Hi John,
I'd be curious to have you elaborate on the reasons behind your statement:
> draft-ietf-cose-hpke is not suitable for LAKE and many other constrained uses
> of COSE.
Is your assessment due to properties of HPKE itself or the way that COSE uses
it?
Curiously,
-- Mike
From: John Mattsson <[email protected]>
Sent: Friday, March 6, 2026 8:34 AM
To: Aritra Banerjee (Nokia) <[email protected]>; [email protected]; cose
<[email protected]>; lake <[email protected]>
Subject: [Lake] COSE and LAKE needs draft-ietf-jose-pqc-ke (was Proposal: Use
HPKE for JWE PQ/PQT straight away)
Adding COSE, LAKE
LAKE WG is counting on draft-ietf-jose-pqc-kem, It is referenced by several
drafts, and has been discussed several times.
draft-ietf-cose-hpke is not suitable for LAKE and many other constrained uses
of COSE.
When I reviewed it last year it looked very much ready for WGLC. I would
suggest to start WGLC.
Cheers,
John Preuß Mattsson
From: Aritra Banerjee (Nokia)
<[email protected]<mailto:[email protected]>>
Date: Wednesday, 11 February 2026 at 18:20
To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: [jose] Re: Proposal: Use HPKE for JWE PQ/PQT straight away
Hello,
The draft-ietf-jose-pqc-kem establishes a clear, HPKE-independent pathway for
systems aiming to transition to PQC-only Key Encapsulation Mechanisms (KEMs).
It does not depend on the new modes defined in draft-ietf-jose-hpke-encrypt.
Instead, draft-ietf-jose-pqc-kem mirrors the original JWE ECDH-style key
agreement model, making it the natural post-quantum analogue of ECDH-ES.
While HPKE-based JOSE provides valuable capabilities, particularly for PQ/T use
cases, deployments seeking a PQC-only key establishment mechanism should not be
required to rely on the new modes introduced in jose-hpke. This draft supports
a minimal-change transition to PQC-only KEMs while remaining aligned with the
existing JWE model, enabling a straightforward and consistent migration path.
Best,
Aritra.
_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]