<?xml version='1.0' encoding='utf-8'?>
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" version="3" category="info" docName="draft-ietf-sshm-mlkem-hybrid-kex-10" number="10042" ipr="trust200902" obsoletes="" updates="" submissionType="IETF" xml:lang="en" tocInclude="true" tocDepth="4" symRefs="true" sortRefs="true" consensus="false" prepTime="2026-08-31T18:51:40" indexInclude="true" scripts="Common,Latin">
  <link href="https://datatracker.ietf.org/doc/draft-ietf-sshm-mlkem-hybrid-kex-10" rel="prev"/>
  <link href="https://dx.doi.org/10.17487/rfc10042" rel="alternate"/>
  <link href="urn:issn:2070-1721" rel="alternate"/>
  <front>
    <title abbrev="PQ SSH">Post-Quantum/Traditional Hybrid Key Exchange with the Module-Lattice-Based Key-Encapsulation Mechanism for Use in SSH</title>
    <seriesInfo name="RFC" value="10042" stream="IETF"/>
    <author fullname="Panos Kampanakis" initials="P." surname="Kampanakis">
      <organization showOnFrontPage="true">AWS</organization>
      <address>
        <email>kpanos@amazon.com</email>
      </address>
    </author>
    <author fullname="Douglas Stebila" initials="D." surname="Stebila">
      <organization showOnFrontPage="true">University of Waterloo</organization>
      <address>
        <email>dstebila@uwaterloo.ca</email>
      </address>
    </author>
    <author fullname="Torben Hansen" initials="T." surname="Hansen">
      <organization showOnFrontPage="true">AWS</organization>
      <address>
        <email>htorben@amazon.com</email>
      </address>
    </author>
    <date month="08" year="2026"/>
    <area>SEC</area>
    <workgroup>sshm</workgroup>
    <keyword>post-quantum SSH</keyword>
    <abstract pn="section-abstract">
      <t indent="0" pn="section-abstract-1">This document defines Post-Quantum Traditional (PQ/T) Hybrid key exchange methods based on the quantum-resistant Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) 
standard and traditional Elliptic-Curve Diffie-Hellman (ECDH) key exchange schemes. These methods are defined for use in the Secure Shell (SSH) transport layer protocol.</t>
    </abstract>
    <boilerplate>
      <section anchor="status-of-memo" numbered="false" removeInRFC="false" toc="exclude" pn="section-boilerplate.1">
        <name slugifiedName="name-status-of-this-memo">Status of This Memo</name>
        <t indent="0" pn="section-boilerplate.1-1">
            This document is not an Internet Standards Track specification; it is
            published for informational purposes.  
        </t>
        <t indent="0" pn="section-boilerplate.1-2">
            This document is a product of the Internet Engineering Task Force
            (IETF).  It has been approved for publication by the Internet
            Engineering Steering Group (IESG).  Not all documents approved by the
            IESG are candidates for any level of Internet Standard; see Section 2
            of RFC 7841.   
        </t>
        <t indent="0" pn="section-boilerplate.1-3">
            Information about the current status of this document, any
            errata, and how to provide feedback on it may be obtained at
            <eref target="https://www.rfc-editor.org/info/rfc10042" brackets="none"/>.
        </t>
      </section>
      <section anchor="copyright" numbered="false" removeInRFC="false" toc="exclude" pn="section-boilerplate.2">
        <name slugifiedName="name-copyright-notice">Copyright Notice</name>
        <t indent="0" pn="section-boilerplate.2-1">
            Copyright (c) 2026 IETF Trust and the persons identified as the
            document authors. All rights reserved.
        </t>
        <t indent="0" pn="section-boilerplate.2-2">
            This document is subject to BCP 78 and the IETF Trust's Legal
            Provisions Relating to IETF Documents
            (<eref target="https://trustee.ietf.org/license-info" brackets="none"/>) in effect on the date of
            publication of this document. Please review these documents
            carefully, as they describe your rights and restrictions with
            respect to this document. Code Components extracted from this
            document must include Revised BSD License text as described in
            Section 4.e of the Trust Legal Provisions and are provided without
            warranty as described in the Revised BSD License.
        </t>
      </section>
    </boilerplate>
    <toc>
      <section anchor="toc" numbered="false" removeInRFC="false" toc="exclude" pn="section-toc.1">
        <name slugifiedName="name-table-of-contents">Table of Contents</name>
        <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1">
          <li pn="section-toc.1-1.1">
            <t indent="0" keepWithNext="true" pn="section-toc.1-1.1.1"><xref derivedContent="1" format="counter" sectionFormat="of" target="section-1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-introduction">Introduction</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.1.2">
              <li pn="section-toc.1-1.1.2.1">
                <t indent="0" keepWithNext="true" pn="section-toc.1-1.1.2.1.1"><xref derivedContent="1.1" format="counter" sectionFormat="of" target="section-1.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-requirements-language">Requirements Language</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.2">
            <t indent="0" pn="section-toc.1-1.2.1"><xref derivedContent="2" format="counter" sectionFormat="of" target="section-2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-pq-t-hybrid-key-exchange">PQ/T Hybrid Key Exchange</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.2.2">
              <li pn="section-toc.1-1.2.2.1">
                <t indent="0" keepWithNext="true" pn="section-toc.1-1.2.2.1.1"><xref derivedContent="2.1" format="counter" sectionFormat="of" target="section-2.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-pq-t-hybrid-key-exchange-me">PQ/T Hybrid Key Exchange Method Abstraction</xref></t>
              </li>
              <li pn="section-toc.1-1.2.2.2">
                <t indent="0" pn="section-toc.1-1.2.2.2.1"><xref derivedContent="2.2" format="counter" sectionFormat="of" target="section-2.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-pq-t-hybrid-key-exchange-mes">PQ/T Hybrid Key Exchange Message Numbers</xref></t>
              </li>
              <li pn="section-toc.1-1.2.2.3">
                <t indent="0" pn="section-toc.1-1.2.2.3.1"><xref derivedContent="2.3" format="counter" sectionFormat="of" target="section-2.3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-pq-t-hybrid-key-exchange-met">PQ/T Hybrid Key Exchange Method Names</xref></t>
                <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.2.2.3.2">
                  <li pn="section-toc.1-1.2.2.3.2.1">
                    <t indent="0" pn="section-toc.1-1.2.2.3.2.1.1"><xref derivedContent="2.3.1" format="counter" sectionFormat="of" target="section-2.3.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-mlkem768nistp256-sha256">mlkem768nistp256-sha256</xref></t>
                  </li>
                  <li pn="section-toc.1-1.2.2.3.2.2">
                    <t indent="0" pn="section-toc.1-1.2.2.3.2.2.1"><xref derivedContent="2.3.2" format="counter" sectionFormat="of" target="section-2.3.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-mlkem1024nistp384-sha384">mlkem1024nistp384-sha384</xref></t>
                  </li>
                  <li pn="section-toc.1-1.2.2.3.2.3">
                    <t indent="0" pn="section-toc.1-1.2.2.3.2.3.1"><xref derivedContent="2.3.3" format="counter" sectionFormat="of" target="section-2.3.3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-mlkem768x25519-sha256">mlkem768x25519-sha256</xref></t>
                  </li>
                </ul>
              </li>
              <li pn="section-toc.1-1.2.2.4">
                <t indent="0" pn="section-toc.1-1.2.2.4.1"><xref derivedContent="2.4" format="counter" sectionFormat="of" target="section-2.4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-shared-secret-k">Shared Secret K</xref></t>
              </li>
              <li pn="section-toc.1-1.2.2.5">
                <t indent="0" pn="section-toc.1-1.2.2.5.1"><xref derivedContent="2.5" format="counter" sectionFormat="of" target="section-2.5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-key-derivation">Key Derivation</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.3">
            <t indent="0" pn="section-toc.1-1.3.1"><xref derivedContent="3" format="counter" sectionFormat="of" target="section-3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-message-size">Message Size</xref></t>
          </li>
          <li pn="section-toc.1-1.4">
            <t indent="0" pn="section-toc.1-1.4.1"><xref derivedContent="4" format="counter" sectionFormat="of" target="section-4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-iana-considerations">IANA Considerations</xref></t>
          </li>
          <li pn="section-toc.1-1.5">
            <t indent="0" pn="section-toc.1-1.5.1"><xref derivedContent="5" format="counter" sectionFormat="of" target="section-5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-security-considerations">Security Considerations</xref></t>
          </li>
          <li pn="section-toc.1-1.6">
            <t indent="0" pn="section-toc.1-1.6.1"><xref derivedContent="6" format="counter" sectionFormat="of" target="section-6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-references">References</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.6.2">
              <li pn="section-toc.1-1.6.2.1">
                <t indent="0" pn="section-toc.1-1.6.2.1.1"><xref derivedContent="6.1" format="counter" sectionFormat="of" target="section-6.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-normative-references">Normative References</xref></t>
              </li>
              <li pn="section-toc.1-1.6.2.2">
                <t indent="0" pn="section-toc.1-1.6.2.2.1"><xref derivedContent="6.2" format="counter" sectionFormat="of" target="section-6.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-informative-references">Informative References</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.7">
            <t indent="0" pn="section-toc.1-1.7.1"><xref derivedContent="Appendix A" format="default" sectionFormat="of" target="section-appendix.a"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-other-combiners">Other Combiners</xref></t>
          </li>
          <li pn="section-toc.1-1.8">
            <t indent="0" pn="section-toc.1-1.8.1"><xref derivedContent="Appendix B" format="default" sectionFormat="of" target="section-appendix.b"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-fips">FIPS</xref></t>
          </li>
          <li pn="section-toc.1-1.9">
            <t indent="0" pn="section-toc.1-1.9.1"><xref derivedContent="" format="none" sectionFormat="of" target="section-appendix.c"/><xref derivedContent="" format="title" sectionFormat="of" target="name-acknowledgements">Acknowledgements</xref></t>
          </li>
          <li pn="section-toc.1-1.10">
            <t indent="0" pn="section-toc.1-1.10.1"><xref derivedContent="" format="none" sectionFormat="of" target="section-appendix.d"/><xref derivedContent="" format="title" sectionFormat="of" target="name-authors-addresses">Authors' Addresses</xref></t>
          </li>
        </ul>
      </section>
    </toc>
  </front>
  <middle>
    <section numbered="true" toc="include" removeInRFC="false" pn="section-1">
      <name slugifiedName="name-introduction">Introduction</name>
      <t indent="0" pn="section-1-1">Secure Shell (SSH) <xref target="RFC4251" format="default" sectionFormat="of" derivedContent="RFC4251"/> performs key establishment using key exchange methods based on Elliptic Curve Diffie-Hellman (ECDH) style schemes defined in <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/> and <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/>. 
        The cryptographic security of these key exchanges relies on certain instances of the discrete logarithm problem being computationally infeasible to solve for adversaries. </t>
      <t indent="0" pn="section-1-2">However, if sufficiently large quantum computers become available, these instances would no longer be computationally infeasible, rendering the current key exchange and authentication methods in SSH insecure. While large quantum computers are not available today, an adversary could record the encrypted communication sent between the client and server in an SSH session and later decrypt it when sufficiently large quantum computers become available.    This kind of attack is known as a 'harvest now, decrypt later' attack <xref target="RFC9958" format="default" sectionFormat="of" derivedContent="RFC9958"/>.</t>
      <t indent="0" pn="section-1-3">This document addresses the problem by extending the SSH transport layer protocol key exchange (<xref section="7" target="RFC4253" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4253#section-7" derivedContent="RFC4253"/>) with Post-Quantum Traditional (PQ/T) Hybrid key exchange methods <xref target="RFC9794" format="default" sectionFormat="of" derivedContent="RFC9794"/>. It follows the migration considerations laid out in <xref section="4.3" target="I-D.ietf-opsawg-rfc5706bis" format="default" sectionFormat="of" derivedLink="https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-rfc5706bis-06#section-4.3" derivedContent="OAM-CONS"/>. The security provided by each key exchange scheme in a PQ/T Hybrid key exchange method is independent. This means that the PQ/T Hybrid key exchange method will always be at least as secure as the most secure key exchange scheme executed as part of the exchange. <xref target="PQ-PROOF" format="default" sectionFormat="of" derivedContent="PQ-PROOF"/> and <xref target="PQ-PROOF2" format="default" sectionFormat="of" derivedContent="PQ-PROOF2"/> contain proofs of security for such PQ/T Hybrid key exchange schemes.</t>
      <t indent="0" pn="section-1-4">In the context of the <xref target="NIST_PQ" format="default" sectionFormat="of" derivedContent="NIST_PQ"/>, key exchange algorithms are formulated as Key-Encapsulation Mechanisms (KEMs), which consist of three algorithms:</t>
      <dl newline="true" spacing="normal" indent="3" pn="section-1-5">
        <dt pn="section-1-5.1">'KeyGen() -&gt; (pk, sk)':</dt>
        <dd pn="section-1-5.2">A probabilistic key generation algorithm, which generates a public key 'pk' and a secret key 'sk'.</dd>
        <dt pn="section-1-5.3">'Encaps(pk) -&gt; (ct, ss)':</dt>
        <dd pn="section-1-5.4">A probabilistic encapsulation algorithm, which takes as input a public key 'pk' and outputs a ciphertext 'ct' and shared secret 'ss'.</dd>
        <dt pn="section-1-5.5">'Decaps(sk, ct) -&gt; ss':</dt>
        <dd pn="section-1-5.6">A decapsulation algorithm, which takes as input a secret key 'sk' and ciphertext 'ct' and outputs a shared secret 'ss', or in some cases, a distinguished error value.</dd>
      </dl>
      <t indent="0" pn="section-1-6">The main security property for KEMs is indistinguishability under adaptive chosen ciphertext attacks (IND-CCA2), which means that shared secret values should be indistinguishable from random strings even given the ability to have arbitrary ciphertexts decapsulated.  IND-CCA2 corresponds to security against an active attacker, and the public key / secret key pair can be treated as a long-term key or reused.  A weaker security notion is indistinguishability under chosen plaintext attack (IND-CPA), which means that the shared secret values should be indistinguishable from random strings given a copy of the public key. IND-CPA roughly corresponds to security against a passive attacker, and sometimes corresponds to one-time key exchange.</t>
      <t indent="0" pn="section-1-7">The post-quantum KEM used in this document is the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM). ML-KEM was standardized in 2024 <xref target="FIPS203" format="default" sectionFormat="of" derivedContent="FIPS203"/> with three parameter variants, ML-KEM-512, ML-KEM-768, and ML-KEM-1024. This specification's PQ/T Hybrid key exchange message abstraction, key derivation, and input to the SSH hash calculation, H, align with the ones defined in <xref target="RFC9941" format="default" sectionFormat="of" derivedContent="RFC9941"/>, which uses a different quantum-resistant KEM.</t>
      <section numbered="true" toc="include" removeInRFC="false" pn="section-1.1">
        <name slugifiedName="name-requirements-language">Requirements Language</name>
        <t indent="0" pn="section-1.1-1">
    The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
    "<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
    described in BCP 14 <xref target="RFC2119" format="default" sectionFormat="of" derivedContent="RFC2119"/> <xref target="RFC8174" format="default" sectionFormat="of" derivedContent="RFC8174"/> 
    when, and only when, they appear in all capitals, as shown here.
        </t>
      </section>
    </section>
    <section anchor="kex" numbered="true" toc="include" removeInRFC="false" pn="section-2">
      <name slugifiedName="name-pq-t-hybrid-key-exchange">PQ/T Hybrid Key Exchange</name>
      <section anchor="kex-abstr" numbered="true" toc="include" removeInRFC="false" pn="section-2.1">
        <name slugifiedName="name-pq-t-hybrid-key-exchange-me">PQ/T Hybrid Key Exchange Method Abstraction</name>
        <t indent="0" pn="section-2.1-1">This section defines the abstract structure of a PQ/T Hybrid key exchange method. This  structure must be instantiated with two key exchange schemes. The byte and string types are to be interpreted in this document as described in <xref target="RFC4251" format="default" sectionFormat="of" derivedContent="RFC4251"/>.</t>
        <t indent="0" pn="section-2.1-2">In a PQ/T Hybrid key exchange, instead of SSH_MSG_KEXDH_INIT <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> or SSH_MSG_KEX_ECDH_INIT <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>, the client sends:</t>
        <sourcecode type="" markers="false" pn="section-2.1-3">
       byte     SSH_MSG_KEX_HYBRID_INIT
       string   C_INIT</sourcecode>
        <t indent="0" pn="section-2.1-4">where C_INIT is the concatenation of C_PK2 and C_PK1 (C_INIT = C_PK2 || C_PK1, where || depicts concatenation). C_PK1 and C_PK2 represent the ephemeral client public keys used for each key exchange of the PQ/T Hybrid mechanism. Typically, C_PK1 represents a traditional / classical (i.e., ECDH) key exchange public key. C_PK2 represents the 'pk' output of the corresponding post-quantum KEM's 'KeyGen' at the client. </t>
        <t indent="0" pn="section-2.1-5">Instead of SSH_MSG_KEXDH_REPLY <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> or SSH_MSG_KEX_ECDH_REPLY <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>, the server sends:</t>
        <sourcecode type="" markers="false" pn="section-2.1-6">
       byte     SSH_MSG_KEX_HYBRID_REPLY
       string   K_S, server's public host key
       string   S_REPLY
       string   the signature on the exchange hash</sourcecode>
        <t indent="0" pn="section-2.1-7">where S_REPLY is the concatenation of S_CT2 and S_PK1 (S_REPLY = S_CT2 || S_PK1). Typically, S_PK1 represents the ephemeral (EC)DH server public key. S_CT2 represents the ciphertext 'ct' output of the corresponding KEM's 'Encaps' algorithm generated by the server, which encapsulates a secret to the client's public key C_PK2. Before producing S_CT2, to prevent length extension attack attempts, the server <bcp14>MUST</bcp14> check that the length of the C_INIT is the sum of the expected length of each public key in the negotiated method, C_PK1 and C_PK2. It also <bcp14>MUST</bcp14> perform the encapsulation key checks defined in Section 7.2 of <xref target="FIPS203" format="default" sectionFormat="of" derivedContent="FIPS203"/>. If any of these checks fail, the client <bcp14>MUST</bcp14> abort using a disconnect message (SSH_MSG_DISCONNECT) with a SSH_DISCONNECT_KEY_EXCHANGE_FAILED as the reason.</t>
        <t indent="0" pn="section-2.1-8">C_PK1, S_PK1, C_PK2, and S_CT2 are used to establish two shared secrets, K_CL and K_PQ. K_CL is the output from the classical ECDH exchange using C_PK1 and S_PK1. K_PQ is the post-quantum shared secret decapsulated from S_CT2. Before decapsulating, to prevent length extension attack attempts, the client <bcp14>MUST</bcp14> check that the length of the S_REPLY is the sum of the expected length of the traditional public key, S_PK1, and the ML-KEM ciphertext, S_CT2, in the negotiated method. The client <bcp14>MUST</bcp14> abort using a disconnect message (SSH_MSG_DISCONNECT) with a SSH_DISCONNECT_KEY_EXCHANGE_FAILED as the reason if the check fails or decapsulation fails for any other reason. K_CL and K_PQ are used together to generate the shared secret K according to <xref target="shared-secret" format="default" sectionFormat="of" derivedContent="Section 2.4"/>. </t>
        <t indent="0" pn="section-2.1-9">For all method names, both the client and server <bcp14>MUST</bcp14> process the ECDH and X25519 public keys (C_PK1 and S_PK1) as described in <xref section="4" target="RFC5656" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc5656#section-4" derivedContent="RFC5656"/> and <xref section="3" target="RFC8731" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc8731#section-3" derivedContent="RFC8731"/>, respectively, including validity and length checks and SSH disconnect messages if the checks fail.</t>
      </section>
      <section anchor="message-numbers" numbered="true" toc="include" removeInRFC="false" pn="section-2.2">
        <name slugifiedName="name-pq-t-hybrid-key-exchange-mes">PQ/T Hybrid Key Exchange Message Numbers</name>
        <t indent="0" pn="section-2.2-1">The message numbers 30-49 are key exchange method specific as specified in <xref target="RFC4250" format="default" sectionFormat="of" derivedContent="RFC4250"/>. These numbers may be redefined by any key exchange method <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> without requiring an IANA registration process. This document defines the following key exchange message numbers:</t>
        <sourcecode type="" markers="false" pn="section-2.2-2">
      #define SSH_MSG_KEX_HYBRID_INIT               30
      #define SSH_MSG_KEX_HYBRID_REPLY              31</sourcecode>
      </section>
      <section anchor="kex-methods" numbered="true" toc="include" removeInRFC="false" pn="section-2.3">
        <name slugifiedName="name-pq-t-hybrid-key-exchange-met">PQ/T Hybrid Key Exchange Method Names</name>
        <t indent="0" pn="section-2.3-1">The PQ/T Hybrid key exchange method names defined in this document (to be used in SSH_MSG_KEXINIT <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/>) are:</t>
        <ul bare="false" empty="false" indent="3" spacing="normal" pn="section-2.3-2">
          <li pn="section-2.3-2.1">mlkem768nistp256-sha256</li>
          <li pn="section-2.3-2.2">mlkem1024nistp384-sha384</li>
          <li pn="section-2.3-2.3">mlkem768x25519-sha256</li>
        </ul>
        <t indent="0" pn="section-2.3-3">These instantiate the abstract PQ/T Hybrid key exchanges defined in <xref target="kex-abstr" format="default" sectionFormat="of" derivedContent="Section 2.1"/>.</t>
        <section numbered="true" toc="include" removeInRFC="false" pn="section-2.3.1">
          <name slugifiedName="name-mlkem768nistp256-sha256">mlkem768nistp256-sha256</name>
          <t indent="0" pn="section-2.3.1-1">mlkem768nistp256-sha256 defines that the traditional client and server public keys C_PK1 and S_PK1 belong to the NIST P-256 curve <xref target="NIST-SP800-186" format="default" sectionFormat="of" derivedContent="NIST-SP800-186"/>. The private and public keys are generated as described therein. The public keys are defined as octet strings for NIST P-256 as per <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>; point compression may be used. The K_CL shared secret is generated from the exchanged C_PK1 and S_PK1 public keys as defined in <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/> (key agreement method ecdh-sha2-nistp256).</t>
          <t indent="0" pn="section-2.3.1-2">The post-quantum C_PK2 and S_CT2 represent ML-KEM-768 public key and ciphertext from the client and server, respectively, which are encoded as octet strings. The K_PQ shared secret is decapsulated from the ciphertext S_CT2 using the client post-quantum KEM private key as defined in <xref target="FIPS203" format="default" sectionFormat="of" derivedContent="FIPS203"/>. </t>
          <t indent="0" pn="section-2.3.1-3">The HASH function used in the key exchange <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> is SHA-256 <xref target="NIST-SHA2" format="default" sectionFormat="of" derivedContent="NIST-SHA2"/> <xref target="RFC6234" format="default" sectionFormat="of" derivedContent="RFC6234"/>.</t>
        </section>
        <section numbered="true" toc="include" removeInRFC="false" pn="section-2.3.2">
          <name slugifiedName="name-mlkem1024nistp384-sha384">mlkem1024nistp384-sha384</name>
          <t indent="0" pn="section-2.3.2-1">mlkem1024nistp384-sha384 defines that the traditional client and server public keys C_PK1 and S_PK1 belong to the NIST P-384 curve <xref target="NIST-SP800-186" format="default" sectionFormat="of" derivedContent="NIST-SP800-186"/>. The private and public keys are generated as described therein. The public keys are defined as octet strings for NIST P-384 as per <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>; point compression may be used. The K_CL shared secret is generated from the exchanged C_PK1 and S_PK1 public keys as defined in <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/> (key agreement method ecdh-sha2-nistp384).</t>
          <t indent="0" pn="section-2.3.2-2">The post-quantum C_PK2 and S_CT2 represent ML-KEM-1024 public key and ciphertext from the client and server, respectively, which are encoded as octet strings. The K_PQ shared secret is decapsulated from the ciphertext S_CT2 using the client post-quantum KEM private key as defined in <xref target="FIPS203" format="default" sectionFormat="of" derivedContent="FIPS203"/>.</t>
          <t indent="0" pn="section-2.3.2-3">The HASH function used in the key exchange <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> is SHA-384 <xref target="NIST-SHA2" format="default" sectionFormat="of" derivedContent="NIST-SHA2"/> <xref target="RFC6234" format="default" sectionFormat="of" derivedContent="RFC6234"/>.</t>
        </section>
        <section numbered="true" toc="include" removeInRFC="false" pn="section-2.3.3">
          <name slugifiedName="name-mlkem768x25519-sha256">mlkem768x25519-sha256</name>
          <t indent="0" pn="section-2.3.3-1">mlkem768x25519-sha256 defines that the traditional client and server public keys C_PK1 and S_PK1 belong to the Curve25519 curve <xref target="RFC7748" format="default" sectionFormat="of" derivedContent="RFC7748"/>. Private and public keys are generated as described therein. The public keys are defined as strings of 32 bytes as per <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/>. The K_CL shared secret is generated from the exchanged C_PK1 and S_PK1 public keys as defined in <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/> (key agreement method curve25519-sha256).</t>
          <t indent="0" pn="section-2.3.3-2">The post-quantum C_PK2 and S_CT2 represent ML-KEM-768 public key and ciphertext from the client and server, respectively, which are encoded as octet strings. The K_PQ shared secret is decapsulated from the ciphertext S_CT2 using the client post-quantum KEM private key as defined in <xref target="FIPS203" format="default" sectionFormat="of" derivedContent="FIPS203"/>.</t>
          <t indent="0" pn="section-2.3.3-3">The HASH function used in the key exchange <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> is SHA-256 <xref target="NIST-SHA2" format="default" sectionFormat="of" derivedContent="NIST-SHA2"/> <xref target="RFC6234" format="default" sectionFormat="of" derivedContent="RFC6234"/>.</t>
        </section>
      </section>
      <section anchor="shared-secret" numbered="true" toc="include" removeInRFC="false" pn="section-2.4">
        <name slugifiedName="name-shared-secret-k">Shared Secret K</name>
        <t indent="0" pn="section-2.4-1">The PQ/T Hybrid key exchange establishes K_CL and K_PQ from the ECDH and ML-KEM key exchanges, respectively. The shared secret, K, is the HASH output of the concatenation of the two shared secrets K_CL and K_PQ as:</t>
        <ul empty="true" bare="false" indent="3" spacing="normal" pn="section-2.4-2">
          <li pn="section-2.4-2.1">
            <t indent="0" pn="section-2.4-2.1.1">K = HASH(K_PQ || K_CL)</t>
          </li>
        </ul>
        <t indent="0" pn="section-2.4-3">This is similar, but not the same (for efficiency) logic as in TLS 1.3 <xref target="RFC9954" format="default" sectionFormat="of" derivedContent="RFC9954"/>. In <xref target="RFC9954" format="default" sectionFormat="of" derivedContent="RFC9954"/>, the classical and post-quantum exchanged secrets are concatenated and used in the key schedule, whereas in this document they are concatenated and hashed before being used in SSH's key derivation methodology.</t>
        <t indent="0" pn="section-2.4-4">The ECDH shared secret was traditionally encoded as an integer (mpint) as per <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/>, <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>, and <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/> and used in deriving the key. In this specification, the two shared secrets, K_PQ and K_CL, are fed into the hash function to derive K, but they are encoded as fixed-length byte arrays, not as integers. Byte arrays are defined in <xref section="5" target="RFC4251" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4251#section-5" derivedContent="RFC4251"/>.    Specifically for K_CL, the conversion from mpint to a byte array is done by
   taking the mpint that the corresponding standalone key exchange method
   would have output and re-encoding it as a fixed-size (32 bytes for
   Curve25519 and secp256r1 or 48 bytes for secp384r1) byte array that is 
   always big-endian.</t>
      </section>
      <section numbered="true" toc="include" removeInRFC="false" pn="section-2.5">
        <name slugifiedName="name-key-derivation">Key Derivation</name>
        <t indent="0" pn="section-2.5-1">The derivation of encryption keys <bcp14>MUST</bcp14> be done from the shared secret K according to <xref section="7.2" target="RFC4253" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4253#section-7.2" derivedContent="RFC4253"/> with a modification on the exchange hash H. </t>
        <t indent="0" pn="section-2.5-2">The PQ/T Hybrid key exchange hash H is the result of computing the HASH, where HASH is the hash algorithm specified in the named PQ/T Hybrid key exchange method name, over the concatenation of the following:</t>
        <sourcecode markers="false" pn="section-2.5-3">
      string V_C, client identification string (CR and LF excluded)
      string V_S, server identification string (CR and LF excluded)
      string I_C, payload of the client's SSH_MSG_KEXINIT
      string I_S, payload of the server's SSH_MSG_KEXINIT
      string K_S, server's public host key
      string C_INIT, client message octet string
      string S_REPLY, server message octet string
      string K, SSH shared secret</sourcecode>
        <t indent="0" pn="section-2.5-4">K, the shared secret used in H, was traditionally encoded as an integer (mpint) as per <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/>, <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>, and <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/>. In this specification, K is the hash output of the two concatenated byte arrays (<xref target="shared-secret" format="default" sectionFormat="of" derivedContent="Section 2.4"/>), which is not an integer. Thus, K is encoded as a string using the process described in <xref section="5" target="RFC4251" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4251#section-5" derivedContent="RFC4251"/> and is then fed along with other data in H to the key exchange method's HASH function to generate encryption keys.
        </t>
      </section>
    </section>
    <section numbered="true" toc="include" removeInRFC="false" pn="section-3">
      <name slugifiedName="name-message-size">Message Size</name>
      <t indent="0" pn="section-3-1">An SSH implementation adhering to <xref target="RFC4253" format="default" sectionFormat="of" derivedContent="RFC4253"/> must be able to support packets with an uncompressed payload length of 32768 bytes or less and a total packet size of 35000 bytes or less (including 'packet_length', 'padding_length', 'payload', 'random padding', and 'mac'). These numbers represent what must be minimally supported by SSH applications. Although some post-quantum key exchange schemes could produce large messages, this document does not define method names (<xref target="kex-methods" format="default" sectionFormat="of" derivedContent="Section 2.3"/>), which can lead to packets exceeding the minimally specified lengths in <xref section="6.1" target="RFC4253" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4253#section-6.1" derivedContent="RFC4253"/>. Thus, this document does not define new behavior for cases where a PQ/T Hybrid key exchange message causes a packet to exceed the minimally supported length.</t>
    </section>
    <section anchor="IANA" numbered="true" toc="include" removeInRFC="false" pn="section-4">
      <name slugifiedName="name-iana-considerations">IANA Considerations</name>
      <t indent="0" pn="section-4-1">IANA has registered the following method names in the "Key Exchange Method Names" registry within the "Secure Shell (SSH) Protocol Parameters" registry group <xref target="IANA-SSH" format="default" sectionFormat="of" derivedContent="IANA-SSH"/>.</t>
      <table anchor="iana-table" align="center" pn="table-1">
        <name slugifiedName="name-new-key-exchange-method-nam">New Key Exchange Method Names</name>
        <thead>
          <tr>
            <th align="left" colspan="1" rowspan="1">Method Name</th>
            <th align="left" colspan="1" rowspan="1">Reference</th>
            <th align="left" colspan="1" rowspan="1">OK to Implement</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left" colspan="1" rowspan="1">mlkem768nistp256-sha256</td>
            <td align="left" colspan="1" rowspan="1">RFC 10042</td>
            <td align="left" colspan="1" rowspan="1">
              <bcp14>SHOULD</bcp14></td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">mlkem1024nistp384-sha384</td>
            <td align="left" colspan="1" rowspan="1">RFC 10042</td>
            <td align="left" colspan="1" rowspan="1">
              <bcp14>SHOULD</bcp14></td>
          </tr>
          <tr>
            <td align="left" colspan="1" rowspan="1">mlkem768x25519-sha256</td>
            <td align="left" colspan="1" rowspan="1">RFC 10042</td>
            <td align="left" colspan="1" rowspan="1">
              <bcp14>SHOULD</bcp14></td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="Security" numbered="true" toc="include" removeInRFC="false" pn="section-5">
      <name slugifiedName="name-security-considerations">Security Considerations</name>
      <t indent="0" pn="section-5-1">The security considerations given in <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/> and <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/> also apply to the ECDH part of the P/T Hybrid key exchange schemes defined in this document.</t>
      <t indent="0" pn="section-5-2">As it is commonly done with (EC)DH keys today, generating an ephemeral key exchange keypair for ECDH and ML-KEM per connection is <bcp14>REQUIRED</bcp14> by this specification. Additionally, implementations <bcp14>MUST NOT</bcp14> reuse randomness in the generation of ML-KEM ciphertexts. As a reminder, the security properties of the protocol in this document, SSH itself, and the cryptographic algorithms used, including ML-KEM, depend on the availability and proper use of cryptographically secure random data. The generation of quality random numbers for the traditional and ML-KEM keypairs and the ML-KEM ciphertext can be difficult; see Section 3.3 of <xref target="FIPS203" format="default" sectionFormat="of" derivedContent="FIPS203"/> for additional information around randomness generation for ML-KEM.</t>
      <t indent="0" pn="section-5-3">Implementations <bcp14>MUST</bcp14> use the encodings for K_PQ, K_CL, and K specified in this document to prevent potential side-channel attacks. The way a derived binary secret string is encoded (i.e., adding or removing zero bytes for encoding) before it is hashed may lead to a variable-length secret, which raises the potential for a side-channel attack. In broad terms, when the secret is longer, the hash function may need to process more blocks internally, which could determine the length of what is hashed. This could leak the most significant bit of the derived secret and/or allow detection of when the most significant bytes are zero. In some unfortunate circumstances, this has led to timing attacks, e.g., the Lucky Thirteen <xref target="LUCKY13" format="default" sectionFormat="of" derivedContent="LUCKY13"/> and Raccoon <xref target="RACCOON" format="default" sectionFormat="of" derivedContent="RACCOON"/> attacks. In <xref target="RFC8731" format="default" sectionFormat="of" derivedContent="RFC8731"/> and <xref target="RFC5656" format="default" sectionFormat="of" derivedContent="RFC5656"/>, the ECDH shared secrets were mpint and fixed-length integer encoded, respectively, which raised a potential for such side-channel attacks. This problem is addressed in this document by encoding K_PQ and K_CL as fixed-length byte arrays and K as a string.</t>
      <t indent="0" pn="section-5-4"><xref target="PQ-PROOF" format="default" sectionFormat="of" derivedContent="PQ-PROOF"/> and <xref target="PQ-PROOF2" format="default" sectionFormat="of" derivedContent="PQ-PROOF2"/> contain
	  proofs of security for PQ/T Hybrid key exchange schemes. <xref target="PQ-PROOF2" format="default" sectionFormat="of" derivedContent="PQ-PROOF2"/> discusses how the key combination
	  to derive K and the derivation of SSH symmetric keys in this
	  document can be proven to be IND-CPA and IND-CCA2 secure with some
	  assumptions.  IND-CPA is achieved if we assume the HASH calls
	  perform as a KDF, which is a reasonable assumption. IND-CCA2
	  security is achieved by assuming the HASH is a random oracle, which
	  is a stronger assumption especially for variants of the SHA-2
	  family, which introduce length extension risks. To
	  leverage a HASH that is more suitable as a random oracle, we could
	  use SHAKE256 or introduce HMAC-SHA-256 as proposed in options (2b)
	  and (2c) in <xref target="appendixA" format="default" sectionFormat="of" derivedContent="Appendix A"/>. This document uses SHA-2,
	  which is ubiquitous, although it makes an IND-CCA2 proof need
	  stronger assumptions because even SSH's traditional key derivation
	  has not been proven to be IND-CCA2.</t>
      <t indent="0" pn="section-5-5">X25519, the traditional elliptic curve key exchange used in one of the PQ/T hybrid methods specified in this document, is generally considered easier to implement securely without side channels than its NIST counterparts (with P256 and P384). Historically, implementations of P256 and P384 have suffered various implementation issues, which have been addressed over time. Optimized X25119 implementations are also more efficient than P256 and P384. Thus, X25519 has seen more adoption than P256 and P384 across cryptographic use cases. NIST curves are sometimes preferred for regulatory compliance.</t>
    </section>
  </middle>
  <back>
    <displayreference target="I-D.connolly-cfrg-xwing-kem" to="XWING-KEM"/>
    <displayreference target="I-D.ietf-opsawg-rfc5706bis" to="OAM-CONS"/>
    <displayreference target="I-D.josefsson-chempat" to="CHEMPAT"/>
    <references pn="section-6">
      <name slugifiedName="name-references">References</name>
      <references pn="section-6.1">
        <name slugifiedName="name-normative-references">Normative References</name>
        <reference anchor="FIPS203" target="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.203.pdf" quoteTitle="true" derivedAnchor="FIPS203">
          <front>
            <title>Module-Lattice-Based Key-Encapsulation Mechanism Standard</title>
            <author>
              <organization abbrev="NIST" showOnFrontPage="true">National Institute of Standards and Technology</organization>
            </author>
            <date year="2024" month="August" day="13"/>
          </front>
          <seriesInfo name="NIST FIPS" value="203"/>
          <seriesInfo name="DOI" value="10.6028/NIST.FIPS.203"/>
        </reference>
        <reference anchor="RFC2119" target="https://www.rfc-editor.org/info/rfc2119" quoteTitle="true" derivedAnchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t indent="0">In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC4251" target="https://www.rfc-editor.org/info/rfc4251" quoteTitle="true" derivedAnchor="RFC4251">
          <front>
            <title>The Secure Shell (SSH) Protocol Architecture</title>
            <author fullname="T. Ylonen" initials="T." surname="Ylonen"/>
            <author fullname="C. Lonvick" initials="C." role="editor" surname="Lonvick"/>
            <date month="January" year="2006"/>
            <abstract>
              <t indent="0">The Secure Shell (SSH) Protocol is a protocol for secure remote login and other secure network services over an insecure network. This document describes the architecture of the SSH protocol, as well as the notation and terminology used in SSH protocol documents. It also discusses the SSH algorithm naming system that allows local extensions. The SSH protocol consists of three major components: The Transport Layer Protocol provides server authentication, confidentiality, and integrity with perfect forward secrecy. The User Authentication Protocol authenticates the client to the server. The Connection Protocol multiplexes the encrypted tunnel into several logical channels. Details of these protocols are described in separate documents. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4251"/>
          <seriesInfo name="DOI" value="10.17487/RFC4251"/>
        </reference>
        <reference anchor="RFC4253" target="https://www.rfc-editor.org/info/rfc4253" quoteTitle="true" derivedAnchor="RFC4253">
          <front>
            <title>The Secure Shell (SSH) Transport Layer Protocol</title>
            <author fullname="T. Ylonen" initials="T." surname="Ylonen"/>
            <author fullname="C. Lonvick" initials="C." role="editor" surname="Lonvick"/>
            <date month="January" year="2006"/>
            <abstract>
              <t indent="0">The Secure Shell (SSH) is a protocol for secure remote login and other secure network services over an insecure network.</t>
              <t indent="0">This document describes the SSH transport layer protocol, which typically runs on top of TCP/IP. The protocol can be used as a basis for a number of secure network services. It provides strong encryption, server authentication, and integrity protection. It may also provide compression.</t>
              <t indent="0">Key exchange method, public key algorithm, symmetric encryption algorithm, message authentication algorithm, and hash algorithm are all negotiated.</t>
              <t indent="0">This document also describes the Diffie-Hellman key exchange method and the minimal set of algorithms that are needed to implement the SSH transport layer protocol. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4253"/>
          <seriesInfo name="DOI" value="10.17487/RFC4253"/>
        </reference>
        <reference anchor="RFC5656" target="https://www.rfc-editor.org/info/rfc5656" quoteTitle="true" derivedAnchor="RFC5656">
          <front>
            <title>Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer</title>
            <author fullname="D. Stebila" initials="D." surname="Stebila"/>
            <author fullname="J. Green" initials="J." surname="Green"/>
            <date month="December" year="2009"/>
            <abstract>
              <t indent="0">This document describes algorithms based on Elliptic Curve Cryptography (ECC) for use within the Secure Shell (SSH) transport protocol. In particular, it specifies Elliptic Curve Diffie-Hellman (ECDH) key agreement, Elliptic Curve Menezes-Qu-Vanstone (ECMQV) key agreement, and Elliptic Curve Digital Signature Algorithm (ECDSA) for use in the SSH Transport Layer protocol. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5656"/>
          <seriesInfo name="DOI" value="10.17487/RFC5656"/>
        </reference>
        <reference anchor="RFC6234" target="https://www.rfc-editor.org/info/rfc6234" quoteTitle="true" derivedAnchor="RFC6234">
          <front>
            <title>US Secure Hash Algorithms (SHA and SHA-based HMAC and HKDF)</title>
            <author fullname="D. Eastlake 3rd" initials="D." surname="Eastlake 3rd"/>
            <author fullname="T. Hansen" initials="T." surname="Hansen"/>
            <date month="May" year="2011"/>
            <abstract>
              <t indent="0">Federal Information Processing Standard, FIPS</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6234"/>
          <seriesInfo name="DOI" value="10.17487/RFC6234"/>
        </reference>
        <reference anchor="RFC8174" target="https://www.rfc-editor.org/info/rfc8174" quoteTitle="true" derivedAnchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t indent="0">RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
        <reference anchor="RFC8731" target="https://www.rfc-editor.org/info/rfc8731" quoteTitle="true" derivedAnchor="RFC8731">
          <front>
            <title>Secure Shell (SSH) Key Exchange Method Using Curve25519 and Curve448</title>
            <author fullname="A. Adamantiadis" initials="A." surname="Adamantiadis"/>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <author fullname="M. Baushke" initials="M." surname="Baushke"/>
            <date month="February" year="2020"/>
            <abstract>
              <t indent="0">This document describes the specification for using Curve25519 and Curve448 key exchange methods in the Secure Shell (SSH) protocol.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8731"/>
          <seriesInfo name="DOI" value="10.17487/RFC8731"/>
        </reference>
      </references>
      <references pn="section-6.2">
        <name slugifiedName="name-informative-references">Informative References</name>
        <reference anchor="I-D.josefsson-chempat" target="https://datatracker.ietf.org/doc/html/draft-josefsson-chempat-05" quoteTitle="true" derivedAnchor="CHEMPAT">
          <front>
            <title>Chempat: Generic Instantiated PQ/T Hybrid Key Encapsulation Mechanisms</title>
            <author fullname="Simon Josefsson" initials="S." surname="Josefsson"/>
            <date day="24" month="June" year="2026"/>
            <abstract>
              <t indent="0">This document specify Chempat as a generic family of instantiated Post-Quantum/Traditional (PQ/T) Hybrid Key Exchange Methods (KEMs). The goal is to provide a generic combiner construct that can be analysed separately for security assurance, and to offer concrete instantiated algorithms for integration into protocol and implementations. Identified instances are provided based on some combinations of traditional Diffie-Hellman key agreement using curves P-256, P-384, X25519, X448, brainpoolP256, brainpoolP384 and brainpoolP512 combined with post quantum methods ML-KEM-768, ML-KEM- 1024, Streamlined NTRU Prime sntrup761, Classic McEliece and FrodoKEM.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-josefsson-chempat-05"/>
          <refcontent>Work in Progress</refcontent>
        </reference>
        <reference anchor="IANA-SSH" target="https://www.iana.org/assignments/ssh-parameters" quoteTitle="true" derivedAnchor="IANA-SSH">
          <front>
            <title>Secure Shell (SSH) Protocol Parameters</title>
            <author>
              <organization showOnFrontPage="true">IANA</organization>
            </author>
          </front>
        </reference>
        <reference anchor="LUCKY13" target="https://ieeexplore.ieee.org/iel7/6547086/6547088/06547131.pdf" quoteTitle="true" derivedAnchor="LUCKY13">
          <front>
            <title>Lucky Thirteen: Breaking the TLS and DTLS record protocols</title>
            <author initials="N.J." surname="Al Fardan">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="K.G." surname="Paterson">
              <organization showOnFrontPage="true"/>
            </author>
            <date year="2013"/>
          </front>
          <refcontent>2013 IEEE Symposium on Security and Privacy, pp. 526-540</refcontent>
          <seriesInfo name="DOI" value="10.1109/SP.2013.42"/>
        </reference>
        <reference anchor="NIST-SHA2" target="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf" quoteTitle="true" derivedAnchor="NIST-SHA2">
          <front>
            <title>Secure Hash Standard (SHS)</title>
            <author>
              <organization abbrev="NIST" showOnFrontPage="true">National Institute of Standards and Technology</organization>
            </author>
            <date month="August" year="2015"/>
          </front>
          <seriesInfo name="NIST FIPS" value="180-4"/>
          <seriesInfo name="DOI" value="10.6028/NIST.FIPS.180-4"/>
        </reference>
        <reference anchor="NIST-SP800-186" quoteTitle="true" target="https://doi.org/10.6028/NIST.SP.800-186" derivedAnchor="NIST-SP800-186">
          <front>
            <title>Recommendations for Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters</title>
            <author initials="L." surname="Chen" fullname="Lily Chen"/>
            <author initials="D." surname="Moody" fullname="Dustin Moody"/>
            <author initials="K." surname="Randall" fullname="Karen Randall"/>
            <author initials="A." surname="Regenscheid" fullname="Andrew Regenscheid"/>
            <author initials="A." surname="Robinson" fullname="Angela Robinson"/>
            <date month="February" year="2023"/>
          </front>
          <refcontent>National Institute of Standards and Technology</refcontent>
          <seriesInfo name="NIST SP" value="800-186"/>
          <seriesInfo name="DOI" value="10.6028/NIST.SP.800-186"/>
        </reference>
        <reference anchor="NIST-SP-800-56C" quoteTitle="true" target="https://doi.org/10.6028/NIST.SP.800-56Cr2" derivedAnchor="NIST-SP-800-56C">
          <front>
            <title>Recommendation for Key-Derivation Methods in Key-Establishment Schemes</title>
            <author initials="E." surname="Barker" fullname="Elaine Barker"/>
            <author initials="L." surname="Chen" fullname="Lily Chen"/>
            <author initials="R." surname="Davis" fullname="Richard Davis"/>
            <date year="2020" month="August"/>
          </front>
          <refcontent>National Institute of Standards and Technology</refcontent>
          <seriesInfo name="NIST SP" value="800-56Cr2"/>
          <seriesInfo name="DOI" value="10.6028/NIST.SP.800-56Cr2"/>
        </reference>
        <reference anchor="NIST-SP-800-133r2" quoteTitle="true" target="https://doi.org/10.6028/NIST.SP.800-133r2" derivedAnchor="NIST-SP-800-133r2">
          <front>
            <title>Recommendation for Cryptographic Key Generation</title>
            <author initials="E." surname="Barker" fullname="Elaine Barker"/>
            <author initials="A." surname="Roginsky" fullname="Allen Roginsky"/>
            <author initials="R." surname="Davis" fullname="Richard Davis"/>
            <date year="2020" month="June"/>
          </front>
          <refcontent>National Institute of Standards and Technology</refcontent>
          <seriesInfo name="NIST SP" value="800-133r2"/>
          <seriesInfo name="DOI" value="10.6028/NIST.SP.800-133r2"/>
        </reference>
        <reference anchor="NIST-SP-800-135" quoteTitle="true" target="https://doi.org/10.6028/NIST.SP.800-135r1" derivedAnchor="NIST-SP-800-135">
          <front>
            <title>Recommendation for Existing Application-Specific Key Derivation Functions</title>
            <author initials="Q." surname="Dang" fullname="Quynh Dang"/>
            <date year="2011" month="December"/>
          </front>
          <refcontent>National Institute of Standards and Technology</refcontent>
          <seriesInfo name="NIST SP" value="800-135r1"/>
          <seriesInfo name="DOI" value="10.6028/NIST.SP.800-135r1"/>
        </reference>
        <reference anchor="NIST-SP-800-227" quoteTitle="true" target="https://doi.org/10.6028/NIST.SP.800-227" derivedAnchor="NIST-SP-800-227">
          <front>
            <title>Recommendations for Key-Encapsulation Mechanisms</title>
            <author initials="G." surname="Alagic" fullname="Gorjan Alagic"/>
            <author initials="E." surname="Barker" fullname="Elaine Barker"/>
            <author initials="L." surname="Chen" fullname="Lily Chen"/>
            <author initials="D." surname="Dustin" fullname="Dustin Moody"/>
            <author initials="A." surname="Robinson" fullname="Angela Robinson"/>
            <author initials="H." surname="Silberg" fullname="Hamilton Silberg"/>
            <author initials="N." surname="Waller" fullname="Noah Waller"/>
            <date year="2025" month="September"/>
          </front>
          <refcontent>National Institute of Standards and Technology</refcontent>
          <seriesInfo name="NIST SP" value="800-227"/>
          <seriesInfo name="DOI" value="10.6028/NIST.SP.800-227"/>
        </reference>
        <reference anchor="NIST_PQ" target="https://csrc.nist.gov/projects/post-quantum-cryptography" quoteTitle="true" derivedAnchor="NIST_PQ">
          <front>
            <title>Post-Quantum Cryptography (PQC)</title>
            <author>
              <organization showOnFrontPage="true">NIST</organization>
            </author>
            <date day="5" month="August" year="2026"/>
          </front>
        </reference>
        <reference anchor="I-D.ietf-opsawg-rfc5706bis" target="https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-rfc5706bis-06" quoteTitle="true" derivedAnchor="OAM-CONS">
          <front>
            <title>Guidelines for Considering Operations and Management in IETF Specifications</title>
            <author fullname="Benoît Claise" initials="B." surname="Claise">
              <organization showOnFrontPage="true">Everything OPS &amp; Arrcus</organization>
            </author>
            <author fullname="Joe Clarke" initials="J." surname="Clarke">
              <organization showOnFrontPage="true">Cisco</organization>
            </author>
            <author fullname="Adrian Farrel" initials="A." surname="Farrel">
              <organization showOnFrontPage="true">Old Dog Consulting</organization>
            </author>
            <author fullname="Samier Barguil" initials="S." surname="Barguil">
              <organization showOnFrontPage="true">Nokia</organization>
            </author>
            <author fullname="Carlos Pignataro" initials="C." surname="Pignataro">
              <organization showOnFrontPage="true">Blue Fern Consulting</organization>
            </author>
            <author fullname="Ran Chen" initials="R." surname="Chen">
              <organization showOnFrontPage="true">ZTE</organization>
            </author>
            <date day="12" month="August" year="2026"/>
            <abstract>
              <t indent="0">New Protocols and Protocol Extensions are best designed with due consideration of the functionality needed to operate and manage them. Retrofitting operations and management considerations is suboptimal. The purpose of this document is to provide guidance to authors and reviewers on what operational and management aspects should be addressed when writing documents in the IETF Stream that document a specification for New Protocols or Protocol Extensions or describe their use. This document obsoletes RFC 5706, replacing it completely and updating it with new operational and management techniques and mechanisms. It also updates RFC 2360 to obsolete mandatory MIB creation. Finally, it introduces a requirement to include an "Operational Considerations" section in new RFCs in the IETF Stream that define New Protocols or Protocol Extensions or describe their use (including relevant YANG Models), while providing an escape clause if no new considerations are identified.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-opsawg-rfc5706bis-06"/>
          <refcontent>Work in Progress</refcontent>
        </reference>
        <reference anchor="PQ-PROOF" target="https://eprint.iacr.org/2020/1364" quoteTitle="true" derivedAnchor="PQ-PROOF">
          <front>
            <title>Security of Hybrid Key Encapsulation</title>
            <author initials="M." surname="Campagna" fullname="Matthew Campagna">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="A." surname="Petcher" fullname="Adam Petcher">
              <organization showOnFrontPage="true"/>
            </author>
            <date year="2020"/>
          </front>
          <refcontent>Cryptology ePrint Archive, Paper 2020/1364</refcontent>
        </reference>
        <reference anchor="PQ-PROOF2" target="https://eprint.iacr.org/2023/972" quoteTitle="true" derivedAnchor="PQ-PROOF2">
          <front>
            <title>Security of Hybrid Key Establishment using Concatenation</title>
            <author initials="A." surname="Petcher" fullname="Adam Petcher">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="M." surname="Campagna" fullname="Matthew Campagna">
              <organization showOnFrontPage="true"/>
            </author>
            <date year="2023"/>
          </front>
          <refcontent>Cryptology ePrint Archive, Paper 2023/972</refcontent>
        </reference>
        <reference anchor="RACCOON" target="https://raccoon-attack.com/" quoteTitle="true" derivedAnchor="RACCOON">
          <front>
            <title>Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)</title>
            <author initials="R." surname="Merget">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="M." surname="Brinkmann">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="N." surname="Aviram">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="J." surname="Somorovsky">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="J." surname="Mittmann">
              <organization showOnFrontPage="true"/>
            </author>
            <author initials="J." surname="Schwenk">
              <organization showOnFrontPage="true"/>
            </author>
            <date year="2020" month="September"/>
          </front>
        </reference>
        <reference anchor="RFC4250" target="https://www.rfc-editor.org/info/rfc4250" quoteTitle="true" derivedAnchor="RFC4250">
          <front>
            <title>The Secure Shell (SSH) Protocol Assigned Numbers</title>
            <author fullname="S. Lehtinen" initials="S." surname="Lehtinen"/>
            <author fullname="C. Lonvick" initials="C." role="editor" surname="Lonvick"/>
            <date month="January" year="2006"/>
            <abstract>
              <t indent="0">This document defines the instructions to the IANA and the initial state of the IANA assigned numbers for the Secure Shell (SSH) protocol. It is intended only for the initialization of the IANA registries referenced in the set of SSH documents. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="4250"/>
          <seriesInfo name="DOI" value="10.17487/RFC4250"/>
        </reference>
        <reference anchor="RFC7748" target="https://www.rfc-editor.org/info/rfc7748" quoteTitle="true" derivedAnchor="RFC7748">
          <front>
            <title>Elliptic Curves for Security</title>
            <author fullname="A. Langley" initials="A." surname="Langley"/>
            <author fullname="M. Hamburg" initials="M." surname="Hamburg"/>
            <author fullname="S. Turner" initials="S." surname="Turner"/>
            <date month="January" year="2016"/>
            <abstract>
              <t indent="0">This memo specifies two elliptic curves over prime fields that offer a high level of practical security in cryptographic applications, including Transport Layer Security (TLS). These curves are intended to operate at the ~128-bit and ~224-bit security level, respectively, and are generated deterministically based on a list of required properties.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7748"/>
          <seriesInfo name="DOI" value="10.17487/RFC7748"/>
        </reference>
        <reference anchor="RFC9794" target="https://www.rfc-editor.org/info/rfc9794" quoteTitle="true" derivedAnchor="RFC9794">
          <front>
            <title>Terminology for Post-Quantum Traditional Hybrid Schemes</title>
            <author fullname="F. Driscoll" initials="F." surname="Driscoll"/>
            <author fullname="M. Parsons" initials="M." surname="Parsons"/>
            <author fullname="B. Hale" initials="B." surname="Hale"/>
            <date month="June" year="2025"/>
            <abstract>
              <t indent="0">One aspect of the transition to post-quantum algorithms in cryptographic protocols is the development of hybrid schemes that incorporate both post-quantum and traditional asymmetric algorithms. This document defines terminology for such schemes. It is intended to be used as a reference and, hopefully, to ensure consistency and clarity across different protocols, standards, and organisations.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9794"/>
          <seriesInfo name="DOI" value="10.17487/RFC9794"/>
        </reference>
        <reference anchor="RFC9941" target="https://www.rfc-editor.org/info/rfc9941" quoteTitle="true" derivedAnchor="RFC9941">
          <front>
            <title>Secure Shell (SSH) Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512</title>
            <author fullname="M. Friedl" initials="M." surname="Friedl"/>
            <author fullname="J. Mojzis" initials="J." surname="Mojzis"/>
            <author fullname="S. Josefsson" initials="S." surname="Josefsson"/>
            <date month="April" year="2026"/>
            <abstract>
              <t indent="0">This document describes a widely deployed hybrid key exchange method in the Secure Shell (SSH) protocol that is based on Streamlined NTRU Prime sntrup761 and X25519 with SHA-512.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9941"/>
          <seriesInfo name="DOI" value="10.17487/RFC9941"/>
        </reference>
        <reference anchor="RFC9954" target="https://www.rfc-editor.org/info/rfc9954" quoteTitle="true" derivedAnchor="RFC9954">
          <front>
            <title>Hybrid Key Exchange in TLS 1.3</title>
            <author fullname="D. Stebila" initials="D." surname="Stebila"/>
            <author fullname="S. Fluhrer" initials="S." surname="Fluhrer"/>
            <author fullname="S. Gueron" initials="S." surname="Gueron"/>
            <date month="July" year="2026"/>
            <abstract>
              <t indent="0">Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum cryptography. This document provides a construction for hybrid key exchange in the Transport Layer Security (TLS) protocol version 1.3.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9954"/>
          <seriesInfo name="DOI" value="10.17487/RFC9954"/>
        </reference>
        <reference anchor="RFC9958" target="https://www.rfc-editor.org/info/rfc9958" quoteTitle="true" derivedAnchor="RFC9958">
          <front>
            <title>Post-Quantum Cryptography for Engineers</title>
            <author fullname="A. Banerjee" initials="A." surname="Banerjee"/>
            <author fullname="T. Reddy.K" initials="T." surname="Reddy.K"/>
            <author fullname="D. Schoinianakis" initials="D." surname="Schoinianakis"/>
            <author fullname="T. Hollebeek" initials="T." surname="Hollebeek"/>
            <author fullname="M. Ounsworth" initials="M." surname="Ounsworth"/>
            <date month="June" year="2026"/>
            <abstract>
              <t indent="0">The advent of a cryptographically relevant quantum computer (CRQC) would render state-of-the-art, traditional public key algorithms deployed today obsolete, as the mathematical assumptions underpinning their security would no longer hold. To address this, protocols and infrastructure must transition to post-quantum algorithms, which are designed to resist both traditional and quantum attacks. This document explains why engineers need to be aware of and understand post-quantum cryptography (PQC), and it details the impact of CRQCs on existing systems and the challenges involved in transitioning to post-quantum algorithms. Unlike previous cryptographic updates, this shift may require significant protocol redesign due to the unique properties of post-quantum algorithms.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9958"/>
          <seriesInfo name="DOI" value="10.17487/RFC9958"/>
        </reference>
        <reference anchor="I-D.connolly-cfrg-xwing-kem" target="https://datatracker.ietf.org/doc/html/draft-connolly-cfrg-xwing-kem-10" quoteTitle="true" derivedAnchor="XWING-KEM">
          <front>
            <title>X-Wing: general-purpose hybrid post-quantum KEM</title>
            <author fullname="Deirdre Connolly" initials="D." surname="Connolly">
              <organization showOnFrontPage="true">SandboxAQ</organization>
            </author>
            <author fullname="Peter Schwabe" initials="P." surname="Schwabe">
              <organization showOnFrontPage="true">MPI-SP &amp; Radboud University</organization>
            </author>
            <author fullname="Bas Westerbaan" initials="B." surname="Westerbaan">
              <organization showOnFrontPage="true">Cloudflare</organization>
            </author>
            <date day="2" month="March" year="2026"/>
            <abstract>
              <t indent="0">This memo defines X-Wing, a general-purpose post-quantum/traditional hybrid key encapsulation mechanism (PQ/T KEM) built on X25519 and ML- KEM-768.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-connolly-cfrg-xwing-kem-10"/>
          <refcontent>Work in Progress</refcontent>
        </reference>
      </references>
    </references>
    <section anchor="appendixA" numbered="true" toc="include" removeInRFC="false" pn="section-appendix.a">
      <name slugifiedName="name-other-combiners">Other Combiners</name>
      <t indent="0" pn="section-appendix.a-1">Other combiners to derive K and the SSH keys were considered while working on this document. These include:</t>
      <ol type="(%d)" indent="adaptive" spacing="normal" start="1" pn="section-appendix.a-2">
		  <li pn="section-appendix.a-2.1" derivedCounter="(1)">K = K_PQ || K_CL. All SSH keys are derived from K as defined in <xref section="7.2" target="RFC4253" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4253#section-7.2" derivedContent="RFC4253"/>.</li>
        <li pn="section-appendix.a-2.2" derivedCounter="(2)">
          <t indent="0" pn="section-appendix.a-2.2.1">All SSH keys are derived from K as defined in <xref section="7.2" target="RFC4253" format="default" sectionFormat="of" derivedLink="https://rfc-editor.org/rfc/rfc4253#section-7.2" derivedContent="RFC4253"/>. </t>
          <ol type="(%c)" indent="adaptive" spacing="normal" start="1" pn="section-appendix.a-2.2.2">
			   <li pn="section-appendix.a-2.2.2.1" derivedCounter="(a)">K = HASH(K_PQ, K_CL). This is the option adopted in this specification.</li>
            <li pn="section-appendix.a-2.2.2.2" derivedCounter="(b)">K = HMAC-HASH(K_PQ, K_CL)</li>
            <li pn="section-appendix.a-2.2.2.3" derivedCounter="(c)">K = HMAC-HASH(0, K_PQ || K_CL)</li>
          </ol>
        </li>
        <li pn="section-appendix.a-2.3" derivedCounter="(3)">K = HKDF-HASH_Extract(0, K_PQ || K_CL). SSH keys are now derived from K using HKDF-HASH(K, H || session_id, 6*sizeof(HASH)).</li>
      </ol>
      <t indent="0" pn="section-appendix.a-3">Option (3) follows the Extract-and-Expand logic described in <xref target="NIST-SP-800-56C" format="default" sectionFormat="of" derivedContent="NIST-SP-800-56C"/>. It deviates from existing SSH key derivation significantly and might be viewed as too far from the current SSH design. It probably would be a good approach for SSH to move from basic hashing everywhere to use proper KDFs with extract/expand, but that should be a separate effort.</t>
      <t indent="0" pn="section-appendix.a-4">We also considered combiners like the ones proposed in <xref target="I-D.josefsson-chempat" format="default" sectionFormat="of" derivedContent="CHEMPAT"/> and <xref target="I-D.connolly-cfrg-xwing-kem" format="default" sectionFormat="of" derivedContent="XWING-KEM"/>. <xref target="I-D.connolly-cfrg-xwing-kem" format="default" sectionFormat="of" derivedContent="XWING-KEM"/> has a separate IND-CCA2 security proof. Although such combiners may be proven IND-CCA2 secure, to be IND-CCA2, the SSH key derivation would still require the assumptions laid out in <xref target="PQ-PROOF2" format="default" sectionFormat="of" derivedContent="PQ-PROOF2"/> and discussed in <xref target="Security" format="default" sectionFormat="of" derivedContent="Section 5"/>.</t>
    </section>
    <section numbered="true" toc="include" removeInRFC="false" pn="section-appendix.b">
      <name slugifiedName="name-fips">FIPS</name>
      <t indent="0" pn="section-appendix.b-1"><xref target="NIST-SP-800-56C" format="default" sectionFormat="of" derivedContent="NIST-SP-800-56C"/> and <xref target="NIST-SP-800-135" format="default" sectionFormat="of" derivedContent="NIST-SP-800-135"/> give NIST recommendations for key derivation methods in key exchange protocols. Some PQ/T Hybrid combinations may combine the shared secret from a NIST-approved algorithm (e.g., ECDH using the nistp256/secp256r1 curve or ML-KEM) with a shared secret from a non-approved algorithm (e.g., X25519). <xref target="NIST-SP-800-227" format="default" sectionFormat="of" derivedContent="NIST-SP-800-227"/> lists simple concatenation as an approved way of producing a PQ/T Hybrid shared secret in which one of the constituent secrets is from an approved algorithm (i.e., secp256r1, secp384r1, ML-KEM) and using it in a key derivation/combination method approved by <xref target="NIST-SP-800-56C" format="default" sectionFormat="of" derivedContent="NIST-SP-800-56C"/> or <xref target="NIST-SP-800-133r2" format="default" sectionFormat="of" derivedContent="NIST-SP-800-133r2"/>. Although the SSH key derivation function does not follow <xref target="NIST-SP-800-56C" format="default" sectionFormat="of" derivedContent="NIST-SP-800-56C"/> or <xref target="NIST-SP-800-133r2" format="default" sectionFormat="of" derivedContent="NIST-SP-800-133r2"/>, it is approved by <xref target="NIST-SP-800-135" format="default" sectionFormat="of" derivedContent="NIST-SP-800-135"/>. This method is the same used in this document to derive SSH keys from the quantum-resistant shared secret. Thus, the SSH key combiner in this document appears to be FIPS-approved although it is not specifically called out in <xref target="NIST-SP-800-227" format="default" sectionFormat="of" derivedContent="NIST-SP-800-227"/>.</t>
    </section>
    <section anchor="Acknowledgements" numbered="false" toc="include" removeInRFC="false" pn="section-appendix.c">
      <name slugifiedName="name-acknowledgements">Acknowledgements</name>
      <t indent="0" pn="section-appendix.c-1">The authors want to thank <contact fullname="Gerardo Ravago"/> from AWS for implementing this document and finding issues. We also want to thank <contact fullname="Damien Miller"/> and <contact fullname="Markus Friedl"/> for their feedback and for implementing some of the SSH key exchange methods in this document in OpenSSH. Special acknowledgements go to <contact fullname="Simon Tatham"/> from Putty, <contact fullname="Loganaden Velvindron"/>, <contact fullname="John Mattsson"/>, <contact fullname="Simon Josefsson"/>, and <contact fullname="Watson Ladd"/> for their valuable suggestions.</t>
    </section>
    <section anchor="authors-addresses" numbered="false" removeInRFC="false" toc="include" pn="section-appendix.d">
      <name slugifiedName="name-authors-addresses">Authors' Addresses</name>
      <author fullname="Panos Kampanakis" initials="P." surname="Kampanakis">
        <organization showOnFrontPage="true">AWS</organization>
        <address>
          <email>kpanos@amazon.com</email>
        </address>
      </author>
      <author fullname="Douglas Stebila" initials="D." surname="Stebila">
        <organization showOnFrontPage="true">University of Waterloo</organization>
        <address>
          <email>dstebila@uwaterloo.ca</email>
        </address>
      </author>
      <author fullname="Torben Hansen" initials="T." surname="Hansen">
        <organization showOnFrontPage="true">AWS</organization>
        <address>
          <email>htorben@amazon.com</email>
        </address>
      </author>
    </section>
  </back>
</rfc>
