%% You should probably cite draft-ietf-lamps-pq-composite-kem-06 instead of this revision. @techreport{ietf-lamps-pq-composite-kem-05, number = {draft-ietf-lamps-pq-composite-kem-05}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/05/}, author = {Mike Ounsworth and John Gray and Massimiliano Pala and Jan Klaußner and Scott Fluhrer}, title = {{Composite ML-KEM for use in X.509 Public Key Infrastructure and CMS}}, pagetotal = 56, year = , month = , day = , abstract = {This document defines combinations of ML-KEM {[}FIPS.203{]} in hybrid with traditional algorithms RSA-OAEP, ECDH, X25519, and X448. These combinations are tailored to meet security best practices and regulatory requirements. Composite ML-KEM is applicable in any application that uses X.509, PKIX, and CMS data structures and protocols that accept ML-KEM, but where the operator wants extra protection against breaks or catastrophic bugs in ML-KEM. For use within CMS, this document is intended to be coupled with the CMS KEMRecipientInfo mechanism in {[}RFC9629{]}.}, }