3 ms·
HPKE has many modes but essentially you don't encrypt a symmetric key with a public key, you combine a public and a private key to derive a symmetric key instea
by ThePhysicist 2y ago
HPKE has many modes but essentially you don't encrypt a symmetric key with a public key, you combine a public and a private key to derive a symmetric key instead. There's more to it like mixing in a secret or another key to authenticate the encryption implicitly at the same time (vs. explicitly using a signing key to e.g. sign a hash). Not a deep expert but in my understanding HPKE codifies existing approaches that are e.g. pioneered by Signal and others before them into an RFC so they become interoperable, which is also the goal with the MLS (message layer security) that is also relying on HPKE (but where efficient key agreement/rotation for groups of people is the main challenge in my understanding, so it focuses more on tree-based approaches for key derivation).