<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.usama-tls-risks-of-mlkem" target="https://datatracker.ietf.org/doc/html/draft-usama-tls-risks-of-mlkem-03">
   <front>
      <title>Analysis of Hybrid Key Exchange and Standalone ML-KEM in TLS 1.3</title>
      <author initials="M. U." surname="Sardar" fullname="Muhammad Usama Sardar">
         <organization>TU Dresden, Germany</organization>
      </author>
      <date month="June" day="11" year="2026" />
      <abstract>
	 <t>   The draft presents _symbolic_ and _computational_ analysis of hybrid
   key exchange and standalone ML-KEM.  In our observation, we believe
   that hybrid key exchange is preferable over standalone ML-KEM until a
   powerful CRQC exists which breaks *all* the bits of pre-quantum.
   This draft also offers opinions of the IETF participants and some
   preliminary discussion to help the developers and policymakers make
   informed choices.  Finally, it offers minimal implementation guidance
   for hybrids.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-usama-tls-risks-of-mlkem-03" />
   
</reference>
