[Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02
Tao Wan <T.Wan@cablelabs.com> Thu, 23 July 2026 14:35 UTC
Return-Path: <T.Wan@cablelabs.com>
X-Original-To: emu@mail2.ietf.org
Delivered-To: emu@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4506611D7F466 for <emu@mail2.ietf.org>; Thu, 23 Jul 2026 07:35:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784817327; bh=vwlOvQ6y/ahe3IXU8CrBRif9vE0cK2aZDaPC4qFmVEA=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=bA4KvYGNz9m66DxMeYyRh8k4nxELFKA5P9zbc6i7KLiu71Nx0qOHHteFrfVP7K33/ b29b0LdKP46UZpgrEJRMuW0JIdrdOXXEQLS1GE19H9c7LWoMhkkN70QsV5+EMkG9s/ PqbCTmjOVskGJ/gvaWys25naU4pja/aP6YbC8SJ0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cablelabs.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zPWITRuERiMe for <emu@mail2.ietf.org>; Thu, 23 Jul 2026 07:35:26 -0700 (PDT)
Received: from SJ2PR03CU001.outbound.protection.outlook.com (mail-westusazon11022075.outbound.protection.outlook.com [52.101.43.75]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1E33F11D7F3DA for <emu@ietf.org>; Thu, 23 Jul 2026 07:35:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=pzrDRxyLjoRBjafTxIeoDDOxv0K584dByBbXpekVX7nxBNMh0izfdgNfBWWJTIOPl2B2mobmf3HbeGz563A1Fc1y0ZPowluy6T4X4QrYe+UrEqwMgo2XEDCLk3eDD/impn8Y1qZ0Jx1SXFr8EuyiLLAls9MHwHsaAUpdfPpEkABFiVNz5diOB8l/hgAL2p/0yDiqhGFoVwMF5fgMBot+hKA4NgcA292mpA8oH8A9tTHu00DxjEI0A1bYawv6ECkTz/jsk64TQjX2hejGzG+/q5SEbOGezAERxMhul+Wm2hYWWKLZr8BFmA+HEx3r5njBeRMF1OAJeRAXOIXaIRNcRQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=vwlOvQ6y/ahe3IXU8CrBRif9vE0cK2aZDaPC4qFmVEA=; b=iDg3DJw/pH4RWB41GB6kNN7hCyYXzVCGr4wgpw6L4QeOWDbaoSmFgdOEkXSscpTm4da9fouEKB3FOKU+yD9RZZ4nimxoBagbDplahu81vZfCqfk+Jbd2YKhxx1/y+Uc4BW9PWOwOuJnj5PgsYr2eVhs++A1oT4YK28IQDLw8oQAC2ExOVViQvj0GU2F37YMDRp67tHwQ926q973mLvGMRXuQiLIjwGmXTcCIoLZUsiPRN160h0Wp0inxrLs1en/TRcsPhTqoHoaUqlSPY6fsxxJzlcn26PgEPTfHZDrIDmxAJOYoq++VUb5aiBBzDswKY55qnnFMN0qLnx7MkG8xJg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cablelabs.com; dmarc=pass action=none header.from=cablelabs.com; dkim=pass header.d=cablelabs.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cablelabs.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vwlOvQ6y/ahe3IXU8CrBRif9vE0cK2aZDaPC4qFmVEA=; b=iv/itbLK/5OkiTzyA1ZG/uEcYk1ueu32okZUc/eT5OWnKtMQyj7Jm2nb/4eXAaW2YFuEdkKzf7lKbj1ibPPL0px4c4J64pXz1GEv2q2Zm3RDuA6Mr2hn0BJAAKcue0cICnoap6kjiyjcxPv+3pYFUsnQ70bALSw3LOXUOCP0jdyCzAyfs2Bh/ZRseVshQ0tMVMC1yzscuNMI82cyFaDT079CranVjNTmkBaW/CwbXDqRfU9Nf22Dnevb6tboSGqxh1JhNGJ7eg0tkMTf/x/s9J6OPiBvtAl18x8XqFXco75c6ZmKNzxnHuSJDZoHvAyfuy9LaZ0FrXP47ieF6yaxZg==
Received: from SN6PR06MB4720.namprd06.prod.outlook.com (2603:10b6:805:9e::14) by SA1PR06MB8418.namprd06.prod.outlook.com (2603:10b6:806:1cd::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.270.5; Thu, 23 Jul 2026 14:34:57 +0000
Received: from SN6PR06MB4720.namprd06.prod.outlook.com ([fe80::eb6b:698a:9f26:2d6c]) by SN6PR06MB4720.namprd06.prod.outlook.com ([fe80::eb6b:698a:9f26:2d6c%4]) with mapi id 15.21.0245.009; Thu, 23 Jul 2026 14:34:57 +0000
From: Tao Wan <T.Wan@cablelabs.com>
To: Heikki Vatiainen <hvn@radiatorsoftware.com>, Wang Guilin <Wang.Guilin@huawei.com>, EMU WG <emu@ietf.org>
Thread-Topic: [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02
Thread-Index: AQHdGNNBzOJkm1KVMEmgjERC1z7nsbZ4GMIAgAAYFgCAAAXfgIABhhHegAFk1Is=
Date: Thu, 23 Jul 2026 14:34:57 +0000
Message-ID: <SN6PR06MB472033F4B1572CE82D34CB03E2C02@SN6PR06MB4720.namprd06.prod.outlook.com>
References: <CAA7Lko-E9emQzNWbEdQMjVQyCwHpj450oRjQMTGj+njezozXbA@mail.gmail.com> <AS4PR07MB882505F76FB0846E55C5140289C22@AS4PR07MB8825.eurprd07.prod.outlook.com> <CAA7Lko-bmm-qK+UsTAhmDnJCy18ApAPihpqWYeLcrZ5x9=-WMg@mail.gmail.com> <AS4PR07MB88255CC04DF12F87B250E9B889C22@AS4PR07MB8825.eurprd07.prod.outlook.com> <6a5fac75.ca1e0f37.179a58.165bSMTPIN_ADDED_BROKEN@mx.google.com> <CAA7Lko-dNbQg8wgqUNsAV6p+7zAHQTfAWXbc319k2ZMXxEwBAw@mail.gmail.com>
In-Reply-To: <CAA7Lko-dNbQg8wgqUNsAV6p+7zAHQTfAWXbc319k2ZMXxEwBAw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cablelabs.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SN6PR06MB4720:EE_|SA1PR06MB8418:EE_
x-ms-office365-filtering-correlation-id: be51eb71-7469-4a9c-809f-08dee8c79195
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|23010399003|1800799024|366016|376014|13003099007|38070700021|56012099006|11063799006|4143699003|10067099003|8096899003|18002099003|22082099003;
x-microsoft-antispam-message-info: LAsBy7/KFNBn6KwXQxq9kXw/2rQdxdqA8x5lvG87PkZcknSK8WI0GyBF8VWNlJu6kgl6zI1w/Fdjg9iWQbh3VUhzA4CsVxUYuD0yqSivVsHcYfsGKa418YSsXPXNKde3arpCf1JJjyoqdL3TjCfjXzK+uC3f/ZpFbEgI7SfJZDPUUmWHNHBEecQxet8L+Tz6qAleDxm3fQ/vyiBCfvrWFkWwHbANeJQtfGBP8mw+aQeNtH0YMUS2ppvWa7n/NBeA2YgPS5erXsnEm2oGrX5mlnF356h5rXtbCa2eHH09yzfUktFSDagjeB+wZupXWmhhVXzDaq5m65XUAfKiLfPSpZVPA6TqcN1ueVsbXfLXvZ+escjSLcLdBLQQzcV5OL/2Q9mouHxwn6mXbOU3SHugfN0aLNwQA/EJynabSAWeD9LG9J9w2d4wEW9o6bZA12kGL3k9iDdCF4rIELnUWb7r8Cf/qyGCvDxUZsW7uWYTdidcZfupak0UoK9nIXstn++miC/DIh3H1wrZDeCqTH4Gz2vHGqI8C5IWpa9Uaz1NaAYQ7QD5G8vmDkzaOlhhRgm0G+18SCOmmCRfLgBsv2hkmtd3oTAxxL6GvdaoC1eNfJX2OYa0C9Q2OJn4BSlskBdLyUjOPNT7bbmqnDlw/aBHXO7FNtBsR16BiY937tvKNkQ=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SN6PR06MB4720.namprd06.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(1800799024)(366016)(376014)(13003099007)(38070700021)(56012099006)(11063799006)(4143699003)(10067099003)(8096899003)(18002099003)(22082099003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: QDOQiSUBOuANPGGLFzslgeHbqU88Ao5RAg2qI4vK8/yFix/IqcIeLZX2+5zOh6aGIEPH8tqg9QGtDrhC2ajdnpmAT9QuS+Q2TJQn5x2IcSLRFMuNxyAWXT/sVK0NyozTLusPaDh39zEbA98tqgKWSxT117T5yXGU5v03AduI3oBE+hxTeLaPS9SVD9Pcs5D5TB4c2OWObBOb7yipaZKntsahj2+lQ4mrswD4WLQjMk4GJYkPfryiEL2HwqwhQsF+y63TyMpLf2/6CG7KwEIf8clgEAuxd+tvJKn7Io0Eu1UdIHVfHD+P91HrPnfsKB2mVvX8sKBjpixJzog5ruaXsag5Im47kfIucvB8+ceGqyw0x+xflgAsI5g9zVV4joAk9e7xqjemWj8ZK43qNXsmOwfZQrnLllaUE51WC1Teb3iMyudF5PVDiv8wHKwqGL7Ajvz1oWYMQex61oG26DbNEtCrVSLfiYaPcikZZh1+SVdDitiMn7JZD1nLhOOb/eeD02eUBg9qja47XHF8JcWD/HPo8u5BPQnijJWpSefSyI6wudYJ/Lvm72qUEnCb5zy5xZ7aP85TvoNXOxzDn+KZvZei0XM1/4Ra+0F/aRw5JSiqqG5bt4/Oq9q2k1tm6hToqibyjL/r/lv1G0LK9Z37Cev+FoKLcmU/1IevcHP9O3xqfUerhuRmnrgnqrKnhI5crpdjDMx0iBJSvXirZuUize45AyhBaErbGD+fKMla6Oo6sw4lpdupcuURy6pQuEm2c2wGgZmgyUtTSwyQu5iJTqXaxlwzeixFt/zx/16jr+NjsU8zvy0v3gRufDLQ3WKFrmwS3yUls+aQZuQ6CkdYEHc2okqc6a6ZXWgZ1Kz3zdLFsczxMA2Ig3mcgV/gmtARmsohlsiUXtRd59DhVj3E1ZrMXZf4dc28ofV/ySuirRC4QGexeZJTr3pU8i/EFkS0eMdoo64JDSUOQUGBlpdP0dQCn1Db5LyHdmpSij3UG/JhE2Qy0GzJdF4ixiGXQEVFm2GE8FY4Bn8PRhiCxu5enIxfc8M3kFXxkQRP2OSf12LrL66C5BMy9oe6ucyIGD+by1AwQ0MK7exLnu/YNt6081QwaTVaM9Qy/YF2pEx4UWH+7OWc0+J/4U8mGOxJ/3eQE7f31FXE0QLp+3nLMcRSgbUsJbroeC7unCT8h9Wdq8Lg3bZY5zPJKfWOGGr5H75LmYBwY/yxFtz4TLqB2RYrS8BA6krW0HEWHI/u3e6GDgVwKKtUYArAmmvOhc8XKa8efGgjvd5zeHgkZYdxM/IVNEsh4K9boi+pUKe18mt0/9xT1ROYb8AdrVRPveD1hJXHx8cQzCq8mBCuh5EPbNwDCQ6lhaxX1d1dPcPmtLjHJy3SE11oKuNBYZObMlyrz5hyHw8LiTmUyocFZfmJK4OOn4DIF+Nxro/DemE5uQnOD3b0YZvcWjxTJN1faXy60ktQ9w7bFL64Cu2LI5nHKu7cpYoHUzd0YwJ842IoyxZCpm6xwsRPWmsoyfaoKsZTbre5BD0l5rrj6RYBdYFdeZkH3EOK1HSFT4VFMfuGy3VpbiwbJwTSVD+Awfu2dK8UpJOe590dCID85N94DtAf0LP7+6V3xox8WFtyOmWKe5AaWIRR5jlR0Qhu8PkUTgQCh8TKF8k7R/SH+t3gJzRlMAOP6VR/zYwWcKf3K8MV+c6tdFJhAsjIluTa7phh2wsn0OpI48OKr6Hg8+iU3e8V2LHYxQ==
Content-Type: multipart/alternative; boundary="_000_SN6PR06MB472033F4B1572CE82D34CB03E2C02SN6PR06MB4720namp_"
MIME-Version: 1.0
X-OriginatorOrg: cablelabs.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SN6PR06MB4720.namprd06.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: be51eb71-7469-4a9c-809f-08dee8c79195
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Jul 2026 14:34:57.1247 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: ce4fbcd1-1d81-4af0-ad0b-2998c441e160
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: c0K/85DsssNYgZRwRMDNL4GskxsMFM5nj4VcEh470BREtMbAK6hFQkrpjA2F/smqeqS1zZg+Y1lyN43jJXXQyA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR06MB8418
Message-ID-Hash: 4MKCMLVWWIH35H2RGPHBFFXPTL24X7NQ
X-Message-ID-Hash: 4MKCMLVWWIH35H2RGPHBFFXPTL24X7NQ
X-MailFrom: T.Wan@cablelabs.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-emu.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Jari Arkko <jari.arkko@ericsson.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02
List-Id: "EAP Methods Update (EMU)" <emu.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/KWMsc5e1KWfhOT2adIG2fxMb31c>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Owner: <mailto:emu-owner@ietf.org>
List-Post: <mailto:emu@ietf.org>
List-Subscribe: <mailto:emu-join@ietf.org>
List-Unsubscribe: <mailto:emu-leave@ietf.org>
Hi Heikki, Thank you for bringing the attention to my post on the 3GPP LS to EMU and the AT_IDENTITY fragmentation draft. Here is some background information on the LS and draft. At 3GPP SA3 May meeting, it was concluded that both standalone and hybrid PQC schemes for SUCI will be supported. However, the proposal to start normative specification of PQC profiles for SUCI was not agreed, partly due to concerns that EAP-AKA’ cannot currently support PQC protected SUCI of large size. So 3GPP SA3 sent the LS, asking IETF EMU to update EAP-AKA’ to support large identities. Based on the request from 3GPP, I proposed the AT_IDENTITY fragmentation draft. It would be great if both the LS and the draft could be discussed at the Friday meeting. Although I cannot attend to present, I hope both are straightforward to discuss without me. I am happy to provide comments by email. Thanks, Tao From: Heikki Vatiainen <hvn@radiatorsoftware.com> Date: Wednesday, July 22, 2026 at 12:29 PM To: Wang Guilin <Wang.Guilin@huawei.com>; EMU WG <emu@ietf.org> Cc: Jari Arkko <jari.arkko@ericsson.com> Subject: [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02 Hello Guilin, after reviewing recent postings for the Friday meeting, I noticed I had missed a draft and messages related to AT_IDENTITY fragmentation and where to need for it comes from. Tao Wan posted on the list on June 2nd two related links: - a link to AT_IDENTITY fragmentation draft: https://datatracker.ietf.org/doc/draft-wan-emu-aka-prime-identity-fragmentation/ - a link to a liaison statement from 3GPP: https://datatracker.ietf.org/liaison/2162/ titled: LS on supporting transmission of large identity in EAP-AKA’ The liaison statement then points to a 3GPP Technical Report with more about SUCI calculation when Post-Quantum Cryptography algorithms are used. The liaison statement is not linked on the EMU WG page even if it directly requests for EAP-AKA' updates. Thanks, Heikki On Tue, 21 Jul 2026 at 20:29, Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>> wrote: Thanks, John. I see. I once thought SUCI is just a symmetric encryption of SUPI, using a key dervived from EAP-AKA or EAP-AKA'. In this case, the length of SUCI will be mainly decided by that of SUPI. Using asymmetric KEM-DEM encryption or HPKE will be a different story. > SUCI is specified in an appendix to 3GPP TS 33.501 since Rel-15. Great! Guilin 发件人:John Mattsson <john.mattsson@ericsson.com<mailto:john.mattsson@ericsson.com>> 收件人:Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>>;Heikki Vatiainen <hvn@radiatorsoftware.com<mailto:hvn@radiatorsoftware.com>> 抄 送:EMU WG <emu@ietf.org<mailto:emu@ietf.org>>;Jari Arkko <jari.arkko@ericsson.com<mailto:jari.arkko@ericsson.com>>;Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>> 时 间:2026-07-21 19:13:14 主 题:Re: [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02 SUCI is an asymmetric KEM-DEM encryption of SUPI (similar to the later HPKE which might be familiar to IETF people). The MTI profiles today use ECC, but already now people are free to use PQC. 3GPP is expected to soon specify PQC profiles for SUCI. And if any government want to use FrodoKEM, 3000 bytes would not be enough :) SUCI is specified in an appendix to 3GPP TS 33.501 since Rel-15. Cheers, John From: Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>> Date: Tuesday, 21 July 2026 at 18:52 To: Heikki Vatiainen <hvn@radiatorsoftware.com<mailto:hvn@radiatorsoftware.com>>; John Mattsson <john.mattsson@ericsson.com<mailto:john.mattsson@ericsson.com>> Cc: EMU WG <emu@ietf.org<mailto:emu@ietf.org>>; Jari Arkko <jari.arkko@ericsson.com<mailto:jari.arkko@ericsson.com>>; Wang Guilin <Wang.Guilin@huawei.com<mailto:Wang.Guilin@huawei.com>> Subject: [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02 Is SUCI a symmetric encryption of SUPI? Any particular coming reasons may lead SUCI much longer? Guilin 发件人:Heikki Vatiainen <hvn@radiatorsoftware.com<mailto:hvn@radiatorsoftware.com>> 收件人:John Mattsson <john.mattsson@ericsson.com<mailto:john.mattsson@ericsson.com>> 抄 送:EMU WG <emu@ietf.org<mailto:emu@ietf.org>>;Jari Arkko <jari.arkko@ericsson.com<mailto:jari.arkko@ericsson.com>> 时 间:2026-07-21 18:20:07 主 题:[Emu] Re: Fragmentation in draft-ietf-emu-pqc-eapaka-02 On Tue, 21 Jul 2026 at 08:38, John Mattsson <john.mattsson@ericsson.com<mailto:john.mattsson@ericsson.com>> wrote: Heikki Vatiainen wrote: >Second, section '7.5 Applicability' notes that AT_IDENTITY may need fragmentation with large SUCI values. SUCI is 3GPP's Subscription Concealed Identifier which is encrypted permanent user identifier. > >If AT_IDENTITY requires fragmentation, then EAP-Request/AKA'-Identity and EAP-ResponseAKA'-Identity exchange, that runs before the first EAP-Request/AKA'-Challenge, needs to be fragmentation aware too. AT_IDENTITY is used only with EAP-Response/AKA-Identity as defined by RFC 4187. > >3GPP TS 33.501 says about maximum size 'total of 3000 octets plus size of input' where input can be a NAI (username@realm). With these maximum sizes even the initial, non-EAP-AKA' EAP-Response/Identity comes problematic too, because of the EAP Identity type definition: > > https://www.rfc-editor.org/rfc/rfc3748.html#section-5.1 > By default, an EAP implementation SHOULD NOT assume that an Identity > Request or Response can be larger than 1020 octets. This seems like an RFC 9048 problem. EAP-AKA' with PQC SUCIs can be used without ephemeral PQC key exchange giving FS and PCS. With 1020 bytes you would not be able to fit a ML-KEM-768 ciphertext (1088 bytes) or ML-KEM-1024 (1568 bytes) . ML-KEM-512 (768 bytes) would work. Since long SUCIs are going to happen in the future, should the fragmentation work be done as an update to RFC 9048? As you wrote, long SUCIs and the draft discussed in this thread cause fragmentation for different reasons. The fragmentation support could then be part of updated base EAP-AKA'. EAP-SIM and EAP-AKA seem not to be affected because there's no use of SUCI planned for them? As an example, I took a look at the 3GPP AAA Server interfaces document, 3GPP TS 29.273, and while it uses EAP-AKA for a number of cases, it seems to use SUCI with EAP-AKA' only. In other words, it seems need for fragmentation could be limited to RFC 9048. One of the ways to get around long SUCI values might be to use a short enough value with EAP-Response/Identity and let EAP-Request/AKA'-Identity exchange to handle identities that are over the 1020 octet threshold. This would match what the EAP-AKA RFC originally suggests too: https://datatracker.ietf.org/doc/html/rfc4187#section-4.1.2.2 (named Relying on EAP-Response/Identity Discouraged): For this reason, it is RECOMMENDED that the EAP peer and server use the method-specific identity attributes in EAP-AKA, and the server is strongly discouraged from relying upon the EAP-Response/Identity. -- Heikki Vatiainen hvn@radiatorsoftware.com<mailto:hvn@radiatorsoftware.com> -- Heikki Vatiainen hvn@radiatorsoftware.com<mailto:hvn@radiatorsoftware.com>
- [Emu] Fragmentation in draft-ietf-emu-pqc-eapaka-… Heikki Vatiainen
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… John Mattsson
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… Heikki Vatiainen
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… John Mattsson
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… Jari Arkko
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… Wang Guilin
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… John Mattsson
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… Wang Guilin
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… Heikki Vatiainen
- [Emu] Re: Fragmentation in draft-ietf-emu-pqc-eap… Tao Wan