[Lake] Re: Request for standardized lightweight quantum-resistant key exchange (on behalf LAKE WG)
John Mattsson <john.mattsson@ericsson.com> Thu, 17 September 2026 08:00 UTC
Received: from PA4PR04CU001.outbound.protection.outlook.com (mail-francecentralazlp170130007.outbound.protection.outlook.com [IPv6:2a01:111:f403:c20a::7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange secp256r1 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 5B26C42 for <lake@ietf.org>; Thu, 17 Sep 2026 08:00:12 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=ericsson.com header.s=selector2 header.b=SKpvMmek; arc=pass ("microsoft.com:s=arcselector10001:i=1"); dmarc=pass (policy=reject) header.from=ericsson.com; spf=pass (mx.ietf.org: domain of john.mattsson@ericsson.com designates 2a01:111:f403:c20a::7 as permitted sender) smtp.mailfrom=john.mattsson@ericsson.com
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=tYcpdxhD9aqFmhL9Vi1PiYSUZuj4iCHZ7DISu+1FvQJhIOY8NIylcSFf6FiC9Sdd3jkIR6ayIwiq9xNAiVLbMuybCer91fZfVryJoLth9Y+QY7mMTLpYTaBdcZVfvBGc1SOzYYiZiqSIgcysR8ayLqj0N6ZcayrTkEZg0q9hG6/7VwvvBAH1T4asMnwks6+mr5UMnpdFZ7SsTp8SGtEnf5xVa/g+zs3KvU5kiWWkswMbTgFLek2GkHawUMM3EPDq+XUTEuvwZKkLLJtmwX4TTflpT+ni8Rx0gT9qlv5DavucbCr/DSafxsDfKRrObxmYzx9ptDRH3WfCkhs12EbgsA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=xo4RCE4lgHSGpxuYAvKsYhnALvhaw0pb9r8uq7dW5FU=; b=XIvXgmvOf9PpZGGCh6uRq8U38PS7I9SXdGPI5LYstBON2CeKsmlPebl1lbTHKzWxmUKMdGRptW2ue/X5W1Kb7Hgsys1f33nkLErNp2tDdGD9zx0tTn39b6TaWo6zwNEQgKrftGEIQ5cZaqXEWa9pQ6mLSebuyKJ2hlg7mfQf5BWRUc9I9FheXRODE+gOxXBrbdCXKV18zJE4r45zh32KCDcyKW6ulEMOYBis79tWSbPAItRUcdZoxt5p1yRVYj/pQOXw17UWohPyeIq671q7bAvpID0pdcVUCk9zwO+pbGNThLxcMxapaaYPBBiTd+4RramD8nQcj/8VFKNf4CFxgg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xo4RCE4lgHSGpxuYAvKsYhnALvhaw0pb9r8uq7dW5FU=; b=SKpvMmekP7gjuByUgtTjFUtNCtOMiHcsFSPNUK1cTr+htKNsUgwcOW5/7FZTvIi86OUPtxdvVKzYi9yDYjs7egDqJ4xtUIbpfP3Sw9/Fk1JhTTPmsbbF3FqsYVG4zOQIgtOMIo+4dj10M6Ix0g67IEPW6ClgmVk4b0RQZuxqLlKvqpr8oMCutkE01ItwOlFQvRD5m2lH5ssAdEdx7bWW09xUPH6Xl7wqivG0gAoYBWSeiqw3wwjsleI5ByqLZvQGbi8dOze8m4OAohHJbJcwnGWqjPNlXcBlkYzNNoQAZCyslkOwQ99mkG9JtWvx0HoTxtS1Ui+BiorE+aw1uNyEBQ==
Received: from AS4PR07MB8825.eurprd07.prod.outlook.com (2603:10a6:20b:4f3::15) by DB8PR07MB6268.eurprd07.prod.outlook.com (2603:10a6:10:13c::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.428.12; Thu, 17 Sep 2026 08:00:02 +0000
Received: from AS4PR07MB8825.eurprd07.prod.outlook.com ([fe80::11a4:5f37:fa92:f174]) by AS4PR07MB8825.eurprd07.prod.outlook.com ([fe80::11a4:5f37:fa92:f174%6]) with mapi id 15.21.0428.009; Thu, 17 Sep 2026 08:00:01 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: 赵运磊 <ylzhao=40fudan.edu.cn@dmarc.ietf.org>, lake <lake@ietf.org>, CFRG <cfrg@irtf.org>
Thread-Topic: [Lake] Re: Request for standardized lightweight quantum-resistant key exchange (on behalf LAKE WG)
Thread-Index: AQHdRlcXRW4btPckfkiqCnJ3/6C0eLbSZs17
Date: Thu, 17 Sep 2026 08:00:01 +0000
Message-ID: <AS4PR07MB8825751F246FCA596D025E4389B82@AS4PR07MB8825.eurprd07.prod.outlook.com>
References: <CAD2CPUGyFPq5Uq5rdb=zHcv_Su96vJXWv17maCVYMo4kRQoLKg@mail.gmail.com> <499787c.bae1.1a0ad771c20.Coremail.ylzhao@fudan.edu.cn>
In-Reply-To: <499787c.bae1.1a0ad771c20.Coremail.ylzhao@fudan.edu.cn>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: AS4PR07MB8825:EE_|DB8PR07MB6268:EE_
x-ms-office365-filtering-correlation-id: 8979e31f-9579-4fe5-7de1-08df1491ad09
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|23010399003|1800799024|376014|366016|13003099007|38070700021|3023799007|10067099003|4143699003|56012099006|11063799006|18002099003|22082099003|8096899003;
x-microsoft-antispam-message-info: +NtkP7orjKQ5ji2k5V/+EB2K9x/pu3LuEznx1/NsmkuiXIJnS7jfHHtXwP8BwgQQfkpY1UYzVfhoGz3/onXyFpi7YwMMzTxyOyjs235KX2pFpk83v3IA+245x09ksmwQ9aPcGEoJG333zRJbUlwTCoxiisiyZ1lQN9vXqr6DBg6zH7Zb+avwQu7E+/sufaHK6oLHR4lUqfLzAQmfyhwLTxe9zRQxzMEhklrd/TUHcj+PZZkgcx04tLW8spOmPE4xnnJrBU2a4kgebUbjuZfpfh4oQAqLKUWcMIZf63W8Dvil2VjQd/DTwD8D9V4yjtYR0EzzjIuAMb+oLNXks19nG8e3q1R8x0tu4bI5r7d2GdvJTAGTrOM4WTKbUH0kIb7RjwxafuQt9jnsiDxgfb6NnzGFa0srUAwDGc4sGMZLkb1Q4VGsVF6w2NTotmxZBV580tS6W7fC6GhY9halFMllo9qMvRefLrzZmTCz50K3CU7vwU4+fY58VMRiUSIZNM15aNPnA4NBSzDP4PvN8P3F1O+qHtExzUxoUmK0Oh2IOQPYZedTgYRelLmZlVwDxZHl18Z6i3pe49SaY73fpziWDOgrquAobc+/HultV7ghAimmF6Lg2+dGh3aw78DgZYLg5sMe1ug4ND72CYM2PTdJPoyKtVr8RH2ioZa6hBSuyLM=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS4PR07MB8825.eurprd07.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(1800799024)(376014)(366016)(13003099007)(38070700021)(3023799007)(10067099003)(4143699003)(56012099006)(11063799006)(18002099003)(22082099003)(8096899003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 4usKwso8fHdEqpWPxlJkFrZhgzEx4u0su8zHsM1Tu8enukHTJl4nzNsRLw5Ez9U9H4LSNK/cc9RiPzD7Btm0onvf9dgvPM9MBEpeuVlE2r/nWHaIGqoqCGuT/K45mbP/1JJuKyB+BIWYh8qI+YnuXux73p7/s604FWvxECJOg3mPHGcKiTZjREQw8Jy+GVlH54qhG1Ws63Pw6NbXIW9bD216CHLL/itfMbTdR7lpA1aYlMBJ7ZcjSRFLZK9DZ+4hueeH7JUZbJYLvwH3HkJu84xRW31uKT1Gxfru5A7lWNXzF6ThMY7KMoMiLOuiCu+2Fsvx7EC2CTsUvkPycdfgIufymkfPKyVW8Q+hSra3ddFr8S5P7Z3uOifPiHnAyn8rnwxMKZKvTP+ARkUJ4NnjoLc7N8657GntcAb4BhQ7P6IJNRkA1K4GNxo8HRxRFDBs1d4pdUkEKkhZTkszAYLkIOnRP6XO81DVoMyuq30d/wct2ujxhb/5qzMixUqhi2sSneBQtJscdbZ5vuMUZ0yO2qpsUuzMisHGzpX+SPM8w83oWpkyLwljkbJ9GUhnVh7nS/6r9ZXsG7weahV0XGE8ftRlsze6N4WE+VZhhBOie2jzB4fm5cE8iYHksQJlBBVcQ/c3i6EvfpfWZle1j2I8Rso5j2o9NNKsraQqdEk6Tfx6PPIHkKthz8dWi4fh2WOFQ+LBUo8nLN0cDKavaXzu3y452HZmxzWNztKOOypKqazRsuUKP2Xwf2/IpADMBmBjqCmlhwPrhh3LLoJHWffJmgNuJiZ9SKs0PGofd+hte9e93In5kJ2+QFdnCHA61zmjY0XqepsIj8OgSnP7x9B6rb3BiDp8deulyYdW4QnOgakJaLy0tFLTRNLl8vJ9ooqjytmrx6NvSJv2QNiujYwz6OyplX/1moOMCdJ//nyh6TG2V/fC7l1YHUxPpQoTLOKLkwuhaai8Rsj2qIRDj6M5V1eVsA0LBQd3O8srS5EaccJ0aB3rFhHlswChhhYwy7scUGCxs9JQe4DBNVz/1j6X5/tM+NhYXpxmroo2YP/d7PiGDhnrsP0l3x8x3FH9tEIzFz9C/DgSi4vMfYb40fkG1/XyhneOAjIcjXEFoNOk5O+lEgGwvQ0BXAU67wsZjKDxXN+XJzXETZFEhoNWOq76ziZyZoog1Wz5KD7wNX21B595TCOMeT/cDjowjXvrGB9EWZyYMg4WKHAERXrIe06ikDMtmgG/0zJqBKKT9Qfn+dvmXTQ4sUiKGqNC+BhReMnj3olda4GS/Gu3CdgyoW6hw3VGBZaIgXnbgMuWhu/NhGtsqm0FvMFiPGvCZAHNmjIZUu9a27dSSgJ7Y3At+hHzUuhZVu3ZwaGvDz1LuYR00QN66ihBnmQEbwGf3AuCnakAN/OyvmkD1weDTsIBUlOhR675UYMafgPwbn35Nr485M5/RbOWkAVtHReWkMcW2ZjY3I9MaaSgm9YFd/h21w6s1U9hIUNQCRoAy3Sbc4bfzQvxnfSco5RvnvTTmLv2rbLCkaeVSTYpcs/k2c4mt3VSIAFN5f8J3bM9IFIDsPVaA6/S4MXAbFK7XhbMSkzJptWRbVDT/0h6Qj+d8zN68eCSdJuYX0Lr7gsMOnxjczZa61o1zdGpRWxbpT6Fq4P676UDZX4BkybXhivOCVBYaxFVqd+qjZ8RZiqEk+m4LSieGovWOr2C4jAz1V8DBEdtOMqsZa3Bf4jA50EohMFS4ILuhpfv0J7CK6VL6Zmsk8njddkIANs5rZQpDJp1khpTfcnk
Content-Type: multipart/alternative; boundary="_000_AS4PR07MB8825751F246FCA596D025E4389B82AS4PR07MB8825eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AS4PR07MB8825.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8979e31f-9579-4fe5-7de1-08df1491ad09
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Sep 2026 08:00:01.5211 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ywafyuGyuSRK8sqBGjkwzy/B99p6+/D3Bwv+cy+5gi1xG8FBC03TDh9L2armFjiEQJDYAptq6PzgO193MiIpFgyy7eLmYmkN+OT4Y0KrKC8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB8PR07MB6268
X-Spamd-Bar: -
Message-ID-Hash: GPPRVTYKNIJHWHQUHJVOZ6IJTJANKNNY
X-Message-ID-Hash: GPPRVTYKNIJHWHQUHJVOZ6IJTJANKNNY
X-MailFrom: john.mattsson@ericsson.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Lake] Re: Request for standardized lightweight quantum-resistant key exchange (on behalf LAKE WG)
List-Id: Lightweight Authenticated Key Exchange <lake.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/lake/3s8S84-eXRbooQrrYNELKUKQF8E>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lake>
List-Help: <mailto:lake-request@ietf.org?subject=help>
List-Owner: <mailto:lake-owner@ietf.org>
List-Post: <mailto:lake@ietf.org>
List-Subscribe: <mailto:lake-join@ietf.org>
List-Unsubscribe: <mailto:lake-leave@ietf.org>
Hi Yunlei, Please don’t spam so many IETF lists. LAKE WG has already discussed KEM-based authentication quite extensively for several years and has adopted the following draft. https://datatracker.ietf.org/doc/draft-ietf-lake-authkem-edhoc/ Given this, it is somewhat surprising that LAKE is not mentioned in your paper. To my knowledge, it is currently the only active standardization effort of KEM-based authentication. >a suggested solution is as follows: First, using ECDH to setup communication encryption key $EK$, due to the MTU limitation of the first two rounds of IKE. Then, using $EK$ to protect the first two rounds of AFS-KEX. Compared to using ML-KEM and MS-DSA, this could reduce about 80% communication bandwidth. I don't think LAKE is interested in quantum-vulnerable ECDH, and LAKE is not IPsec. Moreover, setting up an encrypted channel and then performing KEM-based authentication is not a new idea. Could you send an overview explaining whether any of the ideas in your paper could be used to improve the LAKE protocol, and in particular draft-ietf-lake-authkem-edhoc, without changing its underlying assumptions? It would be helpful to understand what is genuinely new and, importantly, what is actually applicable to LAKE. My high-level understanding is that the main contribution of your paper is to achieve mutually authenticated key exchange with ML-KEM-based authentication using fewer flights, smaller messages, and less computation, by exploiting the additive structure of ML-KEM. A few questions: * Does your approach preserve all the security properties of draft-ietf-lake-authkem-edhoc? * Can it be implemented using a standard ML-KEM API, or does it require access to ML-KEM's internal algebraic structure? * Is the approach specific to ML-KEM, or can the same technique be applied to other KEMs? * Are there any additional requirements or assumptions that must be satisfied before initiating the AKE? Cheers, John Preuß Mattsson From: 赵运磊 <ylzhao=40fudan.edu.cn@dmarc.ietf.org> Date: Thursday, 17 September 2026 at 05:46 To: Renzo Navas <renzoefra@gmail.com> Cc: cfrg@irtf.org <cfrg@irtf.org>; lake <lake@ietf.org>; pqc@ietf.org <pqc@ietf.org>; cose <cose@ietf.org>; ace <Ace@ietf.org> Subject: [Lake] Re: Request for standardized lightweight quantum-resistant key exchange (on behalf LAKE WG) Some people who received this message don't often get email from ylzhao=40fudan.edu.cn@dmarc.ietf.org. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> Dear All: I am Yunlei from Fudan university, Shanghai. I would draw your kind attention on our recently published paper:Post-Quantum Internet Key Exchange via Authenticated Forward-Secure KEM (named AFS-KEX), which is available from: https://eprint.iacr.org/2026/1581 In this work, we present a novel AKE construction from KEM without using signature: more compact, more efficient, more secure against state exposure. We hope this work is applicable to LAKE and post-quantum IKE. With a brief study, a suggested solution is as follows: First, using ECDH to setup communication encryption key $EK$, due to the MTU limitation of the first two rounds of IKE. Then, using $EK$ to protect the first two rounds of AFS-KEX. Compared to using ML-KEM and MS-DSA, this could reduce about 80% communication bandwidth. Best regards Yunlei -----原始郵件----- 發件人: "Renzo Navas" <renzoefra@gmail.com> 發送時間: 2026-09-13 17:52:46 (星期日) 收件人: cfrg@irtf.org 抄送: lake <lake@ietf.org>, pqc@ietf.org, cose <cose@ietf.org>, ace <Ace@ietf.org> 主題: [Lake] Request for standardized lightweight quantum-resistant key exchange (on behalf LAKE WG) Dear CFRG, The LAKE working group is chartered to work on a lightweight mutually authenticated key exchange protocol targeting constrained network environments such as NB-IoT, 6TiSCH, LoRaWAN, IEEE 802.15.4, and BLE. The base LAKE/EDHOC protocol (RFC 9528) is now being updated for the post-quantum setting [1]. In March 2026, the LAKE working group formed a post-quantum Design Team (DT) scoped to evaluate the constrained network scenarios where a quantum-resistant variant of LAKE is realistically deployable. DT identified that the resulting large message sizes due to current PQC algorithms are not well suited for the most constrained IoT environments [2]. At the same time, constrained IoT systems also need to migrate to post-quantum cryptography. LAKE kindly requests CFRG to consider research and specification of lightweight quantum-resistant key exchange algorithms. 1. As shown in the analysis [2], a non-interactive key exchange (NIKE)-based approach to quantum-resistant LAKE could reduce the message size of a mutually authenticated AKE compared to KEM-based approaches, which is particularly beneficial for constrained IoT deployments. In particular, the specification of a lightweight NIKE, such as CTIDH and MIKE, would allow, for example, the deployment of quantum-resistant LAKE in network environments with Maximum Transmission Unit (MTU) of up to 127 bytes (classes S1/S2 [3]). 2. The specification of more optimized KEMs, such as lattice-based KEMs (e.g., BAT and DAWN) would also reduce the message sizes, making quantum-resistant LAKE more efficiently deployable in these constrained settings. LAKE would be happy to provide further input on this topic and to evaluate candidate proposals from a performance point of view. Kind regards, Renzo Navas on behalf of the LAKE WG P.S.: I cross-post this to some WGs that might be interested in this information. [1] https://datatracker.ietf.org/doc/draft-ietf-lake-pqsuites/ [2] https://datatracker.ietf.org/meeting/126/materials/slides-126-lake-08-pq-edhoc-dt-summary-ietf126presentation-00 [3] https://datatracker.ietf.org/doc/draft-ietf-iotops-7228bis/
- [Lake] Request for standardized lightweight quant… Renzo Navas
- [Lake] Re: Request for standardized lightweight q… 赵运磊
- [Lake] Re: [EXT] [COSE] Re: Request for standardi… Blumenthal, Uri - 0553 - MITLL
- [Lake] Re: [EXT] [COSE] Re: Request for standardi… 赵运磊
- [Lake] Re: [Pqc] Re: Re: [EXT] [COSE] Re: Request… Metz, Bobby
- [Lake] Re: [Pqc] Re: Re: [EXT] [COSE] Re: Request… 赵运磊
- [Lake] Re: Request for standardized lightweight q… John Mattsson
- [Lake] Re: Request for standardized lightweight q… 赵运磊
- [Lake] Re: Request for standardized lightweight q… 赵运磊
- [Lake] Re: Request for standardized lightweight q… 赵运磊
- [Lake] 答复: [CFRG] Re: Re: Request for standardize… Niu Danny