Skip to main content

Signature Authentication in the Internet Key Exchange Version 2 (IKEv2) using PQC
draft-reddy-ipsecme-ikev2-pqc-auth-04

Document Type Replaced Internet-Draft (ipsecme WG)
Expired & archived
Authors Tirumaleswar Reddy.K , Valery Smyslov , Scott Fluhrer
Last updated 2025-03-13 (Latest revision 2025-02-10)
Replaced by draft-ietf-ipsecme-ikev2-pqc-auth
RFC stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Formats
Additional resources Mailing list discussion
Stream WG state Adopted by a WG
Document shepherd (None)
IESG IESG state Replaced by draft-ietf-ipsecme-ikev2-pqc-auth
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Signature-based authentication methods are utilized in IKEv2 [RFC7296]. The current version of the Internet Key Exchange Version 2 (IKEv2) protocol supports traditional digital signatures. This document outlines how post-quantum digital signatures, specifically Module-Lattice-Based Digital Signatures (ML-DSA) and Stateless Hash-Based Digital Signatures (SLH-DSA), can be employed as authentication methods within the IKEv2 protocol. It introduces ML- DSA and SLH-DSA capability to IKEv2 without necessitating any alterations to existing IKE operations.

Authors

Tirumaleswar Reddy.K
Valery Smyslov
Scott Fluhrer

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)