Hello,

Thank you to the authors and working group for the continued work on
draft-ietf-jose-hpke-encrypt.

I would like to offer several implementation-focused observations from the
perspective of operational governance, long-term evidence preservation, and
cross-stack interoperability between JOSE-, COSE-, and
transparency-oriented systems.

1. Explicit guidance on authenticated metadata traceability

The draft correctly focuses on cryptographic confidentiality and integrity,
but implementers operating transparency or audit systems may benefit from
clearer guidance regarding:

• which metadata is expected to remain externally observable,

•which fields are integrity protected,

• and which fields may safely participate in external evidence or
transparency logs.

In practice, many deployments will combine:

• JWE/HPKE,

• SCITT-style transparency receipts,

• WORM archival systems,

• and externally verifiable audit traces.

A short operational considerations subsection describing “safe-to-log” vs
“sensitive” metadata classes could reduce implementation ambiguity.

2. Interoperability considerations between JOSE HPKE and COSE HPKE

As parallel JOSE and COSE HPKE efforts mature, implementation divergence
risk may emerge around:

• algorithm identifier handling,

• recipient structure interpretation,

• key lifecycle semantics,

• and canonicalization expectations.

A non-normative interoperability appendix or implementation note
referencing alignment expectations between the JOSE and COSE ecosystems may
help prevent avoidable fragmentation for dual-stack implementers.

3. Evidence preservation and future cryptographic migration

Because HPKE deployments may persist encrypted artifacts for extended
periods, it may be useful to acknowledge:

• long-term cryptographic agility expectations,

• future PQC migration considerations,

• and preservation of sufficient algorithm/context metadata for future
validation or reprocessing.

This is particularly relevant for archival, governance, regulated
infrastructure, and transparency-oriented deployments.

These comments are intended as implementation-supportive operational
observations rather than objections to advancement.

Thank you again to the authors, reviewers, and working group participants
for the effort involved in advancing the specification.

Best regards,

Garth R.T. Smith
Project Ari / PoT Research
Calgary, Alberta, Canada
_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to