Mixing Preshared Keys in the IKE_INTERMEDIATE and CREATE_CHILD_SA Exchanges of the Internet Key Exchange Protocol Version 2 for Post-Quantum Security
RFC 9867, “Mixing Preshared Keys in the IKE_INTERMEDIATE and CREATE_CHILD_SA Exchanges of the Internet Key Exchange Protocol Version 2 for Post-Quantum Security”, is a Proposed Standard document published in November 2025 by V. Smyslov. The canonical text is published by the RFC Editor.
Abstract
An Internet Key Exchange Protocol Version 2 (IKEv2) extension defined in RFC 8784 allows IPsec traffic to be protected against someone storing VPN communications and decrypting them later, when (and if) a Cryptographically Relevant Quantum Computer (CRQC) is available. The protection is achieved by means of a Post-quantum Preshared Key (PPK) that is mixed into the session keys calculation. However, this protection does not cover an initial IKEv2 Security Association (SA), which might be unacceptable in some scenarios. This specification defines an alternative way to provide protection against quantum computers, which is similar to the solution defined in RFC 8784, but it also protects the initial IKEv2 SA.
RFC 8784 assumes that PPKs are static and thus they are only used when an initial IKEv2 SA is created. If a fresh PPK is available before the IKE SA expires, then the only way to use it is to delete the current IKE SA and create a new one from scratch, which is inefficient. This specification defines a way to use PPKs in active IKEv2 SAs for creating additional IPsec SAs and rekey operations.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9867 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9866 Root Node Failure Detector : Fast Detection of Border Router Crashes in the Routing Protocol for Low-Power and Lossy Networks
- RFC 9868 Transport Options for UDP
- RFC 9865 Cursor-Based Pagination of System of Cross-domain Identity Management Resources
- RFC 9869 Datagram Packetization Layer Path MTU Discovery for UDP Options
- RFC 9864 Fully-Specified Algorithms for JSON Object Signing and Encryption and CBOR Object Signing and Encryption
- RFC 9870 Export of UDP Options Information in IP Flow Information Export
- RFC 9863 Path Computation Element Protocol Extension for Color
- RFC 9871 BGP Color-Aware Routing