<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.hu-ipsecme-pqt-hybrid-auth" target="https://datatracker.ietf.org/doc/html/draft-hu-ipsecme-pqt-hybrid-auth-04">
   <front>
      <title>Post-Quantum Traditional (PQ/T) Hybrid PKI Authentication in the Internet Key Exchange Version 2 (IKEv2)</title>
      <author initials="J." surname="Hu" fullname="Jun Hu">
         <organization>Nokia</organization>
      </author>
      <author initials="Y." surname="Morioka" fullname="Yasufumi Morioka">
         <organization>NTT DOCOMO, INC.</organization>
      </author>
      <author initials="G." surname="WANG" fullname="Guilin WANG">
         <organization>Huawei</organization>
      </author>
      <date month="February" day="27" year="2026" />
      <abstract>
	 <t>   One IPsec area that would be impacted by Cryptographically Relevant
   Quantum Computer (CRQC) is IKEv2 authentication based on traditional
   asymmetric cryptographic algorithms: e.g RSA, ECDSA, which are widely
   deployed authentication options of IKEv2.  There are new Post-Quantum
   Cryptographic (PQC) algorithms for digital signature like NIST
   [ML-DSA], However, it takes time for new cryptographic algorithms to
   mature, There is security risk to use only the new algorithm before
   it is field proven.  This document describes a hybrid PKI
   authentication scheme for IKEv2 that incorporates both traditional
   and PQC digital signature algorithms, so that authentication is
   secure as long as one algorithm in the hybrid scheme is secure.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-hu-ipsecme-pqt-hybrid-auth-04" />
   
</reference>
