Hi Ben,

Thanks for this update.  I prefer the way you have things in the draft now 
(outputs of length 256 and 512 bits respectively), primarily for the 
consistency with HMAC.

Best,
Casey

________________________________
From: Ben S3 <[email protected]>
Sent: Wednesday, September 9, 2026 8:50 AM
To: [email protected] <[email protected]>
Subject: [IPsec] Re: I-D Action: draft-ietf-ipsecme-sha3-02.txt

Hi IPSECME!

This version of the draft contains the following substantive updates:
* We removed the use of SHA-3 as a signature hash function. We received 
feedback expressing a preference for SHAKE over SHA-3 in this context, and we 
believe SHAKE covers all use cases where one might want to use SHA-3.
* The document has been renamed to reflect the fact that it now just specifies 
use of KMAC and SHAKE.
* The document no longer uses customisation strings, instead using the presence 
of the trailing 0x01 byte to provide domain separation between prf and prf+. 
This aligns the document with the latest iteration of 
draft-ietf-ipsecme-ikev2-prf-plus.
* Various corrections/clarifications of key sizes, output lengths, and security 
strengths.

We have (at least) one remaining open question, which we'd be interested in the 
WG's thoughts on:

When used as a PRF, the draft currently specifies an output length of 256 bits 
for KMAC-128 and 512 bits for KMAC-256. This is equal to their respective key 
lengths, and is analogous to what is done with HMAC-SHA256/HMAC-SHA512. We 
mainly took this approach for simplicity.

Now, if IKE does not rely on the collision resistance of PRF (and we believe it 
doesn't), then it would be possible to reduce that output length to 128 and 256 
bits respectively. This would also let us reduce the key sizes down to 128/256 
bits. However, this would mean that any future extension to IKE would need to 
check it doesn't rely on collision resistance, so it might just be simpler to 
match what is done with HMAC-SHA2. Either way, interested in the WG's views on 
this one.

Best,
Ben, Adam, and Jonathan

-----Original Message-----
From: [email protected] <[email protected]>
Sent: 09 September 2026 13:46
To: [email protected]
Cc: [email protected]
Subject: [IPsec] I-D Action: draft-ietf-ipsecme-sha3-02.txt

Internet-Draft draft-ietf-ipsecme-sha3-02.txt is now available. It is a work 
item of the IP Security Maintenance and Extensions (IPSECME) WG of the IETF.

   Title:   Use of KMAC and SHAKE in the Internet Key Exchange Protocol Version 
2 (IKEv2) and IPsec
   Authors: Ben Salter
            Adam Raine
            Jonathan Cruickshanks
   Name:    draft-ietf-ipsecme-sha3-02.txt
   Pages:   26
   Dates:   2026-09-09

Abstract:

   This document specifies the use of KMAC128 and KMAC256 within the
   Internet Key Exchange Version 2 (IKEv2), Encapsulating Security
   Payload (ESP), and Authentication Header (AH) protocols.  These
   algorithms can be used as integrity protection algorithms for ESP, AH
   and IKEv2, and as Pseudo-Random Functions (PRFs) for IKEv2.
   Requirements for supporting signature algorithms in IKEv2 that use
   SHA3-256, SHA3-384, SHA3-512, SHAKE128 and SHAKE256 are also
   specified.

The IETF datatracker status page for this Internet-Draft is:
https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-ipsecme-sha3%2F&data=05%7C02%7Ccwwynn%40uwe.nsa.gov%7C8056c012271245c78c9508df0e71124d%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C639245550955478885%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=K%2B0ifRNgz%2FVaAosels4%2BRioAiLcBvznrnGpm9ajRU1A%3D&reserved=0<https://datatracker.ietf.org/doc/draft-ietf-ipsecme-sha3/>

There is also an HTMLized version available at:
https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-ietf-ipsecme-sha3-02&data=05%7C02%7Ccwwynn%40uwe.nsa.gov%7C8056c012271245c78c9508df0e71124d%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C639245550955508344%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=PrjsP%2FFD%2BNYwhtHPjQSf1JkSAvWgFK4jFoWgFEAOTE4%3D&reserved=0<https://datatracker.ietf.org/doc/html/draft-ietf-ipsecme-sha3-02>

A diff from the previous version is available at:
https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ietf.org%2Fiddiff%3Furl2%3Ddraft-ietf-ipsecme-sha3-02&data=05%7C02%7Ccwwynn%40uwe.nsa.gov%7C8056c012271245c78c9508df0e71124d%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C639245550955529480%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yL738CJbOsDqtiL2XxeH%2FaXtYe8Sc9DOGX%2Fom4FpIfs%3D&reserved=0<https://author-tools.ietf.org/iddiff?url2=draft-ietf-ipsecme-sha3-02>

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]
_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to