniu () hotmail ! com>
Date:       2024-03-18 8:07:18
Message-ID: OS3P286MB1920C86EC1C61283A44089BAC12D2 () OS3P286MB1920 ! JPNP286 ! PROD ! OUTLOOK ! COM
[Download RAW message or body]

[Attachment #2 (text/plain)]

I found some inconsistencies between my implementation and -03 draft over the ECDSA \
P-384/SHAKE-256 KMAC-256 instance. I've updated test vectors and posted in the same \
GitHub issue.

发件人: John Mattsson <john.mattsson@ericsson.com>
日期: 星期一, 2024年3月18日 10:13
收件人: Niu Danny <dannyniu@hotmail.com>, cfrg@ietf.org <cfrg@ietf.org>
主题: Re: [CFRG] I-D Action: draft-irtf-cfrg-det-sigs-with-noise-03.txt
Thanks Danny!

We will upload a new version after Brisbane with test vectors.

Cheers,
John Preuß Mattsson

From: Niu Danny <dannyniu@hotmail.com>
Date: Sunday, 17 March 2024 at 20:26
To: John Mattsson <john.mattsson@ericsson.com>, cfrg@ietf.org <cfrg@ietf.org>
Subject: 答复: [CFRG] I-D Action: draft-irtf-cfrg-det-sigs-with-noise-03.txt
I've generated preliminary test vectors for the 6 most common instances of DSS \
algorithms. I've posted it on one of the GitHub issues for this draft: \
https://github.com/cfrg/draft-irtf-cfrg-det-sigs-with-noise/issues/11

发件人: CFRG <cfrg-bounces@irtf.org> 代表 John Mattsson \
<john.mattsson=40ericsson.com@dmarc.ietf.org> 日期: 星期六, 2024年3月16日 \
22:45 收件人: cfrg@ietf.org <cfrg@ietf.org>
主题: Re: [CFRG] I-D Action: draft-irtf-cfrg-det-sigs-with-noise-03.txt
Hi,
We have just uploaded version -03 of Hedged ECDSA and EdDSA Signatures.

- Several of the changes are due to Danny Niu who pointed out that different Zd and \
Zf are not compatible with HMAC_DRBG and that the output length recommendations for \
KMAC led to unecesary many iterations. Danny has also promised to provide test \
vectors. The plan is to provide test vectors on the form

MESSAGE = { }
SECRET KEY = { }
RANDOM DATA = { }
SIGNATURE = { }

which allows testing implementations. This has been requested by several people.

Changes from -02 to -03:

   *  Same randomness Z in step d and f to align with HMAC_DRBG.

   *  Changed Hedged EdDSA order to 0x00 || Z || dom2(F, C) instead of
      dom2(F, C) || Z.  This avoids collisions with RFC 8032 and aligns
      with Bernstein's recommendation to put Z before the context.

   *  Changed KMAC output length recommendations to avoid multiple
      invocations.

   *  Updates some text to align with the hedged signatures/signing
      terminology.

   *  Added more description about the construction.

   *  Editorial changes.

   Changes from -01 to -02:

   *  Different names Zd and Zf for the randomness in ECDSA.

   *  Added empty test vector section as TODO.
Cheers,
John Preuß Mattsson

From: CFRG <cfrg-bounces@irtf.org> on behalf of internet-drafts@ietf.org \
                <internet-drafts@ietf.org>
Date: Sunday, 17 March 2024 at 00:23
To: i-d-announce@ietf.org <i-d-announce@ietf.org>
Cc: cfrg@ietf.org <cfrg@ietf.org>
Subject: [CFRG] I-D Action: draft-irtf-cfrg-det-sigs-with-noise-03.txt
Internet-Draft draft-irtf-cfrg-det-sigs-with-noise-03.txt is now available. It
is a work item of the Crypto Forum (CFRG) RG of the IRTF.

   Title:   Hedged ECDSA and EdDSA Signatures
   Authors: John Preuß Mattsson
            Erik Thormarker
            Sini Ruohomaa
   Name:    draft-irtf-cfrg-det-sigs-with-noise-03.txt
   Pages:   17
   Dates:   2024-03-16

Abstract:

   Deterministic elliptic-curve signatures such as deterministic ECDSA
   and EdDSA have gained popularity over randomized ECDSA as their
   security does not depend on a source of high-quality randomness.
   Recent research, however, has found that implementations of these
   signature algorithms may be vulnerable to certain side-channel and
   fault injection attacks due to their deterministic nature.  One
   countermeasure to such attacks is hedged signatures where the
   calculation of the per-message secret number includes both fresh
   randomness and the message.  This document updates RFC 6979 and RFC
   8032 to recommend hedged constructions in deployments where side-
   channel attacks and fault injection attacks are a concern.  The
   updates are invisible to the validator of the signature and
   compatible with existing ECDSA and EdDSA validators.

The IETF datatracker status page for this Internet-Draft is:
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org \
%2Fdoc%2Fdraft-irtf-cfrg-det-sigs-with-noise%2F&data=05%7C02%7Cjohn.mattsson%40ericsso \
n.com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C \
638461958362723970%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI \
6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=2tEDHm7Hafaxxrtyl8dblJyOGhf6KhtXhpwL5cQVYT8 \
%3D&reserved=0<https://datatracker.ietf.org/doc/draft-irtf-cfrg-det-sigs-with-noise/>

There is also an HTML version available at:
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchi \
ve%2Fid%2Fdraft-irtf-cfrg-det-sigs-with-noise-03.html&data=05%7C02%7Cjohn.mattsson%40e \
ricsson.com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080c6b87953f%7C0% \
7C0%7C638461958362730819%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiL \
CJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=7gqRE%2Bq1rv62472ZbFWNNHkb9%2FYK7kWSL \
wgN473KzEA%3D&reserved=0<https://www.ietf.org/archive/id/draft-irtf-cfrg-det-sigs-with-noise-03.html>


A diff from the previous version is available at:
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ietf.or \
g%2Fiddiff%3Furl2%3Ddraft-irtf-cfrg-det-sigs-with-noise-03&data=05%7C02%7Cjohn.mattsso \
n%40ericsson.com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080c6b87953f \
%7C0%7C0%7C638461958362735971%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2lu \
MzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=iU9Ri9FU4jCWTu60%2BIJLtkrJVGioFI \
6tZP4%2BrXQSUjE%3D&reserved=0<https://author-tools.ietf.org/iddiff?url2=draft-irtf-cfrg-det-sigs-with-noise-03>


Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
CFRG mailing list
CFRG@irtf.org
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailman.irtf.org%2Fm \
ailman%2Flistinfo%2Fcfrg&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7Cbb03fcc1644148a \
ee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638461958362740362%7CUn \
known%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D \
%7C0%7C%7C%7C&sdata=Hv88eE2P%2Fbx8PDija6soUYgE%2Ft50POn2Oe3r3DzFpXA%3D&reserved=0<https://mailman.irtf.org/mailman/listinfo/cfrg>



[Attachment #3 (text/html)]

<html xmlns:o="urn:schemas-microsoft-com:office:office" \
xmlns:w="urn:schemas-microsoft-com:office:word" \
xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" \
xmlns="http://www.w3.org/TR/REC-html40"> <head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:宋体;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"MS Gothic";
	panose-1:2 11 6 9 7 2 5 8 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:DengXian;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:Aptos;
	panose-1:2 11 0 4 2 2 2 2 2 4;}
@font-face
	{font-family:"\@等线";
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"\@宋体";
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"\@MS Gothic";
	panose-1:2 11 6 9 7 2 5 8 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:DengXian;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang="ZH-CN" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.5pt;font-family:DengXian">I found some inconsistencies between my \
implementation and -03 draft over the ECDSA P-384/SHAKE-256 KMAC-256 instance. I've \
updated test vectors and posted in the same GitHub  issue.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.5pt;font-family:DengXian"><o:p>&nbsp;</o:p></span></p> <div \
id="mail-editor-reference-message-container"> <div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span \
style="font-family:宋体;color:black">发件人</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> John Mattsson \
&lt;john.mattsson@ericsson.com&gt;<br> </span><b><span \
style="font-family:宋体;color:black">日期</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> </span><span \
style="font-family:宋体;color:black">星期一</span><span style="color:black">, \
2024</span><span style="font-family:宋体;color:black">年</span><span \
style="color:black">3</span><span \
style="font-family:宋体;color:black">月</span><span \
style="color:black">18</span><span \
style="font-family:宋体;color:black">日</span><span style="color:black">  \
10:13<br> </span><b><span \
style="font-family:宋体;color:black">收件人</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> Niu Danny \
&lt;dannyniu@hotmail.com&gt;, cfrg@ietf.org &lt;cfrg@ietf.org&gt;<br> </span><b><span \
style="font-family:宋体;color:black">主题</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> Re: [CFRG] I-D Action: \
draft-irtf-cfrg-det-sigs-with-noise-03.txt<o:p></o:p></span></p> </div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks \
Danny!</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">We will upload a new version after Brisbane with test \
vectors.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">Cheers,</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">John Preuß Mattsson</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <div \
id="mail-editor-reference-message-container"> <div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="color:black">From:
</span></b><span style="color:black">Niu Danny &lt;dannyniu@hotmail.com&gt;<br>
<b>Date: </b>Sunday, 17 March 2024 at 20:26<br>
<b>To: </b>John Mattsson &lt;john.mattsson@ericsson.com&gt;, cfrg@ietf.org \
&lt;cfrg@ietf.org&gt;<br> <b>Subject: </b></span><span style="font-family:&quot;MS \
Gothic&quot;;color:black">答复</span><span style="color:black">: [CFRG] I-D Action: \
draft-irtf-cfrg-det-sigs-with-noise-03.txt</span><o:p></o:p></p> </div>
<div>
<p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.5pt;font-family:DengXian">I</span><span \
style="font-size:10.5pt;font-family:DengXian">'</span><span lang="EN-US" \
style="font-size:10.5pt;font-family:DengXian">ve generated preliminary test vectors  \
for the 6 most common instances of DSS algorithms. I</span><span \
style="font-size:10.5pt;font-family:DengXian">'</span><span lang="EN-US" \
style="font-size:10.5pt;font-family:DengXian">ve posted it on one of the GitHub \
issues for this draft: <a \
href="https://github.com/cfrg/draft-irtf-cfrg-det-sigs-with-noise/issues/11">https://g \
ithub.com/cfrg/draft-irtf-cfrg-det-sigs-with-noise/issues/11</a></span><o:p></o:p></p>
 <p class="MsoNormal"><span lang="EN-US" \
style="font-size:10.5pt;font-family:DengXian">&nbsp;</span><o:p></o:p></p> <div \
id="mail-editor-reference-message-container"> <div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span \
style="font-family:宋体;color:black">发件人</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> CFRG \
&lt;cfrg-bounces@irtf.org&gt; </span><span \
style="font-family:宋体;color:black">代表</span><span style="color:black"> John \
Mattsson &lt;john.mattsson=40ericsson.com@dmarc.ietf.org&gt;<br> </span><b><span \
style="font-family:宋体;color:black">日期</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> </span><span \
style="font-family:宋体;color:black">星期六</span><span style="color:black">, \
2024</span><span style="font-family:宋体;color:black">年</span><span \
style="color:black">3</span><span \
style="font-family:宋体;color:black">月</span><span \
style="color:black">16</span><span \
style="font-family:宋体;color:black">日</span><span style="color:black">  \
22:45<br> </span><b><span \
style="font-family:宋体;color:black">收件人</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> cfrg@ietf.org \
&lt;cfrg@ietf.org&gt;<br> </span><b><span \
style="font-family:宋体;color:black">主题</span></b><b><span \
style="color:black">:</span></b><span style="color:black"> Re: [CFRG] I-D Action: \
draft-irtf-cfrg-det-sigs-with-noise-03.txt</span><o:p></o:p></p> </div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Hi,</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:11.0pt">We have just uploaded version -03 \
of Hedged ECDSA and EdDSA Signatures.</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">- Several of the changes are due to \
Danny Niu who pointed out that different Zd and Zf are not compatible with HMAC_DRBG \
and that the output length recommendations for KMAC led to unecesary many iterations. \
Danny has also promised to provide test vectors. The plan is to provide test vectors \
on the form</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">MESSAGE = { }</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">SECRET KEY = { \
}</span><o:p></o:p></p> <p class="MsoNormal"><span style="font-size:11.0pt">RANDOM \
DATA = { }</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">SIGNATURE = { }</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">which allows testing \
implementations. This has been requested by several people.</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">Changes from -02 to \
-03:</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Same randomness Z in step d and f to \
align with HMAC_DRBG.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Changed Hedged EdDSA order to 0x00 || Z \
|| dom2(F, C) instead of</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; dom2(F, C) || Z.&nbsp; This \
avoids collisions with RFC 8032 and aligns</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; with \
Bernstein's recommendation to put Z before the context.</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Changed KMAC \
output length recommendations to avoid multiple</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \
invocations.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Updates some text to align with the \
hedged signatures/signing</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \
terminology.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Added more description about the \
construction.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Editorial \
changes.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">&nbsp;&nbsp; Changes from -01 to -02:</span><o:p></o:p></p> \
<p class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Different names \
Zd and Zf for the randomness in ECDSA.</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;&nbsp; *&nbsp; Added empty \
test vector section as TODO.</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">Cheers,</span><o:p></o:p></p> <p class="MsoNormal"><span \
style="font-size:11.0pt">John Preuß Mattsson</span><o:p></o:p></p> <p \
class="MsoNormal"><span style="font-size:11.0pt">&nbsp;</span><o:p></o:p></p> <div \
id="mail-editor-reference-message-container"> <div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="color:black">From:
</span></b><span style="color:black">CFRG &lt;cfrg-bounces@irtf.org&gt; on behalf of \
internet-drafts@ietf.org &lt;internet-drafts@ietf.org&gt;<br> <b>Date: </b>Sunday, 17 \
March 2024 at 00:23<br> <b>To: </b>i-d-announce@ietf.org \
&lt;i-d-announce@ietf.org&gt;<br> <b>Cc: </b>cfrg@ietf.org &lt;cfrg@ietf.org&gt;<br>
<b>Subject: </b>[CFRG] I-D Action: \
draft-irtf-cfrg-det-sigs-with-noise-03.txt</span><o:p></o:p></p> </div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Internet-Draft \
draft-irtf-cfrg-det-sigs-with-noise-03.txt is now available. It<br> is a work item of \
the Crypto Forum (CFRG) RG of the IRTF.<br> <br>
&nbsp;&nbsp; Title:&nbsp;&nbsp; Hedged ECDSA and EdDSA Signatures<br>
&nbsp;&nbsp; Authors: John Preuß Mattsson<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Erik \
Thormarker<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \
Sini Ruohomaa<br> &nbsp;&nbsp; Name:&nbsp;&nbsp;&nbsp; \
draft-irtf-cfrg-det-sigs-with-noise-03.txt<br> &nbsp;&nbsp; Pages:&nbsp;&nbsp; 17<br>
&nbsp;&nbsp; Dates:&nbsp;&nbsp; 2024-03-16<br>
<br>
Abstract:<br>
<br>
&nbsp;&nbsp; Deterministic elliptic-curve signatures such as deterministic ECDSA<br>
&nbsp;&nbsp; and EdDSA have gained popularity over randomized ECDSA as their<br>
&nbsp;&nbsp; security does not depend on a source of high-quality randomness.<br>
&nbsp;&nbsp; Recent research, however, has found that implementations of these<br>
&nbsp;&nbsp; signature algorithms may be vulnerable to certain side-channel and<br>
&nbsp;&nbsp; fault injection attacks due to their deterministic nature.&nbsp; One<br>
&nbsp;&nbsp; countermeasure to such attacks is hedged signatures where the<br>
&nbsp;&nbsp; calculation of the per-message secret number includes both fresh<br>
&nbsp;&nbsp; randomness and the message.&nbsp; This document updates RFC 6979 and \
RFC<br> &nbsp;&nbsp; 8032 to recommend hedged constructions in deployments where \
side-<br> &nbsp;&nbsp; channel attacks and fault injection attacks are a \
concern.&nbsp; The<br> &nbsp;&nbsp; updates are invisible to the validator of the \
signature and<br> &nbsp;&nbsp; compatible with existing ECDSA and EdDSA \
validators.<br> <br>
The IETF datatracker status page for this Internet-Draft is:<br>
<a href="https://datatracker.ietf.org/doc/draft-irtf-cfrg-det-sigs-with-noise/">https: \
//eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc \
%2Fdraft-irtf-cfrg-det-sigs-with-noise%2F&amp;data=05%7C02%7Cjohn.mattsson%40ericsson. \
com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C63 \
8461958362723970%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6I \
k1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=2tEDHm7Hafaxxrtyl8dblJyOGhf6KhtXhpwL5cQVYT8%3D&amp;reserved=0</a><br>
 <br>
There is also an HTML version available at:<br>
<a href="https://www.ietf.org/archive/id/draft-irtf-cfrg-det-sigs-with-noise-03.html"> \
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchi \
ve%2Fid%2Fdraft-irtf-cfrg-det-sigs-with-noise-03.html&amp;data=05%7C02%7Cjohn.mattsson \
%40ericsson.com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080c6b87953f% \
7C0%7C0%7C638461958362730819%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luM \
zIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=7gqRE%2Bq1rv62472ZbFWNNHkb9%2FYK7kWSLwgN473KzEA%3D&amp;reserved=0</a><br>
 <br>
A diff from the previous version is available at:<br>
<a href="https://author-tools.ietf.org/iddiff?url2=draft-irtf-cfrg-det-sigs-with-noise \
-03">https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ie \
tf.org%2Fiddiff%3Furl2%3Ddraft-irtf-cfrg-det-sigs-with-noise-03&amp;data=05%7C02%7Cjoh \
n.mattsson%40ericsson.com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84cebfbfd47abbe52080 \
c6b87953f%7C0%7C0%7C638461958362735971%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJ \
QIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=iU9Ri9FU4jCWTu60%2BIJLtkrJVGioFI6tZP4%2BrXQSUjE%3D&amp;reserved=0</a><br>
 <br>
Internet-Drafts are also available by rsync at:<br>
rsync.ietf.org::internet-drafts<br>
<br>
<br>
_______________________________________________<br>
CFRG mailing list<br>
CFRG@irtf.org<br>
<a href="https://mailman.irtf.org/mailman/listinfo/cfrg">https://eur02.safelinks.prote \
ction.outlook.com/?url=https%3A%2F%2Fmailman.irtf.org%2Fmailman%2Flistinfo%2Fcfrg&amp; \
data=05%7C02%7Cjohn.mattsson%40ericsson.com%7Cbb03fcc1644148aee00108dc45c4b5cc%7C92e84 \
cebfbfd47abbe52080c6b87953f%7C0%7C0%7C638461958362740362%7CUnknown%7CTWFpbGZsb3d8eyJWI \
joiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=H \
v88eE2P%2Fbx8PDija6soUYgE%2Ft50POn2Oe3r3DzFpXA%3D&amp;reserved=0</a></span><o:p></o:p></p>
 </div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>



_______________________________________________
CFRG mailing list
CFRG@irtf.org
https://mailman.irtf.org/mailman/listinfo/cfrg

--===============2088568370792243120==--


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic