[IPsec] Protocol Action: 'Multiple Key Exchanges in IKEv2' to Proposed Standard (draft-ietf-ipsecme-ikev2-multiple-ke-12.txt)
The IESG <iesg-secretary@ietf.org> Fri, 09 December 2022 15:19 UTC
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: ipsec@ietf.org
Delivered-To: ipsec@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 17B17C15C921; Fri, 9 Dec 2022 07:19:46 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 9.2.1
Auto-Submitted: auto-generated
Precedence: bulk
Cc: The IESG <iesg@ietf.org>, draft-ietf-ipsecme-ikev2-multiple-ke@ietf.org, ipsec@ietf.org, ipsecme-chairs@ietf.org, kivinen@iki.fi, rdd@cert.org, rfc-editor@rfc-editor.org
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <167059918607.30282.4167923818577979475@ietfa.amsl.com>
Date: Fri, 09 Dec 2022 07:19:46 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/gQYwPIteaBLH9bhTbAQ5f8VOQHs>
Subject: [IPsec] Protocol Action: 'Multiple Key Exchanges in IKEv2' to Proposed Standard (draft-ietf-ipsecme-ikev2-multiple-ke-12.txt)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Dec 2022 15:19:46 -0000
The IESG has approved the following document: - 'Multiple Key Exchanges in IKEv2' (draft-ietf-ipsecme-ikev2-multiple-ke-12.txt) as Proposed Standard This document is the product of the IP Security Maintenance and Extensions Working Group. The IESG contact persons are Paul Wouters and Roman Danyliw. A URL of this Internet Draft is: https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-multiple-ke/ Technical Summary This document describes how to extend the Internet Key Exchange Protocol Version 2 (IKEv2) to allow multiple key exchanges to take place while computing a shared secret during a Security Association (SA) setup. The primary application of this feature in IKEv2 is the ability to perform one or more post-quantum key exchanges in conjunction with the classical (Elliptic Curve) Diffie-Hellman key exchange, so that the resulting shared key is resistant against quantum computer attacks. Another possible application is the ability to combine several key exchanges in situations when no single key exchange algorithm is trusted by both initiator and responder. This document updates RFC7296 by renaming a transform type 4 from "Diffie-Hellman Group (D-H)" to "Key Exchange Method (KE)" and renaming a field in the Key Exchange Payload from "Diffie-Hellman Group Num" to "Key Exchange Method". It also renames an IANA registry for this transform type from "Transform Type 4 - Diffie- Hellman Group Transform IDs" to "Transform Type 4 - Key Exchange Method Transform IDs". These changes generalize key exchange algorithms that can be used in IKEv2. Working Group Summary The document has WG consensus. The number of authors reflects the expertise needed to draft this document -- both IPsec and PQC cryptography. Document Quality As this document was changing the a cryptographic mechanism in IPsec, it was was subject to a peer-reviewed, formal verification: * DOI: https://dl.acm.org/doi/10.1145/3485832.3485885 * Pre-print: https://www.mnm-team.org/pub/Publikationen/gggh21b/PDF-Version/gggh21b.pdf Several implementors have been integral in developing this document. There is already at least two interoperable implementations of this specification: * strongSwan, https://github.com/strongswan/strongswan/tree/ikev2-qske-multi-ke * ELVIS-PLUS, http://ipsec.elvis.ru/en.html Personnel Document Shepherd: Tero Kivinen Responsible AD: Roman Danyliw