Should HQC use explicit rejection?

17 views
Skip to first unread message

Demi Marie Obenour

unread,
3:49 PM (6 hours ago) 3:49 PM
to pqc-...@list.nist.gov
Explicit rejection was recommended by Sophie Schmieg at the end of <https://keymaterial.net/2024/11/05/hashml-dsa-considered-harmful/>. According to https://eprint.iacr.org/2022/365.pdf ("Failing gracefully: Decryption failures and the Fujisaki-Okamoto transform") by Kathrin Hövelmanns, Andreas Hülsing, and Christian Majenz, there is a security proof for explicit rejection in schemes that use the T-transform, like HQC does. Plaintext confirmation can only improve the situation.

Should HQC use explicit rejection instead of implicit rejection, or is the risk not worth it?

The following combination should provide the strongest binding properties:

1. Use explicit rejection instead of implicit rejection.
2. Use the seed as the private key format, with the expanded format only usable as a cache.
--
Sincerely,
Demi Marie Obenour (she/her/hers)

OpenPGP_signature.asc
Reply all
Reply to author
Forward
0 new messages