[{"author": "John Gray", "text": "<p>Hello!  Good morning (or evening where I am)!  :)</p>", "time": "2026-03-17T01:01:56.000Z"}, {"author": "Lucas Prabel", "text": "<p>Good morning! <span aria-label=\"smiley\" class=\"emoji emoji-1f603\" role=\"img\" title=\"smiley\">:smiley:</span></p>", "time": "2026-03-17T01:02:43.000Z"}, {"author": "Tirumaleswar Reddy.K", "text": "<p>Good morning</p>", "time": "2026-03-17T01:02:51.000Z"}, {"author": "Deb Cooley", "text": "<p>nice, TY</p>", "time": "2026-03-17T01:02:56.000Z"}, {"author": "Michael P", "text": "<p>Hi everyone, <br>\nApologies that I'm remote for my first meeting. <br>\nLooking forward to supporting the WG</p>", "time": "2026-03-17T01:03:46.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Thanks for moving the COSE HPKE draft forward</p>", "time": "2026-03-17T01:06:03.000Z"}, {"author": "Deb Cooley", "text": "<p>JOSE HPKE draft?</p>", "time": "2026-03-17T01:06:38.000Z"}, {"author": "Peter Yee", "text": "<p>Can't hear him well. Mic on?</p>", "time": "2026-03-17T01:07:41.000Z"}, {"author": "David Waite", "text": "<p>can only barely hear him</p>", "time": "2026-03-17T01:07:45.000Z"}, {"author": "Emil Lundberg", "text": "<p>online can't hear Mike</p>", "time": "2026-03-17T01:07:45.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>We were talking about the JOSE HPKE draft?</p>", "time": "2026-03-17T01:07:46.000Z"}, {"author": "Emil Lundberg", "text": "<p>better now</p>", "time": "2026-03-17T01:07:50.000Z"}, {"author": "David Waite", "text": "<p><span aria-label=\"+1\" class=\"emoji emoji-1f44d\" role=\"img\" title=\"+1\">:+1:</span></p>", "time": "2026-03-17T01:07:50.000Z"}, {"author": "Michael P", "text": "<p>That's better</p>", "time": "2026-03-17T01:07:52.000Z"}, {"author": "Tirumaleswar Reddy.K", "text": "<p>much better now.</p>", "time": "2026-03-17T01:07:57.000Z"}, {"author": "Peter Yee", "text": "<p>Now Mike is on. :D</p>", "time": "2026-03-17T01:07:59.000Z"}, {"author": "Carsten Bormann", "text": "<p>meetecho: speaker please</p>", "time": "2026-03-17T01:08:06.000Z"}, {"author": "David Waite", "text": "<p><span aria-label=\"ocean\" class=\"emoji emoji-1f30a\" role=\"img\" title=\"ocean\">:ocean:</span></p>", "time": "2026-03-17T01:08:12.000Z"}, {"author": "David Waite", "text": "<p>Christian Bormann with SPRIND had similar feedback</p>", "time": "2026-03-17T01:12:31.000Z"}, {"author": "Emil Lundberg", "text": "<p>I have read earlier versions, as Mike mentioned</p>", "time": "2026-03-17T01:16:43.000Z"}, {"author": "Carsten Bormann", "text": "<p>Something is blowing into Tiru's microphone</p>", "time": "2026-03-17T01:22:33.000Z"}, {"author": "Nathanael Ritz", "text": "<p>Sounds like he is outside</p>", "time": "2026-03-17T01:23:11.000Z"}, {"author": "Dennis Jackson", "text": "<p>Hannes, what is the positive use case over the HPKE approach?</p>", "time": "2026-03-17T01:36:04.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>John gave the answer on the microphone a few minutes ago</p>", "time": "2026-03-17T01:37:39.000Z"}, {"author": "Deb Cooley", "text": "<p>But that is cose only?</p>", "time": "2026-03-17T01:37:55.000Z"}, {"author": "Brian Campbell", "text": "<p>COSE should maybe figure that out?</p>", "time": "2026-03-17T01:38:20.000Z"}, {"author": "John Gray", "text": "<p>But HPKE is more complicated to implement... this is more straight forward, so I would choose this one...</p>", "time": "2026-03-17T01:38:54.000Z"}, {"author": "Brian Campbell", "text": "<p>which, again, questions why the are unnatural bound together</p>", "time": "2026-03-17T01:39:27.000Z"}, {"author": "Brian Campbell", "text": "<p>unnaturally*</p>", "time": "2026-03-17T01:40:02.000Z"}, {"author": "Yaroslav Rosomakho", "text": "<p>The problem being is that one will not know upfront which one will the peer support. So both will be mandatory to implement to maximise compatibility</p>", "time": "2026-03-17T01:40:11.000Z"}, {"author": "Yaroslav Rosomakho", "text": "<p>Also HPKE typically comes from ready-made HPKE libraries, so I am not sure if HPKE implementation complexity argument really applies....</p>", "time": "2026-03-17T01:41:12.000Z"}, {"author": "Dennis Jackson", "text": "<p>There's pure and hybrid PQ modes for HPKE</p>", "time": "2026-03-17T01:41:50.000Z"}, {"author": "Dennis Jackson", "text": "<p><a href=\"https://datatracker.ietf.org/doc/draft-ietf-hpke-pq/\">https://datatracker.ietf.org/doc/draft-ietf-hpke-pq/</a></p>", "time": "2026-03-17T01:42:00.000Z"}, {"author": "Ben S", "text": "<p>draft-ietf-hpke-pq-04 does request pure ML-KEM codepoints</p>", "time": "2026-03-17T01:42:03.000Z"}, {"author": "Jonathan Hammell", "text": "<p>The IANA registry is Specification Required.  The JOSE Implementation Requirements column is intended to give guidance to implementors what is recommended for general applications. As Tiru noted, there are some customers that may want this, and this draft proposes registering them as Optional under this column.</p>", "time": "2026-03-17T01:42:15.000Z"}, {"author": "Yaroslav Rosomakho", "text": "<p>Non-hybrid ML-KEM codepoints for HPKE has been around for more than a year. There are implementations such as <a href=\"https://www.npmjs.com/package/@hpke/ml-kem\">https://www.npmjs.com/package/@hpke/ml-kem</a></p>", "time": "2026-03-17T01:43:53.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Initially, HPKE did not support PQC algorithm. This was then added at a later stage.</p>", "time": "2026-03-17T01:44:21.000Z"}, {"author": "Dennis Jackson", "text": "<p>John: Can you clarify the complexity of HPKE? Having a bespoke mode for JOSE, rather than a standard approach used by many other WGs, seems more complex</p>", "time": "2026-03-17T01:45:44.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>John is focused on the COSE version for the constrained IoT use case.</p>", "time": "2026-03-17T01:46:44.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>LAKE needs KEM algorithm registrations in COSE, not JOSE.</p>", "time": "2026-03-17T01:47:08.000Z"}, {"author": "Ben S", "text": "<p>More from Deb's cat please!</p>", "time": "2026-03-17T01:47:49.000Z"}, {"author": "Hannes Tschofenig", "text": "<p><span aria-label=\"kitten\" class=\"emoji emoji-1f431\" role=\"img\" title=\"kitten\">:kitten:</span></p>", "time": "2026-03-17T01:47:51.000Z"}, {"author": "Deb Cooley", "text": "<p>He doesn't normally hop on the desk....  usually people just see his tail.</p>", "time": "2026-03-17T01:49:24.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>He wanted to join the JOSE working group discussion</p>", "time": "2026-03-17T01:49:51.000Z"}, {"author": "Deb Cooley", "text": "<p>@meetecho - speaker please</p>", "time": "2026-03-17T01:49:59.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>There is no linkage between this document and the previous discussion. Just for the record</p>", "time": "2026-03-17T01:59:51.000Z"}, {"author": "John Gray", "text": "<p>In regards to the composite signature algorithms, we spent 6 years debating algorithm combinations, and 4 years for composite KEM... Every time we tried to remove algorithms someone came along saying they needed that combination.. So in the end, we ended up with 18 composites signatures and 12 composite KEM... So if you are happy with a small subset, I applaud you!</p>", "time": "2026-03-17T02:06:36.000Z"}, {"author": "Dennis Jackson", "text": "<p>Profiling as narrowly as possible seems like a win.</p>", "time": "2026-03-17T02:15:30.000Z"}, {"author": "Dennis Jackson", "text": "<p>John: SHAKE256 is from the SHA-3 family</p>", "time": "2026-03-17T02:15:57.000Z"}, {"author": "John Gray", "text": "<p>Yes choices makes less work, even in the AI era!  Using less tokens for your implementation is always good right?</p>", "time": "2026-03-17T02:16:49.000Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention silent\" data-user-id=\"2103\">Dennis Jackson</span> <a href=\"#narrow/channel/358-jose/topic/ietf-125/near/206534\">said</a>:</p>\n<blockquote>\n<p>John: SHAKE256 is from the SHA-3 family</p>\n</blockquote>\n<p>Sure, but SHAKE256 is not SHA3-256. My concern is that from a crypto library perspective, this introduces a different incompatible variant of the MLKEM768+X25519 primitive.</p>", "time": "2026-03-17T02:16:54.000Z"}, {"author": "Mike Ounsworth", "text": "<p>But I'm not 100% sure from the slides... let me take a quick look at the details.</p>", "time": "2026-03-17T02:17:26.000Z"}, {"author": "Dennis Jackson", "text": "<p>I thought HPKE used SHAKE256 already?</p>", "time": "2026-03-17T02:18:14.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Yes</p>", "time": "2026-03-17T02:18:21.000Z"}, {"author": "Mike Ounsworth", "text": "<p>... looking</p>", "time": "2026-03-17T02:18:26.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>... looking as well to be 100% sure</p>", "time": "2026-03-17T02:19:22.000Z"}, {"author": "John Gray", "text": "<p>Dennis:  SHAKE256 isn't the same as SHA3 (they produce different output, even if same output length is chosen)..  But yes, their construction is almost the same...</p>", "time": "2026-03-17T02:19:36.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>ML-KEM does use SHAKE256.</p>", "time": "2026-03-17T02:19:57.000Z"}, {"author": "Filip Skokan", "text": "<p>(Turbo)SHAKE128/256 are available single-stage KDFs in HPKE</p>\n<p>aside of those 4 it's the three levels of HKDF(SHA-2)</p>", "time": "2026-03-17T02:20:22.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>See SHAKE256 in <a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-hpke-pq-04\">https://datatracker.ietf.org/doc/html/draft-ietf-hpke-pq-04</a></p>", "time": "2026-03-17T02:20:57.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>For simplicity I think drop ChaCha and only use AES-256-GCM and SHAKE256.</p>\n<p>(Add ChaCha later if it is added as an content encryption algorithm )</p>", "time": "2026-03-17T02:21:03.000Z"}, {"author": "Dennis Jackson", "text": "<p><span class=\"user-mention silent\" data-user-id=\"290\">John Gray</span> <a href=\"#narrow/channel/358-jose/topic/ietf-125/near/206576\">said</a>:</p>\n<blockquote>\n<p>Dennis:  SHAKE256 isn't the same as SHA3 (they produce different output, even if same output length is chosen)..  But yes, their construction is almost the same...</p>\n</blockquote>\n<p>Yes, hence I said same family and not the same :-)</p>", "time": "2026-03-17T02:21:03.000Z"}, {"author": "John Gray", "text": "<p>Composite KEM uses SHA3 for the KEM Combiner KDF...   Perhaps the KDF mentioned on the slide is used differently in HPKE...  I have to look as well... :)</p>", "time": "2026-03-17T02:21:24.000Z"}, {"author": "John Gray", "text": "<p>Dennis...   Yes, they are close siblings...  <span aria-label=\"smile\" class=\"emoji emoji-1f604\" role=\"img\" title=\"smile\">:smile:</span></p>", "time": "2026-03-17T02:22:04.000Z"}, {"author": "Mike Ounsworth", "text": "<p>Ok: definitive answer on the SHA3 vs SHAKE256 thing:<br>\ndraft-ietf-hpke-pq-04 Section 5 says to use SHAKE or TurboSHAKE for the \"Single-Stage HPKE KDF\".<br>\nHOWEVER, Section 4 says that the definition of \"MLKEM768-P256\", \"MLKEM768-X25519\", and \"MLKEM1024-P384\" chains to draft-irtf-cfrg-concrete-hybrid-kems-02, which makes it clear that the _internal_ KDF within the hybrid KEM combiner is SHA3-256.</p>\n<p>So the answer is _both_ SHA3-256 (as the hybrid KEM combiner KDF), _and_ SHAKE256 (as the external KDF at the HPKE layer). That's good. That's how I expected it to be.</p>\n<p>Does that match other people's understanding?</p>", "time": "2026-03-17T02:27:12.000Z"}, {"author": "Jonathan Hammell", "text": "<p>Yes, that was my understanding, too.</p>", "time": "2026-03-17T02:28:12.000Z"}, {"author": "John Gray", "text": "<p>Mike, that makes sense... I figured it was probably two different layers of KDF happening!   Thanks for confirming!</p>", "time": "2026-03-17T02:29:16.000Z"}, {"author": "Dennis Jackson", "text": "<p>Is there a compelling reason to tackle both COSE and JOSE in one draft?</p>", "time": "2026-03-17T02:31:30.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>That was the approach so far in the group.</p>", "time": "2026-03-17T02:32:03.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>See other documents -- ML-DSA, FN-DSA, SLH-DSA</p>", "time": "2026-03-17T02:32:51.000Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention\" data-user-id=\"293\">@Brent Zundel</span> I APOLOGIZE PROFUSELY FOR THE EXPLOSION OF ALGORITHM COMBINATIONS!!!</p>", "time": "2026-03-17T02:36:57.000Z"}, {"author": "Filip Skokan", "text": "<p>Tiru can you mute your mic if you're not speaking?</p>", "time": "2026-03-17T02:37:11.000Z"}, {"author": "Dennis Jackson", "text": "<p>+1 to Brent</p>", "time": "2026-03-17T02:37:24.000Z"}, {"author": "Deb Cooley", "text": "<p>wait @mike you are apologizing to him???  and not to me?</p>", "time": "2026-03-17T02:37:26.000Z"}, {"author": "Brian Campbell", "text": "<p>would like to attend but have a conflict in a diff WG</p>", "time": "2026-03-17T02:38:47.000Z"}, {"author": "Brian Campbell", "text": "<p>can you drop a link @Nick?</p>", "time": "2026-03-17T02:39:04.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>Yes, and cfrg-concrete-hybrid-kems internally use both SHAKE256 and SHA3-256</p>\n<p>\"with SHAKE256 as the PRG and SHA3-256 as the KDF.\"</p>\n<p>An acceptable implementation of FIPS 202 supports both.</p>", "time": "2026-03-17T02:40:24.000Z"}, {"author": "Michael P", "text": "<p>Nick's draft is here <a href=\"https://datatracker.ietf.org/doc/draft-sullivan-crypto-publication/\">https://datatracker.ietf.org/doc/draft-sullivan-crypto-publication/</a></p>", "time": "2026-03-17T02:40:37.000Z"}, {"author": "Nick Sullivan", "text": "<p><a href=\"https://www.ietf.org/archive/id/draft-sullivan-crypto-publication-00.html\">https://www.ietf.org/archive/id/draft-sullivan-crypto-publication-00.html</a></p>", "time": "2026-03-17T02:40:46.000Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention\" data-user-id=\"331\">@Deb Cooley</span> -- in my defense, after trying (and failing) for years to <span aria-label=\"scissors\" class=\"emoji emoji-2702\" role=\"img\" title=\"scissors\">:scissors:</span> down the number of options, we did add a </p>\n<blockquote>\n<p>10.3.  Profiling down the number of options</p>\n</blockquote>\n<p>which basically says \"Just use X-wing\", and which just so happens to align to the same 3  as the upstream CFRG draft.</p>\n<p>MLKEM768-P256<br>\nMLKEM768-X25519<br>\nMLKEM1024-P384</p>\n<p><a href=\"https://datatracker.ietf.org/doc/html/draft-ietf-lamps-pq-composite-kem-12#autoid-44\">https://datatracker.ietf.org/doc/html/draft-ietf-lamps-pq-composite-kem-12#autoid-44</a></p>", "time": "2026-03-17T02:40:56.000Z"}, {"author": "Nick Sullivan", "text": "<p>My document is very relevant to this conversation.</p>", "time": "2026-03-17T02:44:35.000Z"}, {"author": "Nick Sullivan", "text": "<p>Every group at the IETF is going to have this same discussion.</p>", "time": "2026-03-17T02:45:23.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Wise words from our AD</p>", "time": "2026-03-17T02:48:11.000Z"}, {"author": "Dennis Jackson", "text": "<p>Well said!</p>", "time": "2026-03-17T02:48:17.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p><span aria-label=\"clap\" class=\"emoji emoji-1f44f\" role=\"img\" title=\"clap\">:clap:</span> to the AD and mom</p>", "time": "2026-03-17T02:48:21.000Z"}, {"author": "Tirumaleswar Reddy.K", "text": "<p>Thanks Deb for giving the direction for the authors.</p>", "time": "2026-03-17T02:49:19.000Z"}]