[TLS] FW: New Version Notification for draft-wang-tls-hybrid-ecdh-scloud-01.txt
Wang Guilin <Wang.Guilin@huawei.com> Wed, 18 February 2026 14:53 UTC
Return-Path: <Wang.Guilin@huawei.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 44C6EB950E33; Wed, 18 Feb 2026 06:53:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.196
X-Spam-Level:
X-Spam-Status: No, score=-4.196 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dzqjuRFE1QAE; Wed, 18 Feb 2026 06:53:33 -0800 (PST)
Received: from frasgout.his.huawei.com (frasgout.his.huawei.com [185.176.79.56]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 051FAB950E28; Wed, 18 Feb 2026 06:53:33 -0800 (PST)
Received: from mail.maildlp.com (unknown [172.18.224.83]) by frasgout.his.huawei.com (SkyGuard) with ESMTPS id 4fGKJG0gG9zJ46D6; Wed, 18 Feb 2026 22:53:18 +0800 (CST)
Received: from kwepemh500011.china.huawei.com (unknown [7.202.181.142]) by mail.maildlp.com (Postfix) with ESMTPS id C2E1B40086; Wed, 18 Feb 2026 22:53:29 +0800 (CST)
Received: from sinpeml100009.china.huawei.com (7.188.194.204) by kwepemh500011.china.huawei.com (7.202.181.142) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 18 Feb 2026 22:53:27 +0800
Received: from sinpeml500009.china.huawei.com (7.188.194.209) by sinpeml100009.china.huawei.com (7.188.194.204) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.36; Wed, 18 Feb 2026 22:53:27 +0800
Received: from sinpeml500009.china.huawei.com ([7.188.194.209]) by sinpeml500009.china.huawei.com ([7.188.194.209]) with mapi id 15.02.1544.011; Wed, 18 Feb 2026 22:53:26 +0800
From: Wang Guilin <Wang.Guilin@huawei.com>
To: "tls-chairs@ietf.org" <tls-chairs@ietf.org>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] FW: New Version Notification for draft-wang-tls-hybrid-ecdh-scloud-01.txt
Thread-Index: Adyg5cVg9/CZLi7tSjqCht1S6c3Y1w==
Date: Wed, 18 Feb 2026 14:53:26 +0000
Message-ID: <b358d90010994d08a5b89f5387cfcb87@huawei.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.47.120.114]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Message-ID-Hash: JJQNPHEBULR3GDT3X67HKJQD3VXG53OP
X-Message-ID-Hash: JJQNPHEBULR3GDT3X67HKJQD3VXG53OP
X-MailFrom: Wang.Guilin@huawei.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Anyu Wang <anyuwang@tsinghua.edu.cn>, Wang Guilin <Wang.Guilin@huawei.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] FW: New Version Notification for draft-wang-tls-hybrid-ecdh-scloud-01.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/zDGZ66-aXexj3ot6T9J8Tf5IqcQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Dear all, We have submitted a new draft on hybrid key exchange in TLS. This draft specifies how to instantiate hybrid key exchange in TLS 1.3 using ECDHE and SCloud+, a PQ KEM proposed in 2024. SCloud+ is based on the unstructured LWE problem with improved performance. The absence of algebraic structure in such KEMs presumes a higher level of security than for algorithms based on structured lattices. So, the hybrid of ECDHE and SCloud+ may serve as a conservative option for high-security applications using TLS 1.3. Your comments and review are welcome! Thanks, Guilin and Anyu -----Original Message----- From: internet-drafts@ietf.org <internet-drafts@ietf.org> Sent: Monday, 16 February 2026 9:39 pm To: Anyu Wang <anyuwang@tsinghua.edu.cn>; Wang Guilin <Wang.Guilin@huawei.com>; Wang Guilin <Wang.Guilin@huawei.com> Subject: New Version Notification for draft-wang-tls-hybrid-ecdh-scloud-01.txt A new version of Internet-Draft draft-wang-tls-hybrid-ecdh-scloud-01.txt has been successfully submitted by Guilin Wang and posted to the IETF repository. Name: draft-wang-tls-hybrid-ecdh-scloud Revision: 01 Title: Post-quantum Hybrid ECDHE-SCloud+ Key Exchange for TLS 1.3 Date: 2026-02-16 Group: Individual Submission Pages: 12 URL: https://www.ietf.org/archive/id/draft-wang-tls-hybrid-ecdh-scloud-01.txt Status: https://datatracker.ietf.org/doc/draft-wang-tls-hybrid-ecdh-scloud/ HTML: https://www.ietf.org/archive/id/draft-wang-tls-hybrid-ecdh-scloud-01.html HTMLized: https://datatracker.ietf.org/doc/html/draft-wang-tls-hybrid-ecdh-scloud Diff: https://author-tools.ietf.org/iddiff?url2=draft-wang-tls-hybrid-ecdh-scloud-01 Abstract: This draft specifies how to enable hybrid key exchange with ECDHE and SCloud+ in Transport Layer Security protocol version 1.3 (TLS 1.3) to mitigate quantum threats. SCloud+ is an unstructured lattice based KEM (key encapsulation mechanism) with post-quantum security. This draft follows the post-quantum hybrid key exchange framework specified by [TLS.Hybrid], by concatenating the public keys and ciphertexts of ECDHE and SCloud+. Three concrete hybrid key exchange schemes are specified in this draft, which are X25519SCloud+128, SecP256r1SCloud+192 and SecP384r1SCloud+256. [EDNOTE: ... ] The IETF Secretariat