Skip to content

Should aggregation service public key advertisement be covered by the specification? #362

@apasel422

Description

@apasel422

Step 15.1 of the "construct a DAP report" algorithm says:

Let pkR be the public key of the corresponding role from the aggregation service HPKE configuration obtained for the aggregation service indicated by options.Aggregation Service.

The URL for "dap-15-histogram" is expected to identify the DAP Leader role. Implementations need to obtain HPKE configuration for both Aggregators statically. The HPKE configuration must not be fetched on demand, as the time that takes will leak information to callers of measureConversion().

Should we also specify how the aggregation services advertise their public key(s) so that they can be obtained in a standard way across implementations?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions