Hi John,

I'd be curious to have you elaborate on the reasons behind your statement:
> draft-ietf-cose-hpke is not suitable for LAKE and many other constrained uses 
> of COSE.

Is your assessment due to properties of HPKE itself or the way that COSE uses 
it?

                                                       Curiously,
                                                       -- Mike

From: John Mattsson <[email protected]>
Sent: Friday, March 6, 2026 8:34 AM
To: Aritra Banerjee (Nokia) <[email protected]>; [email protected]; cose 
<[email protected]>; lake <[email protected]>
Subject: [Lake] COSE and LAKE needs draft-ietf-jose-pqc-ke (was Proposal: Use 
HPKE for JWE PQ/PQT straight away)

Adding COSE, LAKE

LAKE WG is counting on draft-ietf-jose-pqc-kem, It is referenced by several 
drafts, and has been discussed several times.

draft-ietf-cose-hpke is not suitable for LAKE and many other constrained uses 
of COSE.

When I reviewed it last year it looked very much ready for WGLC. I would 
suggest to start WGLC.

Cheers,
John Preuß Mattsson

From: Aritra Banerjee (Nokia) 
<[email protected]<mailto:[email protected]>>
Date: Wednesday, 11 February 2026 at 18:20
To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: [jose] Re: Proposal: Use HPKE for JWE PQ/PQT straight away
Hello,

The draft-ietf-jose-pqc-kem establishes a clear, HPKE-independent pathway for 
systems aiming to transition to PQC-only Key Encapsulation Mechanisms (KEMs). 
It does not depend on the new modes defined in draft-ietf-jose-hpke-encrypt. 
Instead, draft-ietf-jose-pqc-kem mirrors the original JWE ECDH-style key 
agreement model, making it the natural post-quantum analogue of ECDH-ES.

While HPKE-based JOSE provides valuable capabilities, particularly for PQ/T use 
cases, deployments seeking a PQC-only key establishment mechanism should not be 
required to rely on the new modes introduced in jose-hpke. This draft supports 
a minimal-change transition to PQC-only KEMs while remaining aligned with the 
existing JWE model, enabling a straightforward and consistent migration path.

Best,
Aritra.
_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to