Hi Dmytro,

- Section IV Header Parameter
It is not clear how to specify the nonce (N).

- Ascon Hash
Truncated size e.g. 64 could also be useful, like SHA-256/64

- KDF with Ascon-Hash

I am sure this is the right way to follow. 1) not standardized anyway, 2) it is 
better to use Ascon-CXOF / Ascon-XOF which is designed for KDF.

Lijun

From: Dmytro OCHKAS <[email protected]>
Date: Monday, 27. July 2026 at 18:08
To: cose <[email protected]>
Subject: [COSE] Follow up on Ascon-AEAD128 and Ascon-Hash256 for COSE

CAUTION! External Email. Do not click links or open attachments unless you 
recognize the sender and know the content is safe.

Dear COSE WG,

This is the follow up mail of my presentation on Ascon-AEAD128 and 
Ascon-Hash256 for COSE.
We appreciate a lot all the feedback given during the WG meeting.

To summarize, I will introduce the main highlights of the presentation:
1. NIST SP 800-232 is already out, standardizing Ascon-AEAD128 and 
Ascon-Hash256, so the main blocker of this draft is gone.
2. Ascon-AEAD128 is proposed for COSE encryption in 3 variations: with a 
16-byte tag, an 8-byte tag, and a 4-byte tag.
3. Ascon-Hash256 is proposed for COSE Key Derivation and COSE MAC.
4. During the hackathon, we were working on Implementing Ascon Lightweight 
Cryptographic Suite over COSE.
   Please refer to the related Pull Requests below. If any of you are 
contributors to these repos, feel free to review the PRs and give us your 
feedback. We'll appreciate it a lot.
   libcose -- 
https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fbergzand%2Flibcose%2Fpull%2F132&data=05%7C02%7Clijun.liao%40nio.io%7Ceb8542e85e86429bffdc08deebf93877%7Cea1b2f97423f4ab3bf6d45a36c09ce34%7C1%7C0%7C639207652857001735%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=WOF%2BKGWrAebSGc70DQXxTAPJPYi%2Fi0NESkdYc6q%2F%2BMk%3D&reserved=0<https://github.com/bergzand/libcose/pull/132>
   COSE-C -- 
https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fcose-wg%2FCOSE-C%2Fpull%2F142&data=05%7C02%7Clijun.liao%40nio.io%7Ceb8542e85e86429bffdc08deebf93877%7Cea1b2f97423f4ab3bf6d45a36c09ce34%7C1%7C0%7C639207652857058670%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rMlZG6%2B%2BfTk7B4YGR9KNmQla967I4PonzrSvsBHIWE0%3D&reserved=0<https://github.com/cose-wg/COSE-C/pull/142>
   uoscore-uedhoc (only as a fork for now) -- 
https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fdmochkas%2Fuoscore-uedhoc&data=05%7C02%7Clijun.liao%40nio.io%7Ceb8542e85e86429bffdc08deebf93877%7Cea1b2f97423f4ab3bf6d45a36c09ce34%7C1%7C0%7C639207652857094051%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=TCIMSoD3KkWAVwAGFyKR0TStjp79hRw5%2FGW3I4%2BDx9E%3D&reserved=0<https://github.com/dmochkas/uoscore-uedhoc>
5. If you would like to see Ascon with COSE in any other language than C (Rust, 
Java, Python, ...), please let me know. I will be excited to work together on 
this project.

Also, we propose the following roadmap for the full Ascon integration in COSE. 
Please don't hesitate to give feedback on it.

Status | New Algorithm
  +      Ascon-AEAD128 for COSE encryption (35)
  +      Ascon-AEAD128-64 for COSE encryption (36)
  +      Ascon-AEAD128-32 for COSE encryption (37)
  +      HMAC Ascon-Hash256 for COSE MAC (8)
  +      HMAC Ascon-Hash256/64 for COSE MAC (9)
  +      HKDF Ascon-Hash256 for Key Derivation
  +      direct+HKDF-Ascon-Hash256 (-20)
  -      ECDH-ES+HKDF-Ascon-Hash256
  -      ECDH-SS+HKDF-Ascon-Hash256
  -      Ascon-Hash256 (RFC 9054)


Finally, to keep the draft moving, we would require 2-3 reviews of the draft.
Many thanks to the people who volunteered to do that during the meeting.
As long as the reviews are done, we will address the comments right after.

Please refer to the draft for more details: 
https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ochkas-cose-ascon%2F&data=05%7C02%7Clijun.liao%40nio.io%7Ceb8542e85e86429bffdc08deebf93877%7Cea1b2f97423f4ab3bf6d45a36c09ce34%7C1%7C0%7C639207652857120268%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=PgSMasvjOgKYTZpfq4socqYVyLFNY9ZvCjoLgYZ1qkM%3D&reserved=0<https://datatracker.ietf.org/doc/draft-ochkas-cose-ascon/>

Thanks in advance for making this project come true.

Best regards,
Dmytro

_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]
[Banner]<http://www.nio.io/>
This email and any files transmitted with it are confidential and intended 
solely for the use of the individual or entity to whom they are addressed. You 
may NOT use, disclose, copy or disseminate this information. If you have 
received this email in error, please notify the sender and destroy all copies 
of the original message and all attachments. Please note that any views or 
opinions presented in this email are solely those of the author and do not 
necessarily represent those of the company. Finally, the recipient should check 
this email and any attachments for the presence of viruses. The company accepts 
no liability for any damage caused by any virus transmitted by this email.
_______________________________________________
COSE mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to