Hello, The draft-ietf-jose-pqc-kem establishes a clear, HPKE-independent pathway for systems aiming to transition to PQC-only Key Encapsulation Mechanisms (KEMs). It does not depend on the new modes defined in draft-ietf-jose-hpke-encrypt. Instead, draft-ietf-jose-pqc-kem mirrors the original JWE ECDH-style key agreement model, making it the natural post-quantum analogue of ECDH-ES.
While HPKE-based JOSE provides valuable capabilities, particularly for PQ/T use cases, deployments seeking a PQC-only key establishment mechanism should not be required to rely on the new modes introduced in jose-hpke. This draft supports a minimal-change transition to PQC-only KEMs while remaining aligned with the existing JWE model, enabling a straightforward and consistent migration path. Best, Aritra.
_______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
