Closed bifurcation closed 1 year ago
I don't think we need to update HPKE for that, just define and register the KEM. It should be straightforward to document (e.g., using the Ounsworth CFRG draft), and the HPKE KEM registry is Specification Required, so you don't even need an RFC.
Merging now! Thank you!
@csosto-pk - note that a draft describing X25519+Kyber768 hybrid HPKE (heh) was recently posted
Good idea!
@bifurcation I think a new draft for PQ-hybrid HPKE (no auth modes, just base and PSK a la ia.cr/2022/414 ) is warranted here. It would benefit ECH, MLS and other places imo.
What do you think?