On Tue, Aug 20, 2024 at 01:48:41PM -0500, Orie Steele wrote:
> 
> 
> Current ML-DSA proposal:
> 
> https://datatracker.ietf.org/doc/html/draft-ietf-cose-dilithium-03#name-the-ml-dsa-algorithm-family

As note, there is potential for some confusion in "ML-DSA Algorithm
Family".

JWK refers to "cryptographic algorithm family", but the meaning is
rather different, being defined by kind of key used rather than any
algorithmic similarity. ML-DSA belongs to much larger "cryptographic
algorithm family", which includes things like SLH-DSA and FALCON. It
would also include suitably defined pre-quantum algorithms.


> I was hoping we might send the document to WGLC, and make some final
> adjustments to test vectors, as soon as a good non -ipd version emerges
> that I can use to generate examples.

You mean implementation, right?

And one does not need to care about performance (unless it is something
ridiculous) or side channel attacks in suff like this...




-Ilari

_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to