Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha256; boundary="B_3735726800_707557647" --B_3735726800_707557647 Content-type: text/plain; charset="UTF-8" Content-transfer-encoding: quoted-printable Dear Yunlei, Thank you for your proposals - they are very interesting. I have a few ques= tions. 1. Are there reference implementations of CTRU, OSKR, and others? Optimized= implementations? 2. Would your proposed algorithms, such as OSKR, still be potential subject= s to the same patent claims that, e.g., Kyber is dealing with? 3. You (University, Company, etc.) have some patents covering CTRU, OSKR, a= nd other algorithms that you proposed. It is nice that your email stated: "= we would like to give up all the patents for using our proposals. We hold t= he patents only for protection." Not being a lawyer, I cannot evaluate whet= her that statement is sufficient from legal point of view. Would the patent= (s) holders be willing to make a more "official" statement to that extent? Please feel free to answer on this mailing list, or privately - as you pref= er. Thank you! --=20 V/R, Uri =20 =EF=BB=BFOn 5/12/22, 12:03, "'=E8=B5=B5=E8=BF=90=E7=A3=8A' via pqc-forum" <= pqc-forum@list.nist.gov> wrote: Dear Prof. Bernstein and dear all in PQC community: Here, we would like to make the patent issues clearer.=20 For all the KEM schemes based on LWE/MLWE/LWR/MLWR, they actually have = the same scheme structures. The key differences can be well interpreted w.r= .t what are referred to as the Con/Rec mechanism in=20 https://arxiv.org/abs/1611.06150 (as well as in our KCL proposal). Ever= y KEM based on LWE/MLWE/LWR/MLWR implies a Con/Rec mechanism. The differenc= e between LWE\MLWE-based KEM and LWR\MLWR-based KEM is that Con/Rec in LWE\= MLWE-based is w.r.t. the modulus $q$, but Con/Rec in LWR\MLWR-based is w.r.= t the compression parameter $p$. The Con/Rec implied by Frodo is just one= previously proposed, but it is not optimal (as a consequence Frodo does no= t violate our patents). To the best of our knowledge, AKCN in https://arxi= v.org/abs/1611.06150 (as well as in our KCL proposal) is the first one that= is proved to be optimal. The Con/Rec mechanisms in Kyber and Saber are als= o optimal in correcting errors, but Rec in Kyber involves an unnecessary ro= unding operation which makes it less efficient and more error-prone (the Co= n of AKCN and that of Kyber are the same). Con/Rec of AKCN-MLWE and Saber a= re essentially the same, but w.r.t. the compression parameter $p$ in Saber.= These differences can be clearly noted from the mentioned two arXiv repo= rts:=20 https://arxiv.org/abs/2109.02893 https://arxiv.org/abs/1611.06150 Finally, we would like to stress again we hold all the patents only for= protection against credit (not for economic reasons). We hope the above cl= arifications could make the situation clearer. All my best Yunlei > -----=E5=8E=9F=E5=A7=8B=E9=82=AE=E4=BB=B6----- > =E5=8F=91=E4=BB=B6=E4=BA=BA: "D. J. Bernstein" > =E5=8F=91=E9=80=81=E6=97=B6=E9=97=B4: 2022-05-12 20:55:14 (=E6=98=9F= =E6=9C=9F=E5=9B=9B) > =E6=94=B6=E4=BB=B6=E4=BA=BA: pqc-forum@list.nist.gov > =E6=8A=84=E9=80=81:=20 > =E4=B8=BB=E9=A2=98: Re: On the possibility of achieving NIST security= goals with the recent advances of dual attacksRe: Re: [pqc-forum] Improved= Dual Lattice Attack >=20 > '=E8=B5=B5=E8=BF=90=E7=A3=8A' via pqc-forum writes: > > The recent advances of dual attacks might bring the worry the > > possibility of achieving the security goals set by NIST for > > lattice-based KEM schemes, particularly on dimension of 512. Our > > recent work shows it may still be possible, but with optimized > > constructions. >=20 > Can you please comment on what's covered by your patents related to t= his > work? I noticed that your patents >=20 > https://patents.google.com/patent/CN107566121A/en > https://patents.google.com/patent/CN108173643B/en >=20 > were reported in the KCL/OKCN/AKCN/CNKE submission, which is very > similar to "NewHope without reconciliation". The patents were filed a > month before "NewHope without reconciliation" was published, and I > haven't seen any analysis of the patent coverage. >=20 > It would be useful to see public assurances as to your company's > position regarding usage of "NewHope without reconciliation" and its > variants, such as Kyber, SABER, and your latest proposals. >=20 > ---D. J. Bernstein >=20 > --=20 > You received this message because you are subscribed to the Google Gr= oups "pqc-forum" group. > To unsubscribe from this group and stop receiving emails from it, sen= d an email to pqc-forum+unsubscribe@list.nist.gov. > To view this discussion on the web visit https://groups.google.com/a/= list.nist.gov/d/msgid/pqc-forum/20220512125514.219585.qmail%40cr.yp.to. --=20 You received this message because you are subscribed to the Google Grou= ps "pqc-forum" group. To unsubscribe from this group and stop receiving emails from it, send = an email to pqc-forum+unsubscribe@list.nist.gov. To view this discussion on the web visit https://groups.google.com/a/li= st.nist.gov/d/msgid/pqc-forum/5a91d094.8ba5.180b902887e.Coremail.ylzhao%40f= udan.edu.cn. --=20 You received this message because you are subscribed to the Google Groups "= pqc-forum" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to pqc-forum+unsubscribe@list.nist.gov. To view this discussion on the web visit https://groups.google.com/a/list.n= ist.gov/d/msgid/pqc-forum/740E846A-A9A9-4CC3-BD7E-8C5FF3DD4F3E%40ll.mit.edu= . --B_3735726800_707557647 Content-Type: application/pkcs7-signature; name="smime.p7s" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="smime.p7s" MIIUfQYJKoZIhvcNAQcCoIIUbjCCFGoCAQExDzANBglghkgBZQMEAgEFADALBgkqhkiG9w0B BwGgghJDMIIE8zCCA9ugAwIBAgITJgAABVq3kr35c1qYVgAAAAAFWjANBgkqhkiG9w0BAQsF ADBRMQswCQYDVQQGEwJVUzEfMB0GA1UECgwWTUlUIExpbmNvbG4gTGFib3JhdG9yeTEMMAoG A1UECwwDUEtJMRMwEQYDVQQDDApNSVRMTCBDQS04MB4XDTIyMDQwNDEzNTM1NVoXDTI3MDQw MzEzNTM1NVowYTELMAkGA1UEBhMCVVMxHzAdBgNVBAoTFk1JVCBMaW5jb2xuIExhYm9yYXRv cnkxDzANBgNVBAsTBlBlb3BsZTEgMB4GA1UEAxMXQmx1bWVudGhhbC5VcmkuNTAwMTA1ODQw ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC9NYdvY08CoRve6q3AKBgfzmsefk5M zgm1mGRyvBE44NBXZx5FGTzX98vLsn9ZditfBfYtn9qOydXWmFh06/mKZlJN0Bg4nRs466vX cyKyiY1PGgRPSl64CMdpuwt2/Mf1/+6fZta3Ffroz4GSx9sqxQYGB8QLCR1wxNbYcCghhfyW YUb7BBmhkVYEGFzWk5nBQh9Npo6U1qh5+8zQvTbXSv14xlWenQ2FUHxKHbVVYkle6WuKjbrz it+HhcIWf+E77iVw4nh2avF2o3J4U2VBWM53aITRTfKepHA6edHrxYmSNajSsu9TbEAqYZW+ Gfohw9ji4Q74UcWpdwAcug65AgMBAAGjggGyMIIBrjAdBgNVHQ4EFgQUwcUrH0niWJCqOR90 PBc5IX0RWYowDgYDVR0PAQH/BAQDAgbAMB8GA1UdIwQYMBaAFAepY/eqZM/S+hvIfQE1id5I FbRrMDMGA1UdHwQsMCowKKAmoCSGImh0dHA6Ly9jcmwubGwubWl0LmVkdS9nZXRjcmwvbGxj YTgwZgYIKwYBBQUHAQEEWjBYMC0GCCsGAQUFBzAChiFodHRwOi8vY3JsLmxsLm1pdC5lZHUv Z2V0dG8vbGxjYTgwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vY3NwLmxsLm1pdC5lZHUvb2NzcDA9 BgkrBgEEAYI3FQcEMDAuBiYrBgEEAYI3FQiDg+Udh+ynZoathxWD6vBFhbahHx2Fy94yh/+K cwIBZAIBCjAiBgNVHSUBAf8EGDAWBggrBgEFBQcDBAYKKwYBBAGCNwoDDDAZBgNVHREEEjAQ gQ51cmlAbGwubWl0LmVkdTAYBgNVHSAEETAPMA0GCyqGSIb3EgIBAwEIMCcGCSsGAQQBgjcU AgQaHhgATABMAFUAcwBlAHIAUwBpAGcALQBTAFcwDQYJKoZIhvcNAQELBQADggEBAJ+zQ365 LelAZV/UiO5ekekrpdjdQJ2pjlicGLhlQ1nBVgk3nLMFfi+MX5MUagzqCxZLXnU4eCbPjrZC MZRrN6/iSGVxEt4zclP82KUbFLxcHTEpglBARmze2eaurPPV5R1qKdVZQDbJE2pt9gyHYKM7 vpXtv+7MalLDzWUVIbeC8bHGr5SOn417R0XANNptDAhI+Y84rXjINWb6Qyc3pCTv2KheGePR ztfOlzJ8yxKwVW8CfqD9GhUr1lBJPu+CMxn7337BlpjRgfOi5FYBsbOPeo+fGosBK+bxDbbK aS5R+4K+irSppZUQL6rbkFs98efVDnNsl/mX7edtERHXnB4wggTAMIIDqKADAgECAgEaMA0G CSqGSIb3DQEBCwUAMFYxCzAJBgNVBAYTAlVTMR8wHQYDVQQKExZNSVQgTGluY29sbiBMYWJv cmF0b3J5MQwwCgYDVQQLEwNQS0kxGDAWBgNVBAMTD01JVExMIFJvb3QgQ0EtMjAeFw0yMTA0 MTQxMTAwMDBaFw0zMjA0MTQxMTAwMDBaMFExCzAJBgNVBAYTAlVTMR8wHQYDVQQKDBZNSVQg TGluY29sbiBMYWJvcmF0b3J5MQwwCgYDVQQLDANQS0kxEzARBgNVBAMMCk1JVExMIENBLTgw ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC20qJRmL57N3pdHf9QGwW079emEfyo 8IvWXtCOr13el7DfD2ZEbn7Xr5Ubg6RJ1uDX8L/0btB/gT5vVQFylFPt0xZDj5zMyPmHMkxf xEvu0y/CArI0a8iDpZwubXU1jSvXSx6wFphXB6s1CuQTro8F9N0WrjHravsI7UYeuemTOEim f0aCGwDF5jlXZn42uSCU1dNpJ9SuyvUOJ3oDoVo4epR9fTbNd3lGKnm+8srrLx4mVhxmlFlg Ow/rDA+5KC/yUNr9z/bzLl6CTUQQbfAgFd52C/6adnxkigAiSGt4Jm9asCnw8ui0wFjZijJZ Uqamh5t9e5pQEHXRtUenj3XDAgMBAAGjggGcMIIBmDASBgNVHRMBAf8ECDAGAQH/AgEAMB0G A1UdDgQWBBQHqWP3qmTP0vobyH0BNYneSBW0azAfBgNVHSMEGDAWgBT/ycllTFOA8akMPCGu girH7vgy+zAOBgNVHQ8BAf8EBAMCAYYwZwYIKwYBBQUHAQEEWzBZMC4GCCsGAQUFBzAChiJo dHRwOi8vY3JsLmxsLm1pdC5lZHUvZ2V0dG8vTExSQ0EyMCcGCCsGAQUFBzABhhtodHRwOi8v b2NzcC5sbC5taXQuZWR1L29jc3AwNAYDVR0fBC0wKzApoCegJYYjaHR0cDovL2NybC5sbC5t aXQuZWR1L2dldGNybC9MTFJDQTIwgZIGA1UdIASBijCBhzANBgsqhkiG9xICAQMBBjANBgsq hkiG9xICAQMBCDANBgsqhkiG9xICAQMBBzANBgsqhkiG9xICAQMBCTANBgsqhkiG9xICAQMB CjANBgsqhkiG9xICAQMBCzANBgsqhkiG9xICAQMBDjANBgsqhkiG9xICAQMBDzANBgsqhkiG 9xICAQMBEDANBgkqhkiG9w0BAQsFAAOCAQEAk5J8nagkqLkBH8OEa/Xljh61/LR9xNWVyICG YF6au84DtRVPKf+FJMVH4LVpkszkD1jzXvdghP8kTTpxv52zPFY4u7d6DVMhT9uGSQTpnVa8 MrV+H9PWpy/zQFdMbndsagZXLef4OOnbD9QlFLn+uivTbFb2lzDJLBXhhyCaVO1XISZ8LB/G L4EE6cQtkZRYTc7TVrjjN3zVcZL90yAvnThzWUtXVWzbliYu9mEB7ikWMX4VIEF3DPzOEh1q prgEy4TcklpQW1F02zyctHymFSXGGy1RpzvRKG/oUTw+sgXHCSiQDnPLFVbQsPd2lYUu3HXw ZZ+ldq2pGt4yylMZ7jCCA4owggJyoAMCAQICAQEwDQYJKoZIhvcNAQELBQAwVjELMAkGA1UE BhMCVVMxHzAdBgNVBAoTFk1JVCBMaW5jb2xuIExhYm9yYXRvcnkxDDAKBgNVBAsTA1BLSTEY MBYGA1UEAxMPTUlUTEwgUm9vdCBDQS0yMB4XDTE2MDQyMDEyMDAwMFoXDTM1MDQxOTIzNTk1 OVowVjELMAkGA1UEBhMCVVMxHzAdBgNVBAoTFk1JVCBMaW5jb2xuIExhYm9yYXRvcnkxDDAK BgNVBAsTA1BLSTEYMBYGA1UEAxMPTUlUTEwgUm9vdCBDQS0yMIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEAv3WoBEGOOJtm4ucvaf6vKIFPs8watCd6Smwq/XeRNo7P3jPIxNPw F398RGDUmPJIXA7idzD6j0opFIW+kLqYye9e788PV0dqaJlX8818fNDbSE+8B6hieqKTR7Vf OI74UVQEUKVRFuRFw6uVYuvgew2Tj/C2dEee37eruQl5nHkbV2OsWnZ7O+yt+etd6HRcaXLl P9q8WKgA3B7vkOVIMCKoAuaWj+BFq7K+WNkiyi/KdOH9JmOpbyRK4jcA7xbLnF8JFUSNg5c4 Y1BJrFaZtkCeG6Nm9p524GllkRFzPgpj8VicV+AK+9rY07dTx02kYotTnKuy0YxBAwsUXxAQ EwIDAQABo2MwYTAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBT/ycllTFOA8akMPCGugirH 7vgy+zAfBgNVHSMEGDAWgBT/ycllTFOA8akMPCGugirH7vgy+zAOBgNVHQ8BAf8EBAMCAYYw DQYJKoZIhvcNAQELBQADggEBAHqYfEf/3J5aMKhlYQ0PnUAbMB8jZSr9/HvjfOF00crFUCfS rqG8JQwo+S/iq66gcp62FEgJ0fQkDgVg6m+C2ETo1LoWiSxhYCfcSIQECljlXwR8wFSayF82 2S69IqvHhdq4d58jU6gYi6ssjU4vwsvsVLRJKk/m/Cg/w8gW6YHM5ahBD6/5Ccel2fI7oSms kO991+otrC11YfDwCFvz7Am0r+K9iVhSWta4hmIuV0YBia07eZKSO02LPgQ8YOz3ku0Yt+mh 8VWRKux2CcYjMpk+WDV0BMp75tqb6pqBFkcKvEBXqxg+8+G/umjii4H0c5kvJhaQyykbmOKm xO9IcJIwggT2MIID3qADAgECAhNZAAUW1xDL1n3IkFBHAAAABRbXMA0GCSqGSIb3DQEBCwUA MFExCzAJBgNVBAYTAlVTMR8wHQYDVQQKDBZNSVQgTGluY29sbiBMYWJvcmF0b3J5MQwwCgYD VQQLDANQS0kxEzARBgNVBAMMCk1JVExMIENBLTUwHhcNMjEwNzA2MjM0ODI1WhcNMjYwMzAy MjM1OTU5WjBhMQswCQYDVQQGEwJVUzEfMB0GA1UEChMWTUlUIExpbmNvbG4gTGFib3JhdG9y eTEPMA0GA1UECxMGUGVvcGxlMSAwHgYDVQQDExdCbHVtZW50aGFsLlVyaS41MDAxMDU4NDCC ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALMRXUPN5Fz28jb9GOca2/6HDq5EE4Hu T1enB0TiMEnOTipW88pgPmSZ/AAFyJF7AWX7PYPw94Ed/Bbs7yCCa6WZS7cQzdHOWppx9gRZ AxkR8+TgosxPcHoCMXmI/hXtVdZ7mwZlpBGJvyBe6YRmxOWLl3WiCRi/gBThwEWsiQZOfhEN 7hC2GhgCKetpNlTRPxslLmkStNlnjNAxhet8Vm/KSYJFVPOx3qytdLwnO6sz4AfIJJQkFX26 6oP0F/4bjRGlIZrZpdUPGiydpJl1r5SRcYs1ZE7JHErULWSyiAIzBDHUCTcN2GnFoR+9fz92 q2VIHvNHx7bV1hd0E0zlC9UCAwEAAaOCAbUwggGxMB0GA1UdDgQWBBSQ5IixU+wo9uUYNUB4 G/ea7vuWEjAOBgNVHQ8BAf8EBAMCBSAwHwYDVR0jBBgwFoAUL++7xg0du+lq/qxn8wc7CHb2 S1kwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5sbC5taXQuZWR1L2dldGNybC9sbGNh NTBmBggrBgEFBQcBAQRaMFgwLQYIKwYBBQUHMAKGIWh0dHA6Ly9jcmwubGwubWl0LmVkdS9n ZXR0by9sbGNhNTAnBggrBgEFBQcwAYYbaHR0cDovL29jc3AubGwubWl0LmVkdS9vY3NwMD0G CSsGAQQBgjcVBwQwMC4GJisGAQQBgjcVCIOD5R2H7Kdmhq2HFYPq8EWFtqEfHYXr0HCD6+0g AgFkAgELMCUGA1UdJQQeMBwGBFUdJQAGCCsGAQUFBwMEBgorBgEEAYI3CgMEMBkGA1UdEQQS MBCBDnVyaUBsbC5taXQuZWR1MBgGA1UdIAQRMA8wDQYLKoZIhvcSAgEDAQgwJwYJKwYBBAGC NxQCBBoeGABMAEwAVQBzAGUAcgBFAG4AYwAtAFMAVzANBgkqhkiG9w0BAQsFAAOCAQEAICZO a7qQQMDGZzRUaX+Mm/3meVo0nTEdNby178MGq6uYGUS4keIkljEoI+KiEMbT8rtCOBZwomnO HdJmLuRUEgrVAos27V4yjvoic8QKsz+qEhxslFg/2EYMAbTsyLqg34R+wG5o6K95ohUrgLud fPxAmcLOFBtIZBr/3DUIlzw4xHKiX2ruex7YOrQccgXb2qGtNB7tG6jAaXqFb+NZTJhj+3pd OiZiZanzpZvPLIH6Xe4awqDrok7q9ImwwSSQorNrJxKKtA3vLUW3DGvom3XDiOjDqpzhmqXC u6Wf7JfrSJRaudU2WyvYfPk7NQlkLR/1G6Xz+zKqO/cBt2aNATGCAf4wggH6AgEBMGgwUTEL MAkGA1UEBhMCVVMxHzAdBgNVBAoMFk1JVCBMaW5jb2xuIExhYm9yYXRvcnkxDDAKBgNVBAsM A1BLSTETMBEGA1UEAwwKTUlUTEwgQ0EtOAITJgAABVq3kr35c1qYVgAAAAAFWjANBglghkgB ZQMEAgEFAKBpMC8GCSqGSIb3DQEJBDEiBCAzfJFRPlZ+DN9MEDVIYcCnX9NciUUjR6pe3CCH c8Pb7TAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0yMjA1MTgx NzUzMjBaMA0GCSqGSIb3DQEBAQUABIIBAAY2VxbryQ7MIc3MO/JNrDvkcLvj9pXPDxbYuGqX gfVvq6RmDVP73J6VjOL0e7CWkUon+BU39PvFSl/qgYQwUfn49mhjRU41xDVdISeArI9ooEd3 gbbC12RO7RKCL+yK+fk4j8uLoSW/DYJT9R/kg8+9HWJpKeXa6ZQDuVPA6qBCU2GFO8p81UV+ Rpe9sIieVrx8Qxh3QF8zgQdSqm37J4RSv9WvV1GmJykUhXXEzylkNDPSH6F0+jxZljjQHzZO UyAuBDmwLZ2aV7PpYgfhkx4uAWxvFXT8JZoghL+9pgaK5Sw+2wOYeMPJcae54y5wg1u1ToyT O1XE2ga4xYdpoUU= --B_3735726800_707557647--