> A key transport protocol is similar to a key exchange algorithm in that the sender, Alice, generates a random symmetric key and then encrypts it under the receiver’s public key. Upon successful decryption, both parties then share this secret key.
Isn't the following just describing how everyday PKE works?
> The general paradigm here is called "hybrid public-key encryption" because it combines a non-interactive key exchange based on public-key cryptography for establishing a shared secret, and a symmetric encryption scheme for the actual encryption.
It feels like the blog post is not principally concerned with explaining the benefits of HPKE, because everyone is already using it, but rather just proposing a standard for the many ways people are doing it.
The real benefit of this is the long tail of obscure applications whose weaknesses no one is looking at - until eventually, some bad actor does.
Replacing working cryptographic standards is expected from an NSA front.
> A paper by Martinez et al. provides a thorough and technical comparison of these different standards. The key points are that all these existing schemes have shortcomings. They either rely on outdated or not-commonly-used primitives such as RIPEMD and CMAC-AES, lack accommodations for moving to modern primitives (e.g., AEAD algorithms), lack proofs of IND-CCA2 security, or, importantly, fail to provide test vectors and interoperable implementations
For more thorough analysis of one of its novelties namely authenticated mode you can check this paper:
Analysing the HPKE Standard:
https://link.springer.com/chapter/10.1007/978-3-030-77870-5_...
From what I can gather it seems to me this work tries to unify and generalize several existing hybrid public key encryption standards, which all apparently have various issues, mostly stemming from using outdated primitives and no extensibility.
So this work tries to introduce extesibility in a secure way, while also ensuring interoperability. The motivation seems to be able to use HPKE in IETF standards.
Another benefit over previous standards seems to be the addition of authenticated modes, where the sender authenticates itself to the recipient.
It's a subset of what Noise defines, standardized and further parameterized.
The point of the RFC is to level up (and make consistent) future cryptographic designs from the IETF. It's not something you'd use directly.
https://neilmadden.blog/2021/01/22/hybrid-encryption-and-the...
tl;dr: resistance to padding attacks, better support for non-RSA cryptosystems