Support for RFC 9242 and RFC 9370 Hybrid Keys (PQ KEM) is added to our Post Quantum
solution.
Post Quantum Hybrid Key Exchange VPN
extends your PAN-OS post-quantum VPN security by adding the ability to create
post-quantum cryptographic (PQC) hybrid keys using the NIST round 3 and round 4
cryptographic suites. You can future proof your VPN encryption keys and safeguard
against harvest now, decrypt later (HNDL) attacks by combining multiple key exchange
mechanisms (KEM) with full crypto agility.
The hybrid key technology is based on RFC 9242 and RFC 9370, and allows you to add up
to seven additional key exchange mechanisms (KEM). With each additional KEM added,
the level of quantum resistance increases as the attacker needs all used KEMs to
become vulnerable before the key can be broken. You can
apply the hybrid key technology to both
IKEv2's key exchange and IPSec's rekey key exchange to ensure all VPN key exchanges
are quantum resistant.
To provide in-depth quantum defense, you can also enable both of its post quantum VPN
technologies together. If both the RFC 8784 post quantum pre-shared key (released
with PAN-OS 11.1) and this new PQ Hybrid Key feature are enabled, PAN-OS generates
the hybrid key and then mixes in the static pre-shared key.