@techreport{usama-tls-risks-of-mlkem-04, number = {draft-usama-tls-risks-of-mlkem-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-usama-tls-risks-of-mlkem/04/}, author = {Muhammad Usama Sardar}, title = {{Analysis of Hybrid Key Establishment and Standalone ML-KEM in TLS 1.3}}, pagetotal = 20, year = 2026, month = jun, day = 21, abstract = {This memo is a work-in-progress and maps out the technical facets relevant to the quantum-resistant key establishment in TLS 1.3 and provides some preliminary discussion to help developers and policymakers make informed choices. In particular, it presents hybrid key establishment and standalone ML-KEM in TLS 1.3. Moreover, it offers minimal implementation guidance for hybrid key establishment. The memo finally presents technical insights into hybrid key establishment and standalone ML-KEM in TLS 1.3. Our observation is that hybrid key establishment is preferable over standalone ML-KEM until a powerful CRQC exists which breaks most bits of pre-quantum. This memo is not a standard nor has it been shown to have consensus of the IETF community.}, }