[IPsec] I-D Action: draft-ietf-ipsecme-ikev2-multiple-ke-12.txt

internet-drafts@ietf.org Thu, 01 December 2022 12:55 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: ipsec@ietf.org
Delivered-To: ipsec@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DEAAC14CEE0; Thu, 1 Dec 2022 04:55:38 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Cc: ipsec@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 9.1.0
Auto-Submitted: auto-generated
Precedence: bulk
Reply-To: ipsec@ietf.org
Message-ID: <166989933863.52387.4743452944348873533@ietfa.amsl.com>
Date: Thu, 01 Dec 2022 04:55:38 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/_njE_2DtoHP8JktWx65QXxadWa0>
Subject: [IPsec] I-D Action: draft-ietf-ipsecme-ikev2-multiple-ke-12.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Dec 2022 12:55:38 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the IP Security Maintenance and Extensions WG of the IETF.

        Title           : Multiple Key Exchanges in IKEv2
        Authors         : C. Tjhai
                          M. Tomlinson
                          G. Bartlett
                          S. Fluhrer
                          D. Van Geest
                          O. Garcia-Morchon
                          Valery Smyslov
  Filename        : draft-ietf-ipsecme-ikev2-multiple-ke-12.txt
  Pages           : 37
  Date            : 2022-12-01

Abstract:
   This document describes how to extend the Internet Key Exchange
   Protocol Version 2 (IKEv2) to allow multiple key exchanges to take
   place while computing a shared secret during a Security Association
   (SA) setup.

   The primary application of this feature in IKEv2 is the ability to
   perform one or more post-quantum key exchanges in conjunction with
   the classical (Elliptic Curve) Diffie-Hellman (EC)DH key exchange, so
   that the resulting shared key is resistant against quantum computer
   attacks.  Since there is currently no post-quantum key exchange that
   is as well-studied as (EC)DH, performing multiple key exchanges with
   different post-quantum algorithms along with the well-established
   classical key exchange algorithms addresses this concern, since the
   overall security is at least as strong as each individual primitive.

   Another possible application for this extension is the ability to
   combine several key exchanges in situations when no single key
   exchange algorithm is trusted by both initiator and responder.

   This document utilizes the IKE_INTERMEDIATE exchange, by means of
   which multiple key exchanges are performed when an IKE SA is being
   established.  It also introduces a new IKEv2 exchange
   IKE_FOLLOWUP_KE, which is used for the same purpose when the IKE SA
   is up (during rekeys or creating additional Child SAs).

   This document updates RFC7296 by renaming a transform type 4 from
   "Diffie-Hellman Group (D-H)" to "Key Exchange Method (KE)" and
   renaming a field in the Key Exchange Payload from "Diffie-Hellman
   Group Num" to "Key Exchange Method".  It also renames an IANA
   registry for this transform type from "Transform Type 4 - Diffie-
   Hellman Group Transform IDs" to "Transform Type 4 - Key Exchange
   Method Transform IDs".  These changes generalize key exchange
   algorithms that can be used in IKEv2.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-multiple-ke/

There is also an htmlized version available at:
https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-ikev2-multiple-ke-12

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-ipsecme-ikev2-multiple-ke-12


Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts