What ETSI TS 103 744 CYBER - Quantum-safe Hybrid Key Exchanges (CatKDF and CasKDF) requires
ETSI TS 103 744 V1.1.1, published December 2020 under reference DTS/CYBER-QSC-0015, is a Technical Specification of the ETSI CYBER technical committee titled Quantum-safe Hybrid Key Exchanges. It specifies several methods for deriving cryptographic keys from multiple shared secrets, where the shared secrets are established using existing classical key agreement schemes such as elliptic curve Diffie-Hellman in NIST SP 800-56Ar3 and new quantum-safe key encapsulation mechanisms. Unlike a technical report, it uses normative shall language and is therefore testable. The assurance property it delivers is stated in clause 4.1: the quantum-safe hybrid key exchanges specified ensure that the derived key is at least as secure as the maximum security of the key exchange method, and the resulting hybrid scheme will remain secure if one of the key exchange methods remains secure. Its scope is limited to elliptic curve Diffie-Hellman and quantum-safe key encapsulation mechanisms; Quantum Key Distribution is identified as an alternative method of establishing a shared secret using quantum mechanics but is outside the scope, although a pre-shared key for the specified methods may be established using a previous session or an alternative key-establishment method such as QKD. Two hybrid key agreement schemes are specified. The concatenate scheme with its key derivation function CatKDF exchanges all public keys in a single message and all response values in a single message, forms secret as the concatenation psk followed by k1 through kn, computes f_context from the context and the exchanged messages MA and MB using the context formatting function, and returns key_material from a single KDF invocation. The cascade scheme with its key derivation function CasKDF performs the exchanges in distinct messages, chaining them so that chain_secret0 is the pre-shared key or the empty octet string and for each round round_secret_i is computed by the PRF over the previous chain secret, the new shared secret and that round's messages, with the KDF then producing both the next chain secret and that round's key material. The KDF is run n times, each time injecting the shared secret from the next key exchange, and intermediate key material may be used to protect the messages of later rounds. Error handling is normative in both schemes: if any response function returns an error indicator the responder shall respond with an error message and terminate, and the initiator shall terminate on receiving an error message or on any receive function returning an error indicator. Approved hash functions are limited to SHA-256, SHA-384, SHA-512 and SHA-512/256 from FIPS PUB 180-4 and SHA3-256, SHA3-384 and SHA3-512 from FIPS PUB 202, and all key encapsulation mechanisms shall provide OW-CPA security.
Pillar: Aviation, Defense & Quantum · Authority: European Telecommunications Standards Institute (ETSI), Technical Committee CYBER · Version: 1.0.0 · Last updated:
Primary source: https://www.etsi.org/deliver/etsi_ts/103700_103799/103744/01.01.01_60/ts_103744v010101p.pdf
SHA-256 integrity: adb93614e1743185682818498a5e85924cfa4b037c83a8724dcaabb0f302018d
Primary Citations — 10 traced to source
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/etsi-ts-103-744-quantum-safe-hybrid-key-exchange.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/etsi-ts-103-744-quantum-safe-hybrid-key-exchange.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/etsi-ts-103-744-quantum-safe-hybrid-key-exchange
- Back to registry: Browse all 10,099 compliance nodes