Hello,

The draft-ietf-jose-pqc-kem establishes a clear, HPKE-independent pathway for 
systems aiming to transition to PQC-only Key Encapsulation Mechanisms (KEMs). 
It does not depend on the new modes defined in draft-ietf-jose-hpke-encrypt. 
Instead, draft-ietf-jose-pqc-kem mirrors the original JWE ECDH-style key 
agreement model, making it the natural post-quantum analogue of ECDH-ES.

While HPKE-based JOSE provides valuable capabilities, particularly for PQ/T use 
cases, deployments seeking a PQC-only key establishment mechanism should not be 
required to rely on the new modes introduced in jose-hpke. This draft supports 
a minimal-change transition to PQC-only KEMs while remaining aligned with the 
existing JWE model, enabling a straightforward and consistent migration path.

Best,
Aritra.
_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to