Skip to content

Conversation

@sander
Copy link
Contributor

@sander sander commented Jan 20, 2025

I have not fully checked the details yet, but suspect that the ARKG spec can be simplified by referring to the KEM from RFC 9180.

It removes the ability to provide a context string, but I don’t think that is a problem, since the output from KEM-Encap is ephemeral and therefore bound to the application context anyway.

Referring to DHKEM specifically does add "HPKE-v1" to the HKDF input keying material, which is awkward. But there seem to be already precedents of Internet-Drafts and RFCs reusing the DHKEM outside of the context of HPKE.

Probably the section “Using ECDH as the KEM” can be removed as well, if we find a predefined KEM for secp256k1.

@sander sander requested review from emlun and ve7jtb as code owners January 20, 2025 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant