4 ms·
https://mailarchive.ietf.org/arch/msg/cfrg/3SXM0I9jVs5i38SyahhMF1Q4fBc/ https://mailarchive.ietf.org/arch/msg/cfrg/3SXM0I9jVs5i38Sya... The idea here is to
by ramchip 2y ago
https://mailarchive.ietf.org/arch/msg/cfrg/3SXM0I9jVs5i38SyahhMF1Q4fBc/ https://mailarchive.ietf.org/arch/msg/cfrg/3SXM0I9jVs5i38Sya...
The idea here is to write a clean, easy-to-use spec for hybrid public-key
encryption. (We're using the name "ECIES", but as the draft notes, the
idea is clearly more general.) This primitive has come up in IETF work on
MLS and ESNI [0][1], and in several other protocols, e.g., through the NaCl
"box" API [2]. The hope here is to have a single spec that unifies these
ideas and can be the target of formal verification.
I admit that there's a little bit of XKCD#927 here [3], but I think there's
good work to do here in terms of addressing some more modern use cases
(e.g., streaming / multiple encryptions from a single DH) and possibly
enabling better post-quantum support by generalizing to KEM instead of DH.