LAMPS X. Song Internet-Draft ZTE Corp. Intended status: Standards Track M. Chen Expires: 26 March 2027 China Mobile 22 September 2026 Composite FrodoKEM for use in X.509 Public Key Infrastructure draft-song-lamps-pq-composite-frodokem-00 Abstract Composite FrodoKEM defines combinations of FrodoKEM with RSA-OAEP, ECDH, X25519, and X448. This document specifies the algorithm definitions, key formats, and certificate conventions for using Composite FrodoKEM in the X.509 Public Key Infrastructure. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 26 March 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Song & Chen Expires 26 March 2027 [Page 1] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 1.1. Requirements Language . . . . . . . . . . . . . . . . . . 3 2. Composite FrodoKEM . . . . . . . . . . . . . . . . . . . . . 3 2.1. FrodoKEM Component . . . . . . . . . . . . . . . . . . . 3 2.2. Traditional Component Algorithms . . . . . . . . . . . . 4 2.3. Composite FrodoKEM Construction . . . . . . . . . . . . . 4 3. Composite FrodoKEM Operations . . . . . . . . . . . . . . . . 4 3.1. Key Generation . . . . . . . . . . . . . . . . . . . . . 4 3.2. Key Encapsulation Mechanism . . . . . . . . . . . . . . . 5 3.3. Key Decapsulation Mechanism . . . . . . . . . . . . . . . 6 3.4. Key Combiner . . . . . . . . . . . . . . . . . . . . . . 7 4. Key Format . . . . . . . . . . . . . . . . . . . . . . . . . 8 4.1. Public Key Format . . . . . . . . . . . . . . . . . . . . 8 4.2. Private Key Format . . . . . . . . . . . . . . . . . . . 9 4.3. Encoding Rules . . . . . . . . . . . . . . . . . . . . . 9 5. Algorithm Identifiers . . . . . . . . . . . . . . . . . . . . 9 5.1. Composite FrodoKEM Algorithm Identifiers . . . . . . . . 9 5.2. KEM Combiner Labels . . . . . . . . . . . . . . . . . . . 12 6. ASN.1 Module . . . . . . . . . . . . . . . . . . . . . . . . 12 7. Security Considerations . . . . . . . . . . . . . . . . . . . 20 8. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 20 8.1. PKIX Module Identifier Registry . . . . . . . . . . . . . 20 8.2. PKIX Algorithm Registry . . . . . . . . . . . . . . . . . 20 9. References . . . . . . . . . . . . . . . . . . . . . . . . . 22 9.1. Normative References . . . . . . . . . . . . . . . . . . 22 9.2. Informative References . . . . . . . . . . . . . . . . . 23 Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 24 1. Introduction [ISO18033-2-AMD2] specifies FrodoKEM, a family of quantum-resistant key encapsulation mechanisms (KEMs) based on the Learning With Errors (LWE) problem over unstructured lattices. The detailed algorithm specification, including the KeyGen, Encapsulate, and Decapsulate procedures, is provided in [I-D.longa-cfrg-frodokem]. FrodoKEM offers multiple parameter sets, with the recommended sets for general use including FrodoKEM-976 for NIST security level 3 and FrodoKEM-1344 for NIST security level 5. This document defines Composite FrodoKEM, which combines a FrodoKEM component with a traditional component algorithm (RSA-OAEP, ECDH, X25519, or X448) to produce a hybrid KEM that provides both post- quantum and classical security guarantees. Song & Chen Expires 26 March 2027 [Page 2] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 This document specifies the algorithm definitions, key formats, and certificate conventions for using Composite FrodoKEM in the X.509 Public Key Infrastructure [RFC5280]. Companion documents define the use of Composite FrodoKEM in specific protocols such as CMS [RFC9629] and TLS. 1.1. Requirements Language The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here. 2. Composite FrodoKEM 2.1. FrodoKEM Component FrodoKEM [ISO18033-2-AMD2] is a key encapsulation mechanism based on the Learning With Errors (LWE) problem over unstructured lattices. FrodoKEM defines two modes of operation: standard and ephemeral. As introduced in [I-D.longa-cfrg-frodokem], standard FrodoKEM doubles the length of the seedSE value and incorporates a public random salt value into encapsulation; it MAY be used in any application. Ephemeral FrodoKEM is intended only for applications where the number of ciphertexts generated per public key is small. This document specifies the use of standard FrodoKEM for composite combinations with traditional KEM algorithms. For each FrodoKEM parameter set, [I-D.longa-cfrg-frodokem] defines two implementation variants that differ in the internal pseudorandom function: a SHAKE variant and an AES variant. This document specifies the use of both variants for each parameter set. The parameter sets of standard FrodoKEM used in this document are shown below: +-------------+----------------+--------+--------+--------+------+ | NIST Level | Parameter Set | pk | sk | ct | ss | +-------------+----------------+--------+--------+--------+------+ | Level 3 | FrodoKEM-976 | 15,632 | 31,296 | 15,792 | 24 | +-------------+----------------+--------+--------+--------+------+ | Level 5 | FrodoKEM-1344 | 21,520 | 43,088 | 21,696 | 32 | +-------------+----------------+--------+--------+--------+------+ Table 1: Size (in bytes) of keys and ciphertexts of FrodoKEM Song & Chen Expires 26 March 2027 [Page 3] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 2.2. Traditional Component Algorithms The following traditional component algorithms are used with Composite FrodoKEM: RSA-OAEP: RSA encryption scheme with Optimal Asymmetric Encryption Padding. When used as a KEM component, RSA-OAEP generates a random shared secret, encrypts it with the recipient's RSA public key, and transmits the resulting ciphertext. The RSA-OAEP parameters used with Composite FrodoKEM follow the conventions specified in RFC8017. ECDH: Elliptic Curve Diffie-Hellman key agreement using the NIST prime curves. When used as a KEM component, ECDH performs ephemeral- static key agreement and hashes the resulting shared point to produce a shared secret. X25519 and X448: Elliptic Curve Diffie-Hellman key agreement using the Curve25519 and Curve448 Montgomery curves, respectively. These are used as KEMs in a manner analogous to ECDH. 2.3. Composite FrodoKEM Construction A Composite FrodoKEM public key is a concatenation of a FrodoKEM public key and a traditional algorithm public key. A Composite FrodoKEM private key is a concatenation of the corresponding private keys. The public key and private key formats are identical for both the SHAKE and AES variants of a given parameter set; the variants are distinguished only by the algorithm identifier (OID). The encapsulation and decapsulation procedures for Composite FrodoKEM invoke the underlying component algorithms independently and then combine the resulting shared secrets using a KEM combiner (see Section 3.4). 3. Composite FrodoKEM Operations This section defines the key generation, encapsulation, decapsulation, and shared secret combiner algorithms for Composite FrodoKEM. 3.1. Key Generation The Composite FrodoKEM key generation algorithm performs the following steps: Song & Chen Expires 26 March 2027 [Page 4] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 1. Generate a FrodoKEM key pair using the parameter set implied by the algorithm identifier (SHAKE or AES variant): (frodo_pk, frodo_sk) <- FrodoKEM.KeyGen() 2. Generate a traditional algorithm key pair: (trad_pk, trad_sk) <- Trad.KeyGen() 3. The Composite FrodoKEM public key is the concatenation of the component public keys: ek = frodo_pk || trad_pk 4. The Composite FrodoKEM private key is the concatenation of the component private keys: dk = frodo_sk || trad_sk 3.2. Key Encapsulation Mechanism The Composite FrodoKEM encapsulation algorithm performs the following steps: Song & Chen Expires 26 March 2027 [Page 5] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 1. Separate the public keys based on the FrodoKEM parameter set implied by the algorithm identifier: switch FrodoKEM do case FrodoKEM-976: frodo_pk = ek[0:15632] trad_pk = ek[15632:] case FrodoKEM-1344: frodo_pk = ek[0:21520] trad_pk = ek[21520:] 2. Perform the respective component encapsulation operations according to their algorithm specifications: (frodo_ct, frodo_ss) <- FrodoKEM.Encapsulate(frodo_pk) (trad_ct, trad_ss) <- TradKEM.Encap(trad_pk) 3. If either FrodoKEM.Encapsulate() or TradKEM.Encap() return an error, then this process MUST return an error. 4. Encode the ciphertext: ct = frodo_ct || trad_ct 5. Combine the KEM secrets and additional context to yield the composite shared secret (see Section 3.4): ss = SHA3-256(frodo_ss || trad_ss || trad_ct || trad_pk || Label) 6. Output composite shared secret key and ciphertext: return (ss, ct) 3.3. Key Decapsulation Mechanism The Composite FrodoKEM decapsulation algorithm performs the following steps: Song & Chen Expires 26 March 2027 [Page 6] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 1. Separate the private keys based on the FrodoKEM parameter set implied by the algorithm identifier: switch FrodoKEM do case FrodoKEM-976: frodo_sk = dk[0:31296] trad_sk = dk[31296:] case FrodoKEM-1344: frodo_sk = dk[0:43088] trad_sk = dk[43088:] 2. Separate the ciphertext into its components based on the FrodoKEM parameter set implied by the algorithm identifier: switch FrodoKEM do case FrodoKEM-976: frodo_ct = ct[0:15792] trad_ct = ct[15792:] case FrodoKEM-1344: frodo_ct = ct[0:21696] trad_ct = ct[21696:] 3. Perform the respective component decapsulation operations according to their algorithm specifications: frodo_ss <- FrodoKEM.Decapsulate(frodo_sk, frodo_ct) trad_ss <- TradKEM.Decap(trad_sk, trad_ct) 4. If either FrodoKEM.Decapsulate() or TradKEM.Decap() return an error, then this process MUST return an error. 5. Combine the KEM secrets and additional context to yield the composite shared secret (see Section 3.4): ss = SHA3-256(frodo_ss || trad_ss || trad_ct || trad_pk || Label) 6. Output composite shared secret key: return ss 3.4. Key Combiner The KEM combiner takes as input the shared secrets and ciphertext from the component algorithms and produces a single composite shared secret. For all Composite FrodoKEM algorithms specified in this document, the combiner is defined as follows: Song & Chen Expires 26 March 2027 [Page 7] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 ss = SHA3-256(frodo_ss || trad_ss || trad_ct || trad_pk || Label) where: o frodo_ss is the shared secret output from the FrodoKEM component. o trad_ss is the shared secret output from the traditional component. o trad_ct is the ciphertext output from the traditional component. o trad_pk is the public key of the traditional component. o Label is the KEM Combiner Label value defined in Section 5.2. o || denotes concatenation. o SHA3-256 is the SHA3-256 hash function [FIPS202]. The inclusion of the traditional ciphertext, traditional public key, and Label in the combiner input provides binding between the shared secret and the specific keying material, mitigating risks from partial key compromise. The same combiner is used for both the SHAKE and AES variants of Composite FrodoKEM. 4. Key Format 4.1. Public Key Format The Composite FrodoKEM public key is a concatenation of the component public keys: CompositeFrodoKEMPublicKey ::= BIT STRING The value of the BIT STRING is: bytes = frodo_pk || trad_pk where frodo_pk is the raw FrodoKEM public key bytes and trad_pk is the traditional algorithm public key in its native encoding. For ECDH and RSA-OAEP components, the trad_pk is encoded according to [RFC5480] and [RFC8017], respectively. For X25519 and X448 components, the trad_pk is the 32-octet or 56-octet Montgomery u-coordinate, respectively. Song & Chen Expires 26 March 2027 [Page 8] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 When carried in an X.509 SubjectPublicKeyInfo structure [RFC5280], the algorithm field contains the Composite FrodoKEM OID, and the subjectPublicKey field contains the CompositeFrodoKEMPublicKey. 4.2. Private Key Format The Composite FrodoKEM private key is a concatenation of the component private keys: CompositeFrodoKEMPrivateKey ::= OCTET STRING The value of the OCTET STRING is: bytes = frodo_sk || trad_sk where frodo_sk is the raw FrodoKEM private key bytes and trad_sk is the traditional algorithm private key in its native encoding. When carried in an Asymmetric Key Package [RFC5958], the privateKeyAlgorithm field is set to the corresponding Composite FrodoKEM algorithm identifier, the privateKey field contains the CompositeFrodoKEMPrivateKey, and the publicKey field contains the CompositeFrodoKEMPublicKey. 4.3. Encoding Rules All ASN.1 objects SHALL be encoded using DER on serialization. The deserialization routines do not check for well-formedness of the cryptographic material they are recovering. It is assumed that underlying cryptographic primitives will catch malformed values and raise an appropriate error. 5. Algorithm Identifiers 5.1. Composite FrodoKEM Algorithm Identifiers The following object identifiers are assigned for Composite FrodoKEM algorithms. For each FrodoKEM parameter set and traditional algorithm combination, two variants are defined: a SHAKE variant and an AES variant. The SHAKE variants use FrodoKEM with SHAKE as the internal pseudorandom function; the AES variants use FrodoKEM with AES as the internal pseudorandom function. The two variants are not interoperable and are assigned distinct object identifiers. Song & Chen Expires 26 March 2027 [Page 9] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 -- SHAKE Variants id-FrodoKEM976-RSA2048-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD1 } id-FrodoKEM976-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD2 } id-FrodoKEM976-RSA4096-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD3 } id-FrodoKEM976-X25519-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD4 } id-FrodoKEM976-ECDH-P256-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD5 } id-FrodoKEM976-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD6 } id-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD7 } id-FrodoKEM1344-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD8 } id-FrodoKEM1344-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD9 } id-FrodoKEM1344-ECDH-brainpoolP384r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD10 } id-FrodoKEM1344-X448-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD11 } Song & Chen Expires 26 March 2027 [Page 10] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 id-FrodoKEM1344-ECDH-P521-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD12 } -- AES Variants id-FrodoKEM976-AES-RSA2048-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD13 } id-FrodoKEM976-AES-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD14 } id-FrodoKEM976-AES-RSA4096-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD15 } id-FrodoKEM976-AES-X25519-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD16 } id-FrodoKEM976-AES-ECDH-P256-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD17 } id-FrodoKEM976-AES-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD18 } id-FrodoKEM976-AES-ECDH-brainpoolP256r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD19 } id-FrodoKEM1344-AES-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD20 } id-FrodoKEM1344-AES-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD21 } id-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD22 } Song & Chen Expires 26 March 2027 [Page 11] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 id-FrodoKEM1344-AES-X448-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD23 } id-FrodoKEM1344-AES-ECDH-P521-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD24 } The parameters field for all Composite FrodoKEM algorithm identifiers MUST be absent. 5.2. KEM Combiner Labels For each Composite FrodoKEM algorithm, a KEM Combiner Label is used within the KEM combiner to bind the shared secret to the specific algorithm. The Label is a fixed ASCII string that uniquely identifies the composite algorithm. The Label values are provided in two forms: where the label value is alphanumeric ASCII, they are represented below as strings. Where the label value contains problematic characters, such as backslashes, they are represented directly in hexadecimal to avoid transcription errors. For example, the Label for id-FrodoKEM976-ECDH-P384-SHA3-256 is "FrodoKEM976-P384", the label for id-FrodoKEM976-RSA2048-SHA3-256 is "FrodoKEM976-RSA2048". Because the SHAKE and AES variants have distinct object identifiers, they produce distinct Label values, ensuring that shared secrets derived from the two variants are cryptographically separated. 6. ASN.1 Module Composite FrodoKEM uses a substantially non-ASN.1 based encoding, as specified in [I-D.ietf-lamps-pq-composite-kem], leading to a smaller overall ASN.1 module. Composite-FrodoKEM-2026 { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) id-mod(0) id-mod-composite-frodokem-2026(TBDMOD) } DEFINITIONS IMPLICIT TAGS ::= BEGIN Song & Chen Expires 26 March 2027 [Page 12] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 EXPORTS ALL; IMPORTS PUBLIC-KEY, AlgorithmIdentifier{}, SMIME-CAPS FROM AlgorithmInformation-2009 { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) id-mod(0) id-mod-algorithmInformation-02(58) } KEM-ALGORITHM FROM KEMAlgorithmInformation-2023 { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) id-mod(0) id-mod-kemAlgorithmInformation-2023(109) } ; -- -- Information Object Classes -- pk-CompositeKEM {OBJECT IDENTIFIER:id} PUBLIC-KEY ::= { IDENTIFIER id -- KEY no ASN.1 wrapping -- PARAMS ARE absent CERT-KEY-USAGE { keyEncipherment } -- PRIVATE-KEY no ASN.1 wrapping -- } kema-CompositeKEM { OBJECT IDENTIFIER:id, PUBLIC-KEY:publicKeyType } KEM-ALGORITHM ::= { IDENTIFIER id -- VALUE no ASN.1 wrapping -- PARAMS ARE absent PUBLIC-KEYS { publicKeyType } SMIME-CAPS { IDENTIFIED BY id } } -- -- SHAKE Variants -- Song & Chen Expires 26 March 2027 [Page 13] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 id-FrodoKEM976-RSA2048-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD1 } pk-FrodoKEM976-RSA2048-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-RSA2048-SHA3-256 } kema-FrodoKEM976-RSA2048-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-RSA2048-SHA3-256, pk-FrodoKEM976-RSA2048-SHA3-256 } id-FrodoKEM976-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD2 } pk-FrodoKEM976-RSA3072-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-RSA3072-SHA3-256 } kema-FrodoKEM976-RSA3072-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-RSA3072-SHA3-256, pk-FrodoKEM976-RSA3072-SHA3-256 } id-FrodoKEM976-RSA4096-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD3 } pk-FrodoKEM976-RSA4096-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-RSA4096-SHA3-256 } kema-FrodoKEM976-RSA4096-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-RSA4096-SHA3-256, pk-FrodoKEM976-RSA4096-SHA3-256 } id-FrodoKEM976-X25519-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD4 } pk-FrodoKEM976-X25519-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-X25519-SHA3-256 } kema-FrodoKEM976-X25519-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-X25519-SHA3-256, pk-FrodoKEM976-X25519-SHA3-256 } Song & Chen Expires 26 March 2027 [Page 14] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 id-FrodoKEM976-ECDH-P256-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD5 } pk-FrodoKEM976-ECDH-P256-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-ECDH-P256-SHA3-256 } kema-FrodoKEM976-ECDH-P256-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-ECDH-P256-SHA3-256, pk-FrodoKEM976-ECDH-P256-SHA3-256 } id-FrodoKEM976-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD6 } pk-FrodoKEM976-ECDH-P384-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-ECDH-P384-SHA3-256 } kema-FrodoKEM976-ECDH-P384-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-ECDH-P384-SHA3-256, pk-FrodoKEM976-ECDH-P384-SHA3-256 } id-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD7 } pk-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256 } kema-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256, pk-FrodoKEM976-ECDH-brainpoolP256r1-SHA3-256 } id-FrodoKEM1344-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD8 } pk-FrodoKEM1344-RSA3072-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-RSA3072-SHA3-256 } kema-FrodoKEM1344-RSA3072-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-RSA3072-SHA3-256, Song & Chen Expires 26 March 2027 [Page 15] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 pk-FrodoKEM1344-RSA3072-SHA3-256 } id-FrodoKEM1344-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD9 } pk-FrodoKEM1344-ECDH-P384-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-ECDH-P384-SHA3-256 } kema-FrodoKEM1344-ECDH-P384-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-ECDH-P384-SHA3-256, pk-FrodoKEM1344-ECDH-P384-SHA3-256 } id-FrodoKEM1344-ECDH-brainpoolP384r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD10 } pk-FrodoKEM1344-ECDH-brainpoolP384r1-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-brainpoolP384r1-P384-SHA3-256 } kema-FrodoKEM1344-ECDH-brainpoolP384r1-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-ECDH-brainpoolP384r1-SHA3-256, pk-FrodoKEM1344-ECDH-brainpoolP384r1-SHA3-256 } id-FrodoKEM1344-X448-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD11 } pk-FrodoKEM1344-X448-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-X448-SHA3-256 } kema-FrodoKEM1344-X448-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-X448-SHA3-256, pk-FrodoKEM1344-X448-SHA3-256 } id-FrodoKEM1344-ECDH-P521-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD12 } pk-FrodoKEM1344-ECDH-P521-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-ECDH-P521-SHA3-256 } kema-FrodoKEM1344-ECDH-P521-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { Song & Chen Expires 26 March 2027 [Page 16] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 id-FrodoKEM1344-ECDH-P521-SHA3-256, pk-FrodoKEM1344-ECDH-P521-SHA3-256 } -- -- AES Variants -- id-FrodoKEM976-AES-RSA2048-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD13 } pk-FrodoKEM976-AES-RSA2048-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-RSA2048-SHA3-256 } kema-FrodoKEM976-AES-RSA2048-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-RSA2048-SHA3-256, pk-FrodoKEM976-AES-RSA2048-SHA3-256 } id-FrodoKEM976-AES-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD14 } pk-FrodoKEM976-AES-RSA3072-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-RSA3072-SHA3-256 } kema-FrodoKEM976-AES-RSA3072-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-RSA3072-SHA3-256, pk-FrodoKEM976-AES-RSA3072-SHA3-256 } id-FrodoKEM976-AES-RSA4096-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD15 } pk-FrodoKEM976-AES-RSA4096-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-RSA4096-SHA3-256 } kema-FrodoKEM976-AES-RSA4096-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-RSA4096-SHA3-256, pk-FrodoKEM976-AES-RSA4096-SHA3-256 } id-FrodoKEM976-AES-X25519-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD16 } Song & Chen Expires 26 March 2027 [Page 17] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 pk-FrodoKEM976-AES-X25519-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-X25519-SHA3-256 } kema-FrodoKEM976-AES-X25519-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-X25519-SHA3-256, pk-FrodoKEM976-AES-X25519-SHA3-256 } id-FrodoKEM976-AES-ECDH-P256-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD17 } pk-FrodoKEM976-AES-ECDH-P256-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-ECDH-P256-SHA3-256 } kema-FrodoKEM976-AES-ECDH-P256-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-ECDH-P256-SHA3-256, pk-FrodoKEM976-AES-ECDH-P256-SHA3-256 } id-FrodoKEM976-AES-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD18 } pk-FrodoKEM976-AES-ECDH-P384-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-ECDH-P384-SHA3-256 } kema-FrodoKEM976-AES-ECDH-P384-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-ECDH-P384-SHA3-256, pk-FrodoKEM976-AES-ECDH-P384-SHA3-256 } id-FrodoKEM976-AES-ECDH-brainpoolP256r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD19 } pk-FrodoKEM976-AES-ECDH-brainpoolP256r1-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM976-AES-ECDH-P384-SHA3-256 } kema-FrodoKEM976-AES-ECDH-brainpoolP256r1-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM976-AES-ECDH-brainpoolP256r1-SHA3-256, pk-FrodoKEM976-AES-ECDH-brainpoolP256r1-SHA3-256 } id-FrodoKEM1344-AES-RSA3072-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD20 } Song & Chen Expires 26 March 2027 [Page 18] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 pk-FrodoKEM1344-AES-RSA3072-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-AES-RSA3072-SHA3-256 } kema-FrodoKEM1344-AES-RSA3072-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-AES-RSA3072-SHA3-256, pk-FrodoKEM1344-AES-RSA3072-SHA3-256 } id-FrodoKEM1344-AES-ECDH-P384-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD21 } pk-FrodoKEM1344-AES-ECDH-P384-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-AES-ECDH-P384-SHA3-256 } kema-FrodoKEM1344-AES-ECDH-P384-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-AES-ECDH-P384-SHA3-256, pk-FrodoKEM1344-AES-ECDH-P384-SHA3-256 } id-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD22 } pk-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256 } kema-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256, pk-FrodoKEM1344-AES-ECDH-brainpoolP384r1-SHA3-256 } id-FrodoKEM1344-AES-X448-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) mechanisms(5) pkix(7) alg(6) TBD23 } pk-FrodoKEM1344-AES-X448-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-AES-X448-SHA3-256 } kema-FrodoKEM1344-AES-X448-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-AES-X448-SHA3-256, pk-FrodoKEM1344-AES-X448-SHA3-256 } id-FrodoKEM1344-AES-ECDH-P521-SHA3-256 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) dod(6) internet(1) security(5) Song & Chen Expires 26 March 2027 [Page 19] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 mechanisms(5) pkix(7) alg(6) TBD24 } pk-FrodoKEM1344-AES-ECDH-P521-SHA3-256 PUBLIC-KEY ::= pk-CompositeKEM { id-FrodoKEM1344-AES-ECDH-P521-SHA3-256 } kema-FrodoKEM1344-AES-ECDH-P521-SHA3-256 KEM-ALGORITHM ::= kema-CompositeKEM { id-FrodoKEM1344-AES-ECDH-P521-SHA3-256, pk-FrodoKEM1344-AES-ECDH-P521-SHA3-256 } END 7. Security Considerations The Security Considerations for implementing a composite algorithm defined in [I-D.ietf-lamps-pq-composite-kem] apply to this document. Additional security considerations specific to FrodoKEM, including side-channel resistance, fault attack mitigations, and parameter set selection guidance, discussed in [I-D.longa-cfrg-frodokem-security-considerations] and [I-D.smyslov-lamps-frodokem-certificates] apply to this specification as well. 8. IANA Considerations 8.1. PKIX Module Identifier Registry IANA is requested to allocate a value from the "SMI Security for PKIX Module Identifier" registry for the ASN.1 module defined in Section 6. +=========+================================+===============+ | Decimal | Description | References | +=========+================================+===============+ | TBDMOD | id-mod-composite-frodokem-2026 | This Document | +---------+--------------------------------+---------------+ Table 1: SMI Security for PKIX Module Identifier 8.2. PKIX Algorithm Registry IANA is requested to allocate values from the "SMI Security for PKIX Algorithm" registry (1.3.6.1.5.5.7.6) for the Composite FrodoKEM algorithm identifiers listed in Section 5.1. Song & Chen Expires 26 March 2027 [Page 20] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 +=========+===================================+===============+ | Decimal | Description | References | +=========+===================================+===============+ | TBD1 | id-FrodoKEM976-RSA2048-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD2 | id-FrodoKEM976-RSA3072-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD3 | id-FrodoKEM976-RSA4096-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD4 | id-FrodoKEM976-X25519-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD5 | id-FrodoKEM976-ECDH-P256-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD6 | id-FrodoKEM976-ECDH-P384-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD7 | id-FrodoKEM976-ECDH- | This Document | | | brainpoolP256r1-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD8 | id-FrodoKEM1344-RSA3072-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD9 | id-FrodoKEM1344-ECDH- | This Document | | | P384-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD10 | id-FrodoKEM1344-ECDH- | This Document | | | brainpoolP384r1-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD11 | id-FrodoKEM1344-X448-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD12 | id-FrodoKEM1344-ECDH- | This Document | | | P521-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD13 | id-FrodoKEM976-AES- | This Document | | | RSA2048-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD14 | id-FrodoKEM976-AES- | This Document | | | RSA3072-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD15 | id-FrodoKEM976-AES- | This Document | | | RSA4096-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD16 | id-FrodoKEM976-AES- | This Document | | | X25519-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD17 | id-FrodoKEM976-AES-ECDH- | This Document | | | P256-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD18 | id-FrodoKEM976-AES-ECDH- | This Document | | | P384-SHA3-256 | | Song & Chen Expires 26 March 2027 [Page 21] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 +---------+-----------------------------------+---------------+ | TBD19 | id-FrodoKEM976-AES-ECDH- | This Document | | | brainpoolP256r1-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD20 | id-FrodoKEM1344-AES- | This Document | | | RSA3072-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD21 | id-FrodoKEM1344-AES-ECDH- | This Document | | | P384-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD22 | id-FrodoKEM1344-AES-ECDH- | This Document | | | brainpoolP384r1-SHA3-256 | | +---------+-----------------------------------+---------------+ | TBD23 | id-FrodoKEM1344-AES-X448-SHA3-256 | This Document | +---------+-----------------------------------+---------------+ | TBD24 | id-FrodoKEM1344-AES-ECDH- | This Document | | | P521-SHA3-256 | | +---------+-----------------------------------+---------------+ Table 2: SMI Security for PKIX Algorithm 9. References 9.1. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, . [RFC5280] Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., and W. Polk, "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile", RFC 5280, DOI 10.17487/RFC5280, May 2008, . [RFC5480] Turner, S., Brown, D., Yiu, K., Housley, R., and T. Polk, "Elliptic Curve Cryptography Subject Public Key Information", RFC 5480, DOI 10.17487/RFC5480, March 2009, . [RFC5958] Turner, S., "Asymmetric Key Packages", RFC 5958, DOI 10.17487/RFC5958, August 2010, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, May 2017, . Song & Chen Expires 26 March 2027 [Page 22] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 9.2. Informative References [I-D.ietf-lamps-pq-composite-kem] Ounsworth, M., Gray, J., Pala, M., Klaussner, J., and S. Fluhrer, "Composite ML-KEM for use in X.509 Public Key Infrastructure", Work in Progress, Internet-Draft, draft- ietf-lamps-pq-composite-kem-21, 1 September 2026, . [I-D.longa-cfrg-frodokem] Longa, P. and J. W. Bos, "FrodoKEM: key encapsulation from learning with errors", Work in Progress, Internet-Draft, draft-longa-cfrg-frodokem-03, 22 June 2026, . [I-D.longa-cfrg-frodokem-security-considerations] Longa, P., Bos, J. W., Ehlen, S., and D. Stebila, "Security Considerations for FrodoKEM", Work in Progress, Internet-Draft, draft-longa-cfrg-frodokem-security- considerations-00, 22 June 2026, . [I-D.smyslov-lamps-frodokem-certificates] Smyslov, V., "Internet X.509 Public Key Infrastructure - Algorithm Identifiers for FrodoKEM", Work in Progress, Internet-Draft, draft-smyslov-lamps-frodokem-certificates- 03, 6 July 2026, . [ISO18033-2-AMD2] ISO, "ISO/IEC 18033-2:2006/Amd 2:2026 Information technology - Security techniques - Encryption algorithms - Part 2: Asymmetric ciphers, Amendment 2", June 2026, . [RFC8017] Moriarty, K., Ed., Kaliski, B., Jonsson, J., and A. Rusch, "PKCS #1: RSA Cryptography Specifications Version 2.2", RFC 8017, DOI 10.17487/RFC8017, November 2016, . [RFC9629] Housley, R., Gray, J., and T. Okubo, "Using Key Encapsulation Mechanism (KEM) Algorithms in the Cryptographic Message Syntax (CMS)", RFC 9629, DOI 10.17487/RFC9629, August 2024, . Song & Chen Expires 26 March 2027 [Page 23] Internet-Draft Composite FrodoKEM for X.509 PKI September 2026 Authors' Addresses Xueyan Song ZTE Corp. China Email: song.xueyan2@zte.com.cn Meiling Chen China Mobile China Email: chenmeiling@chinamobile.com Song & Chen Expires 26 March 2027 [Page 24]