Investigating the Quantum Safe Migration of IETF protocol suite

133 views
Skip to first unread message

Mohit Rai

unread,
Jul 26, 2026, 10:40:27 AM (2 days ago) Jul 26
to pqc-forum
Hello Everyone,

My name is Mohit and I am working on my thesis, titled as "Investigating the Quantum Safe Migration of IETF protocol suite". In that, I intend to review the IETF protocols and the work done in full Post-quantum Migration & Partial/Hybrid Migration and implement one specified protocol in using a Hybrid (Only Key Exchange KEMs and/or signature algorithms), as per the gap identified

I have currently reviewed the IETF drafts and/or separate  on SSH, IPSEC, TLS, QUIC, MIME, etc. A lot of them have most been transitioned to Post-quantum using a Hybrid approach. I and humbly requesting help in identifying/researching protocols, where full or Hybrid Post-quantum transitions, is still in process or has not happened yet. Accordingly frameworks in which they can be implemented, would also be really helpful.

Anything, in this predicament would of great value. looking forward to your response.

Regards
Mohit

Q R

unread,
Jul 26, 2026, 12:16:02 PM (2 days ago) Jul 26
to Mohit Rai, pqc-forum

--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/fbeba0ac-38ef-4af6-be65-cda8f0a72956n%40list.nist.gov.

John Mattsson

unread,
Jul 26, 2026, 4:42:00 PM (2 days ago) Jul 26
to Mohit Rai, pqc-forum
Hi Mohit,

>I have currently reviewed the IETF drafts and/or separate  on SSH, IPSEC, TLS, QUIC, MIME, etc. A lot of them have most been transitioned to Post-quantum using a Hybrid approach.

I think it is important to distinguish between key exchange and digital signatures, as well as between protocol specifications and real-world deployments.

While IETF recommends hybrids for key exchange, that will likely not be the case for signatures. The Web is e.g., expected to use hybrid key exchange (X25519MLKEM768) together with standalone authentication (ML-DSA-44), which I think is a very sensible approach.

In practice, the right choice depends heavily on the use case, the protocol, the migration timeline, and your assessment of when a cryptographically relevant quantum computer (CRQC) will become available.

A good general recommendation is to use things that are already widely deployed whenever possible, as this maximizes implementation maturity. Conversely, if you believe nation-state adversaries will have access to CRQCs as early as 2029, deploying PQ/T hybrids now provide little benefit and merely consume additional bandwidth, computation, and implementation complexity.

From a specification perspective, the most mature area is standalone signatures in X.509

From a deployment perspective, the most mature area is hybrid key exchange, which has already seen significant real-world deployment in TLS and SSH

Standalone post-quantum key exchange is somewhat less mature, while hybrid signatures remain the least mature.

>I and humbly requesting help in identifying/researching protocols, where full or Hybrid Post-quantum transitions, is still in process or has not happened yet.

I do not think any IETF protocol has fully migrated to PQC yet, that will likely take until 2035 or beyond.

One interesting protocol is LAKE, which defines a lightweight authenticated key exchange (AKE) protocol for constrained devices and low-bandwidth radio networks. More broadly, the IoT ecosystem encompasses a wide variety of deployment scenarios, each with very different resource constraints. The size of ML-KEM and ML-DSA is a significant challenge for many constrained environments. LAKE has recently been rechartered to address post-quantum migration. In addition to signature-based authentication, the working group has adopted work on KEM-based authentication. It has also identified the lack of lightweight post-quantum KEMs and NIKEs (non-interactive key exchange schemes) as a key challenge, and plans to ask CFRG to consider the specification of suitable lightweight post-quantum key exchange algorithms. (LAKE has already standardized NIKE based authentication).

Another interesting protocol is MIKEY-SAKKE, which uses identity-based cryptography and currently has no straightforward migration path to post-quantum cryptography.

Cheers,
John Preuß Mattsson

From: pqc-...@list.nist.gov <pqc-...@list.nist.gov> on behalf of Mohit Rai <raimo...@gmail.com>
Date: Sunday, 26 July 2026 at 16:40
To: pqc-forum <pqc-...@list.nist.gov>
Subject: [pqc-forum] Investigating the Quantum Safe Migration of IETF protocol suite

You don't often get email from raimo...@gmail.com. Learn why this is important

Demi Marie Obenour

unread,
Jul 26, 2026, 5:13:35 PM (2 days ago) Jul 26
to Mohit Rai, pqc-forum
DNSSEC is going to struggle. The records being signed are small compared to the signatures, and the core DNS infrastructure uses UDP with its 1232-byte limit. SQIsign is far too slow, and the other algorithms (except, possibly, FN-DSA-512) have too large signatures and public keys.

I suspect the long-term solution involves a significant change to DNS itself, such that security is built-in from the beginning rather than being bolted on after the fact.
--
Sincerely,
Demi Marie Obenour (she/her/hers)
OpenPGP_signature.asc
Reply all
Reply to author
Forward
0 new messages