On Fri, Jul 21, 2023 at 12:41:50AM +0900, AJITOMI Daisuke wrote: > > > ... why would we go out of our way to add extra information to this > > process, when we are supposed to be trying to design for a compact / > > constrained environment? > > > ... The current draft(or "hkc" approach) does not prohibit implementing > only a specific combination of KEM/KDF/AEAD for constrained environments, > and it is also possible not to put HPKE algorithm information in > COSE_Key/JWK as an implicit agreement between a sender and a recipient.
To be clear, constrained applications are _expected_ to profile down and only implement one or a few HPKE ciphersuites. And this has to happen even with ciphersuites, because the some applications require 17-2-2 (or its compact counterpart) as the only supported ciphersuite, but very constrained applications can't implement either of those. -Ilari _______________________________________________ COSE mailing list [email protected] https://www.ietf.org/mailman/listinfo/cose
