Hi Panos,

thanks for addressing my comment. It looks good.

One nit. In the introduction, first paragraph, the last sentence seems to be 
broken:
“This includes Internet Key Exchange Protocol Version 2 (IKEv2, which the 
security is based on using the (EC)DH key exchange in the IKE_SA_INIT messages”

By the way, I’m fine with not adding ML-KEM-512 to the document, but I won’t 
object either.

Leonie


Von: Kampanakis, Panos <kpa...@amazon.com>
Gesendet: Dienstag, 20. Februar 2024 05:25
An: Bruckert, Leonie <leonie.bruck...@secunet.com>; ipsec@ietf.org
Cc: Ravago, Gerardo <g...@amazon.com>
Betreff: RE: [IPsec] Comment on draft-kampanakis-ml-kem-ikev2


Hi Leonie,

I am circling back. I updated the terminology in the just submitted the -02 
version. https://datatracker.ietf.org/doc/html/draft-kampanakis-ml-kem-ikev2-02



Thank you for the suggestion about draft-ietf-pquip-pqt-hybrid-terminology.



Hopefully IPSECME will discuss this draft in Brisbane.



From: IPsec <ipsec-boun...@ietf.org<mailto:ipsec-boun...@ietf.org>> On Behalf 
Of Bruckert, Leonie
Sent: Tuesday, January 30, 2024 6:40 AM
To: ipsec@ietf.org<mailto:ipsec@ietf.org>
Subject: [EXTERNAL] [IPsec] Comment on draft-kampanakis-ml-kem-ikev2


CAUTION: This email originated from outside of the organization. Do not click 
links or open attachments unless you can confirm the sender and know the 
content is safe.


Thanks for setting up this draft!

Have you considered to align terminology with 
draft-ietf-pquip-pqt-hybrid-terminology? It defines a “PQ/T Hybrid Key 
Encapsulation Mechanism” as a “multi-algorithm KEM made up of two or more 
component KEM algorithms where at least one is a post-quantum algorithm and at 
least one is a traditional algorithm“. This definition may not perfectly match 
how a hybrid KEM is done in IKEv2 as it is a sequential approach. However, I 
think it would be good to have a reference to the terminology draft.

Leonie

_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to