Using Pre-Shared Key in the Cryptographic Message Syntax
RFC 8696, “Using Pre-Shared Key in the Cryptographic Message Syntax”, is a Proposed Standard document published in December 2019 by R. Housley. The canonical text is published by the RFC Editor.
Abstract
The invention of a large-scale quantum computer would pose a serious challenge for the cryptographic algorithms that are widely deployed today. The Cryptographic Message Syntax (CMS) supports key transport and key agreement algorithms that could be broken by the invention of such a quantum computer. By storing communications that are protected with the CMS today, someone could decrypt them in the future when a large-scale quantum computer becomes available. Once quantum-secure key management algorithms are available, the CMS will be extended to support the new algorithms if the existing syntax does not accommodate them. This document describes a mechanism to protect today's communication from the future invention of a large-scale quantum computer by mixing the output of key transport and key agreement algorithms with a pre-shared key.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8696 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8694 Applicability of the Path Computation Element to Inter-area and Inter-AS MPLS and GMPLS Traffic Engineering
- RFC 8692 Internet X.509 Public Key Infrastructure: Additional Algorithm Identifiers for RSASSA-PSS and ECDSA Using SHAKEs
- RFC 8700 Fifty Years of RFCs
- RFC 8691 Basic Support for IPv6 Networks Operating Outside the Context of a Basic Service Set over IEEE Std 802.11
- RFC 8690 Clarification of Segment ID Sub-TLV Length for RFC 8287
- RFC 8689 SMTP Require TLS Option
- RFC 8688 A Session Initiation Protocol Response Code for Rejected Calls
- RFC 8687 OSPF Routing with Cross-Address Family Traffic Engineering Tunnels