Protocol Action: 'Use of Hybrid Public Key Encryption (HPKE) with JSON Web Encryption (JWE)' to Proposed Standard (draft-ietf-jose-hpke-encrypt-22.txt)

The IESG <iesg-secretary@ietf.org> Thu, 24 September 2026 15:59 UTC

Received: by mx.ietf.org (Postfix) id A6D3F52; Thu, 24 Sep 2026 15:59:26 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ietf.org; s=mail; t=1790265566; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:mime-version: content-type:content-type:content-type: content-transfer-encoding:content-transfer-encoding:content-transfer-encoding; bh=vL3vSrHfnEPKldKE4BvOrNYgEIJt0trvNa2plzm4XoI=; b=TgrkgV/wi/+PM189Je8LCI0yGjGvJeBFCYJ5IAEiOx0TEx6Wu72sZzheJ9sT9R3opo4KqX 2g+me9JSn/fziprJdbnPgK/7jZyPxrTUnOOtx6Ep1ADW567KNp+DYHjVPB2IGQ57OY559y Ufz/Awn/H153Q61Ldcl2zElpoTrCPL0=
Authentication-Results: ORIGINATING; auth=pass smtp.auth=mail2@ietf.org smtp.mailfrom=iesg-secretary@ietf.org
Received: from [10.244.9.157] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 4A63B139C3815; Thu, 24 Sep 2026 08:59:21 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Subject: Protocol Action: 'Use of Hybrid Public Key Encryption (HPKE) with JSON Web Encryption (JWE)' to Proposed Standard (draft-ietf-jose-hpke-encrypt-22.txt)
X-Test-IDTracker: no
X-IETF-IDTracker: 12.77.0
Auto-Submitted: auto-generated
Precedence: bulk
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <179026556124.307436.11499733037832473105@dt-datatracker-69f6c78549-jvtvd>
Date: Thu, 24 Sep 2026 08:59:21 -0700
Message-ID-Hash: EKIZIBLHVRGCBPCJDZMBPM4EXXGGQFKH
X-Message-ID-Hash: EKIZIBLHVRGCBPCJDZMBPM4EXXGGQFKH
X-MailFrom: iesg-secretary@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-ietf-announce.ietf.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: The IESG <iesg@ietf.org>, draft-ietf-jose-hpke-encrypt@ietf.org, jose-chairs@ietf.org, jose@ietf.org, michael.p1@ncsc.gov.uk, rfc-editor@rfc-editor.org
X-Mailman-Version: 3.3.10
List-Id: "IETF announcement list. No discussions." <ietf-announce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-announce/_uj_0vBGyqo1gU347b7Y2VMfBHY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-announce>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Owner: <mailto:ietf-announce-owner@ietf.org>
List-Post: <mailto:ietf-announce@ietf.org>
List-Subscribe: <mailto:ietf-announce-join@ietf.org>
List-Unsubscribe: <mailto:ietf-announce-leave@ietf.org>

The IESG has approved the following document:
- 'Use of Hybrid Public Key Encryption (HPKE) with JSON Web Encryption
   (JWE)'
  (draft-ietf-jose-hpke-encrypt-22.txt) as Proposed Standard

This document is the product of the Javascript Object Signing and Encryption
Working Group.

The IESG contact persons are Christopher Inacio and Deb Cooley.

A URL of this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-jose-hpke-encrypt/




Technical Summary

   This specification defines how to use Hybrid Public Key Encryption
   (HPKE) with JSON Web Encryption (JWE).  HPKE enables public key
   encryption of arbitrary-sized plaintexts to a recipient's public key,
   and provides security against adaptive chosen ciphertext attacks.
   This specification chooses a specific subset of the HPKE features to
   use with JWE.

   This specification updates RFC 7516 (JWE) to enable use of Integrated
   Encryption as a Key Management Mode.

Working Group Summary

The document has received reviews on mailing lists and GitHub from a range of
individuals. Thorough review was prompted by a first WGLC in June 2025, which
did not pass but led to a number of issues being raised and rectified. Broad
agreement was reached during the second WGLC in February 2026. There has been
suggestion to include PQC algorithms in this draft, but broad agreement to do
that in a separate draft.

During IETF Last Call, it became apparent that there was a disconnect with respect
to algorithms that are currently specified in the IANA JOSE registries.
  
This second run through the process is to remove HPKE-4-KE and HPKE-6-KE as options 
in the Key Encryption mode.  This is the only change!  

Document Quality

There is mailing list discussion which highlights multiple interoperable implementations.

No external reviews, or other specialized reviews were required.

The original RFC9180 (HPKE) published by CFRG is being reworked, the draft-ietf-hpke-hpke is in AD review.  
COSE has a parallel draft which has been submitted to the IESG for publication.

Personnel

   The Document Shepherd for this document is Michael P. The Responsible
   Area Director is Deb Cooley.