%% You should probably cite draft-hu-ipsecme-pqt-hybrid-auth-05 instead of this revision. @techreport{hu-ipsecme-pqt-hybrid-auth-04, number = {draft-hu-ipsecme-pqt-hybrid-auth-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hu-ipsecme-pqt-hybrid-auth/04/}, author = {Jun Hu and Yasufumi Morioka and Guilin WANG}, title = {{Post-Quantum Traditional (PQ/T) Hybrid PKI Authentication in the Internet Key Exchange Version 2 (IKEv2)}}, pagetotal = 14, year = , month = , day = , abstract = {One IPsec area that would be impacted by Cryptographically Relevant Quantum Computer (CRQC) is IKEv2 authentication based on traditional asymmetric cryptographic algorithms: e.g RSA, ECDSA, which are widely deployed authentication options of IKEv2. There are new Post-Quantum Cryptographic (PQC) algorithms for digital signature like NIST {[}ML-DSA{]}, However, it takes time for new cryptographic algorithms to mature, There is security risk to use only the new algorithm before it is field proven. This document describes a hybrid PKI authentication scheme for IKEv2 that incorporates both traditional and PQC digital signature algorithms, so that authentication is secure as long as one algorithm in the hybrid scheme is secure.}, }