RFC 9370: Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2)
In plain English — editorial summary, not part of the RFC
This document describes how to extend the Internet Key Exchange Protocol Version 2 (IKEv2) to allow multiple key exchanges to take place while computing a shared secret during a Security Association (SA) setup. This document utilizes the IKE_INTERMEDIATE exchange, where multiple key exchanges are performed when an IKE SA is being established. It also introduces a new IKEv2 exchange, IKE_FOLLOWUP_KE, which is used for the same purpose when the IKE SA is being rekeyed or is creating additional Child SAs. This document updates RFC 7296 by renaming a Transform Type 4 from "Diffie-Hellman Group (D-H)" to "Key Exchange Method (KE)" and renaming a field in the Key Exchange Payload from "Diffie-Hellman Group Num" to "Key Exchange Method". It also renames an IANA registry for this Transform Type from "Transform Type 4 - Diffie- Hellman Group Transform IDs" to "Transform Type 4 - Key Exchange Method Transform IDs". These changes generalize key exchange algorithms that can be used in IKEv2.
Document record
- Document ID
- RFC9370
- Published
- May 2023
- Authors
- CJ. Tjhai; M. Tomlinson; G. Bartlett; S. Fluhrer; D. Van Geest; O. Garcia-Morchon; V. Smyslov
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 29
- Also known as
- —
- Updates:
- RFC 7296
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9763Related Certificates for Use in Multiple Authentications within a ProtocolCurrent
June 2025
- RFC 9794Terminology for Post-Quantum Traditional Hybrid SchemesCurrent
June 2025
- RFC 9980Post-Quantum Cryptography in OpenPGPCurrent
June 2026
- RFC 10024Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3Current
August 2026
- RFC 9242Intermediate Exchange in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
May 2022
- RFC 9867Mixing Preshared Keys in the IKE_INTERMEDIATE and CREATE_CHILD_SA Exchanges of the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-Quantum SecurityCurrent
November 2025
- RFC 9935Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)Current
March 2026
- RFC 9941Secure Shell (SSH) Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512Current
April 2026
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?