Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 for Post-quantum Security
RFC 8784, “Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 for Post-quantum Security”, is a Proposed Standard document published in June 2020 by S. Fluhrer, P. Kampanakis, D. McGrew, V. Smyslov. The canonical text is published by the RFC Editor.
Abstract
The possibility of quantum computers poses a serious challenge to cryptographic algorithms deployed widely today. The Internet Key Exchange Protocol Version 2 (IKEv2) is one example of a cryptosystem that could be broken; someone storing VPN communications today could decrypt them at a later time when a quantum computer is available. It is anticipated that IKEv2 will be extended to support quantum-secure key exchange algorithms; however, that is not likely to happen in the near term. To address this problem before then, this document describes an extension of IKEv2 to allow it to be resistant to a quantum computer by using preshared keys.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8784 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8783 Distributed Denial-of-Service Open Threat Signaling Data Channel Specification
- RFC 8785 JSON Canonicalization Scheme
- RFC 8782 Distributed Denial-of-Service Open Threat Signaling Signal Channel Specification
- RFC 8786 Updated Rules for Processing Stateful PCE Request Parameters Flags
- RFC 8781 Discovering PREF64 in Router Advertisements
- RFC 8787 Location Source Parameter for the SIP Geolocation Header Field
- RFC 8780 The Path Computation Element Communication Protocol Extension for Wavelength Switched Optical Network Routing and Wavelength Assignment
- RFC 8788 Eligibility for the 2020-2021 Nominating Committee