{
  "fills_gap": "First machine-checked analysis of the FINALIZED multi-KE. The only prior formal analysis (Gazdag et al., ACSAC 2021) modeled a SINGLE additional KE on a superseded 2019/2020 draft and explicitly deferred the multi-KE case to future work.",
  "honest_scope": "Symbolic model of a SIMPLIFIED IKEv2 (not the full protocol); classical Dolev-Yao attacker only. The active-CRQC downgrade (attacker breaks the classical KE in real time AND holds/breaks the long-term auth key) is OUT OF SCOPE \u2014 it is already public and WG-owned (RFC 9370 \u00a75; draft-ietf-ipsecme-ikev2-downgrade-prevention). A symbolic reachability check, not a computational proof; teeth-verified.",
  "main_model": "ikev2_rfc9370_multi_ke_downgrade_hunt.pv",
  "main_verdict": "RESIST",
  "module": "ikev2_rfc9370_downgrade",
  "prover": "ProVerif (real binary, via make outward-provers)",
  "resist_cert_valid": true,
  "result": "The finalized RFC 9370 multi-KE RESISTS classical-MITM downgrade (a Dolev-Yao attacker cannot force two ML-KEM-supporting peers into a classical-only session while both AUTH verify), and the teeth control confirms this is caused by AUTH covering the negotiated additional-KE transforms + IntAuth \u2014 not a modeling artifact.",
  "sprint": 140,
  "status": "a machine-checked resist-certificate on a THIRD-PARTY deployed protocol (strongSwan 6.0, Palo Alto). Not a break; not estate IP. No legal/novelty/FTO/essentiality/price conclusion.",
  "target": "IKEv2 multiple key exchanges \u2014 FINALIZED RFC 9370 + RFC 9242 IntAuth (classical-MITM downgrade)",
  "teeth_model": "ikev2_no_transform_binding_teeth_hunt.pv",
  "teeth_verdict": "BREAK"
}
