Hybrid Key Establishment in Production: Post-Quantum Cryptography

Added:

Speaker Introduction
Threat and Solutions
NIST Standards
Hybrid Advantages
Protocol Integration
Binding Properties
Hybrid KEM Designs
Q&A Insights

Speaker Introduction

0:09
Playing Section
  • 1

    Session begins with host introducing the speaker and topic on hybrid quantum-resistant cryptography.

  • 2

    Speaker's background is in cryptography and migrating protocols to quantum-resilient postures.

Fundamental principles of public-key cryptography, including Diffie-Hellman (DH) key exchange and Elliptic Curve Cryptography (ECC).
The theoretical threat of quantum computing to classical cryptography, specifically Shor's algorithm and its impact on RSA and ECC security.
Basic understanding of Key Encapsulation Mechanisms (KEMs) and how they differ from traditional interactive key exchange protocols.
Familiarity with network security protocols, particularly TLS (Transport Layer Security) handshakes and how session keys are established.
Advanced deployment strategies for migrating existing enterprise networks to post-quantum standards, following NIST migration frameworks.
Exploration of post-quantum digital signature schemes (such as ML-DSA and SPHINCS+) for authentication, complementing hybrid key agreements.
Performance and latency optimization techniques for handling larger post-quantum key sizes in bandwidth-constrained or IoT environments.
Design principles of cryptographic agility, enabling software architectures to easily swap algorithms as post-quantum standards evolve.
14.7K views40likes52:00@durumcrustulumOriginal Release: 2025-08-27

Hybrid key establishment combines classical and post-quantum cryptographic primitives to protect against quantum attacks while maintaining backward compatibility with existing protocols. This approach addresses the 'harvest now, decrypt later' threat where adversaries can store encrypted traffic today and decrypt it with future quantum computers. The presentation covers practical implementations including TLS 1.3's integration of Kyber with elliptic curve Diffie-Hellman, Apple's iMessage PQ3 update, and Signal's post-quantum enhancements. Key considerations include binding properties beyond IND-CCA security, implicit versus explicit rejection mechanisms, and the trade-offs between bespoke protocol integrations and generic hybrid KEM constructions like X-Wing.