From the draft:
“This document specifies extensions to the Kerberos PKINIT pre-authentication mechanism [RFC4556] [RFC8636] to support post-quantum key establishment using the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) algorithms defined in [FIPS203].
The extensions define a new kemInfo arm in PA-PK-AS-REP, a KDCKEMInfo structure signed by the KDC, HKDF-based AS reply key derivation (HKDF-SHA-512 for ML-KEM), downgrade-prevention rules, and a PAChecksum2 extension providing checksum algorithm agility in PKAuthenticator. The KEM path framework supports multiple KEM algorithms including ML-KEM, composite ML-KEM algorithms, and future KEM standards. […]”
Commented on by project QARC also here:
https://www.linkedin.com/posts/pqc-eccc-horizoneurope-share-7471084738410303489-hLVS
- Read more and origin of text: https://www.ietf.org/archive/id/draft-bokovoy-kitten-pkinit-pqc-00.html
- Foto von Markus Winkler auf Unsplash