Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="9TMbTd9iBw2cvCBn" --9TMbTd9iBw2cvCBn Content-Type: text/plain; charset="UTF-8" Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Andreas H=C3=BClsing writes: > Our mail said, from a provable security perspective, the bounds are the s= ame > for explicit and implicit rejection for Kyber. This suggests that there i= s > no problem with falling into explicit rejection via a side-channel attack= . I'll substitute numbers for the actual formulas to clarify my concern here. When the proofs available merely say SecLevel(ImplicitRejectKEM) >=3D SecLevel(PKE) - 200 and SecLevel(ExplicitRejectKEM) >=3D SecLevel(PKE) - 200 they do not provide a logical basis for the following equations: SecLevel(ExplicitRejectKEM) =3D SecLevel(ImplicitRejectKEM) =3D SecLevel= (PKE). I understood "as secure as implicit rejection" to be indicating at least the first equation, and in context I'd expect many people to understand it as also indicating the second. ---D. J. Bernstein --=20 You received this message because you are subscribed to the Google Groups "= pqc-forum" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to pqc-forum+unsubscribe@list.nist.gov. To view this discussion on the web visit https://groups.google.com/a/list.n= ist.gov/d/msgid/pqc-forum/20221220165757.24985.qmail%40cr.yp.to. --9TMbTd9iBw2cvCBn Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE3QolqQXydru4e4ITsMANTjsOVFkFAmOh6ZQACgkQsMANTjsO VFlV0hAAmaaERb2zPYxaE7f63fGCqhxJclMbkFmAyl/qaOsEFDbMyU8ADkVY2X7O +BBWDOReuJhRi07mJpPFuQzG0WMx64rAzAvWoHbxBtABRP6My7mH98MhhXXAHlr5 NBN3dr8Xu4GwFNygqlzybPP5lng+IvyY3ezsL1yD/fWA/SRQqPJ/CceIAwW0puch KZcpOChy9bq0vtNTv2l+va6eCDcdeKpk++RsWuenEzz5gc0xdeOwrSTIMgtJcM3q uLUGvqgkRWgFYuhVq3xNEziBXTXjaB8rHfvlxp/7Nqf2CPi2AFZwLJ0IXDDyQTqN LdqL/Yd0EKVXJMjCx2GCP5Fo/3X+vasqcu0gmdyWYPlKMMapiKNUz/i+HVYj2yGz lR2NP2WtvYlSmhZXn2o9W+94i9Kpgd6DaLgRDDuogb/7XegXuRtKCo3N1zfNxGhk O5fpWfFtgkSKfTua2yQgWYbbPZIKJhdzafOzUwlHe+E77WMv//E6xeCEM7qblR3J mOUTfVtGVqRfAYcjOTrFCdEwU8ZnXKzADX6c8Sz8aOz7n7jhBl9ZodKPGIRewNPa 8KeS/XlL66hSIv/PR6HfnpiIt66r6dBsLDppKpwNlJpsFcspjNVBIdKnwE2i3sWC XU2uYMOapTKrE1GIDnvPkvYUfn7Yewd+R0FlhiwiljfUsUTsmeE= =89ZD -----END PGP SIGNATURE----- --9TMbTd9iBw2cvCBn--