On Tue, Jun 24, 2025 at 2:07 AM Hannes Tschofenig <Hannes.Tschofenig=
[email protected]> wrote:

> Hi all,
>
> the JOSE and COSE chairs have issued a working group last call on the two
> HPKE drafts. Most of the content has been aligned, as far as the structural
> differences between COSE and JOSE allow.
>
> However, there are some noteworthy differences between the two drafts:
>
> - The COSE-HPKE draft introduces a new CBOR structure called
> Recipient_structure, which is passed into the Additional Authenticated Data
> (AAD) field of the HPKE invocation. This structure contains the protected
> headers from the COSE_recipient (if present) as well as fixed fields, such
> as the algorithm used in the next layer.
>
> - The JOSE-HPKE draft does not define an equivalent structure. It
> basically leaves it up to a profile of the draft (or to the developer) to
> define the inforrmation it wants to incorporate.
>
> Both drafts support the inclusion of mutually known private information
> via the info field in HPKE. Additionally, each draft offers different
> extension points for passing additional data into the AAD and info fields.
>

As mentioned in the PR on the JOSE-HPKE
<https://github.com/ietf-wg-jose/draft-ietf-jose-hpke-encrypt/pull/41>
draft, I don't think the way "mutually known private information" is used
is accurate or helpful to consumers of the document. I suspect that
similarly applies for the COSE-HPKE draft.



>
> I believe further alignment between the two documents would be beneficial.
>

Does sending this only to the COSE list imply that you think alignment
should come in the form of COSE moving towards JOSE? Or am I reading too
much into that?

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._
_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to