Hi John!
thank you for your email. The most important statement is that you
believe the COSE HPKE draft is ready for WGLC. It is also good to hear
that you believe draft-ietf-jose-pqc-kem is important for your work.
Good that there is a draft ready for you.
Additionally, you raised several questions, which I do not believe we
necessarily need to discuss since they are ultimately the decision of
the LAKE group.
Ciao
Hannes
Am 06.03.2026 um 17:33 schrieb John Mattsson:
Adding COSE, LAKE
LAKE WG is counting on draft-ietf-jose-pqc-kem, It is referenced by
several drafts, and has been discussed several times.
draft-ietf-cose-hpke is not suitable for LAKE and many other
constrained uses of COSE.
When I reviewed it last year it looked very much ready for WGLC. I
would suggest to start WGLC.
Cheers,
John PreuĂ Mattsson
*From: *Aritra Banerjee (Nokia) <[email protected]>
*Date: *Wednesday, 11 February 2026 at 18:20
*To: *[email protected] <[email protected]>
*Subject: *[jose] Re: Proposal: Use HPKE for JWE PQ/PQT straight away
Hello,
The draft-ietf-jose-pqc-kem establishes a clear, HPKE-independent
pathway for systems aiming to transition to PQC-only Key Encapsulation
Mechanisms (KEMs). It does not depend on the new modes defined in
draft-ietf-jose-hpke-encrypt. Instead, draft-ietf-jose-pqc-kem mirrors
the original JWE ECDH-style key agreement model, making it the natural
post-quantum analogue of ECDH-ES.
While HPKE-based JOSE provides valuable capabilities, particularly for
PQ/T use cases, deployments seeking a PQC-only key establishment
mechanism should not be required to rely on the new modes introduced
in jose-hpke. This draft supports a minimal-change transition to
PQC-only KEMs while remaining aligned with the existing JWE model,
enabling a straightforward and consistent migration path.
Best,
Aritra.
_______________________________________________
jose mailing list [email protected]
To unsubscribe send an email [email protected]
_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]