Use of the RSA-KEM Algorithm in the Cryptographic Message Syntax
RFC 9690, “Use of the RSA-KEM Algorithm in the Cryptographic Message Syntax”, is a Proposed Standard document published in February 2025 by R. Housley, S. Turner. It obsoletes RFC 5990. The canonical text is published by the RFC Editor.
Abstract
The RSA Key Encapsulation Mechanism (RSA-KEM) algorithm is a one-pass (store-and-forward) cryptographic mechanism for an originator to securely send keying material to a recipient using the recipient's RSA public key. The RSA-KEM algorithm is specified in Clause 11.5 of ISO/IEC: 18033-2:2006. This document specifies the conventions for using the RSA-KEM algorithm as a standalone KEM algorithm and the conventions for using the RSA-KEM algorithm with the Cryptographic Message Syntax (CMS) using KEMRecipientInfo as specified in RFC 9629. This document obsoletes RFC 5990.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9690 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9692 RIFT: Routing in Fat Trees
- RFC 9693 Benchmarking Methodology for Stateful NATxy Gateways
- RFC 9694 Guidelines for the Definition of New Top-Level Media Types
- RFC 9695 The 'haptics' Top-Level Media Type
- RFC 9696 Routing in Fat Trees Applicability and Operational Considerations
- RFC 9698 The JMAPACCESS Extension for IMAP
- RFC 9700 Best Current Practice for OAuth 2.0 Security
- RFC 9701 JSON Web Token Response for OAuth Token Introspection