Document: draft-ietf-ipsecme-ikev2-pqc-auth
Title: Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)
using PQC
Reviewer: Tony Li
Review result: Has Nits
OPSDIR Last Call Review of draft-ietf-ipsecme-ikev2-pqc-auth
Reviewer: Tony Li
Disclaimer: I don't do security. My crypto skills ended with Caesar
ciphers. I have no expertise in IKE. This is purely an operational review.
Overall: Ready, with nits
Substantive:
Section 3.2:
Please add a reference for side-channel attacks and how they might
apply to deterministic mode. While I don't feel you need to write a
tutorial on this, a reference to follow would be most helpful.
Editorial:
Section 1:
OLD
...
[FIPS205] can be employed as authentication methods within
IKEv2, as they have been standardized the US National
Institute of Standards and Technology (NIST) PQC project.
NEW
...
[FIPS205] can be employed as authentication methods within
IKEv2, as they have been standardized by the US National
Institute of Standards and Technology (NIST) PQC project.
Section 3.1:
OLD
IKEv2 can use arbitrary signature algorithms as described in
Signature Authentication in IKEv2 [RFC7427], where the
"Digital Signature" authentication method supersedes
previously defined signature authentication methods. Any PQC
digital signature algorithm can be incorporated using the
"Digital Signature" authentication method, as defined in
[RFC7427].
These two sentences seem highly redundant. If there is some nuance
here, it needs clarification.
OLD
DER encoded AlgorithmIdentifier ASN.1 objects will be used to
uniquely identify PQC signature algorithm scheme and the
parameter set associated with it.
NEW
DER encoded AlgorithmIdentifier ASN.1 objects will be used to
uniquely identify the PQC signature algorithm scheme and the
parameter set associated with it.
Please expand the acronym DER.
Section 3.2.1:
OLD
...
(value 5) is defined in Section 2 of using EdDSA in IKEv2
[RFC8420]
...
NEW
...
(value 5) is defined in Section 2 of "Using the Edwards-Curve
Digital Signature Algorithm (EdDSA) in the Internet Key
Exchange Protocol Version 2 (IKEv2)" [RFC8420]
...
Please use an explicit complete title in the reference, otherwise it
does not parse.
OLD
...
SIGNATURE_HASH_ALGORITHMS notify. Furthermore, PQC signature
...
NEW
...
SIGNATURE_HASH_ALGORITHMS notification. Furthermore, PQC signature
...
OR
...
SIGNATURE_HASH_ALGORITHMS Notify payload. Furthermore, PQC signature
...
Please capitalize Notify when you are referring to a Notify payload,
throughout the document.
Section 3.3:
OLD
Authentication Method Announcement: Using Announcing Supported
Authentication Method in IKEv2 [RFC9593], which enables peers
to declare their supported authentication methods.
NEW
Authentication Method Announcement: Using "Announcing
Supported Authentication Methods in the Internet Key Exchange
Protocol Version 2 (IKEv2)" [RFC9593], which enables peers
to declare their supported authentication methods.
Quoting the title is necessary for the sentence to parse. Please
quote accurate titles throughout the document.
OLD
This improves interoperability when IKEv2 peers are configured
with multiple credential types of different type to
authenticate each other.
NEW
This improves authentication interoperability when IKEv2 peers
are configured with multiple credential types.
OLD
However, cryptographic agility, the ability to negotiate and
use different cryptographic algorithms is gaining increased
attention for ensuring long-term security and
interoperability.
NEW
However, cryptographic agility, the ability to negotiate and
use different cryptographic algorithms, is gaining increased
attention for ensuring long-term security and
interoperability.
Section 4:
OLD
...
hardness lattice problems over module lattices (i.e., the
Module Learning with Errors problem ((commonly referred to as
MLWE)).
NEW
...
hardness lattice problems over module lattices (i.e., the
Module Learning with Errors problem (commonly referred to as
MLWE)).
Section 6:
OLD
Both ML-DSA and SLH-DSA offer deterministic and hedged signing
modes, where the hedged signing modes includes fresh
randomness in the
NEW
Both ML-DSA and SLH-DSA offer deterministic and hedged signing
modes, where the hedged signing modes include fresh
randomness in the
_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]