it doesn't matter how you get to the meetecho, as long as you do.

Would like a minute or two if there are others interested in working on ascon with COSE

I have asked to have some time to discuss the possibility of a +CWT, structured suffix, RATs WG EAT has some interest in requesting it's registration

I have some slides for that, Orie.

Shall I upload them?

It's two slides.

yes, please

It's a file name. When (if) it gets published, it will only be called RFC xxxx, and only the datatracker will remember the file name that it once was.

Ivaylo, Orie, new slides proposed. you'll need to use the tools icon to import new documents.

I think they are now available, thank you!

Link to the NIST call for opinions on additional parameter sets for SPHINCS+ (smaller number of lifetime signatures), which this WG might want to have an opinion / liaison statement about.



Regarding the presentation. ECC and RSA do not break with the introduction of quantum computing. They brake if someone builds a very large and very robust quantum computer, A CRQC.

Note that NIST might change the names of the algorithms. That was done with Rijndael and Keccak.

For both Rijndael and Keccak, we knew the names long before those candidates were chosen. I don't think there's an intended name for a post-quantum signature algorithms, especially if there's going to be several of them.

what's wrong with: PQalg0. PGalg1, PQalg2 ??? :-)

RSA II: The Sequel

If we're letting NIST choose the name it's going to be DSA III.

PQDSA 1, 2, and 3

I was making a joke, but DSA actually makes a certain amount of sense

Whatever NIST does, we should obey and use the same names on algorithms and parameters. But that will likely be clear in already in the draft standards.

At RWPQC yesterday Dustin Moody said the names would be something like: MLWE-SIG (Dilithium), NSIS-SIG (Falcon), SHBS-SIG (SPHINCS+)

@John Preu\u00df Mattsson : if you cram everything in a byte string, you are again writing custom coders/decoders, with all the vulnerabilities ensuing.

@Tim I know what RSA did last summer!

Regrding key format for BLS. Shoudn't this be defined by CFRG as was done for Curve25519 and Edwards25519.

Tim Hollebeek

Thanks for offering to review the draft. Appreciated

We are all individuals

I might review the HPKE draft, but I make no promise...

I am also in support of doing draft-ajitomi-cose-cose-key-jwk-hpke-kem in the COSE group

I read the draft

I have read it

I read it

I have read the draft

I read TSA-TST

I have read the document, and I support adoption

I read it

I have read the doc and support adoption

Happy to read draft-steele-cose-merkle-tree-proofs-00

Happy to read draft-steele-cose-merkle-tree-proofs-01 :-)

May want to see is SATP WG can use this too

Happy to read draft-stleele-cose-merkle-tree-proofs-01 :)

There is a relationship to typ, I asked the list about this... COSE doesn't have typ or +jwt which are related to media types

", "time": "2023-03-27T05:53:17Z"}, {"author": "Carsten Bormann", "text": "

", "time": "2023-03-27T06:00:46Z"}]