Paper 2026/1172

Post-Quantum Migration Strategy for RSA Encryption

Udara Pathum, WSO2
Ashen De Silva, WSO2, Northeastern University
Abstract

Organizations relying on RSA-OAEP encryption in protocols such as JWE, SAML, and OIDC face a critical challenge: transitioning to post-quantum cryptography without disrupting operational continuity. This paper presents a phased migration strategy that uses RSA-KEM-ML-KEM composite Key Encapsulation Mechanisms as an intermediary step between current RSA-OAEP encryption and the target state of pure ML-KEM adoption. We formalize the RSA-KEM-ML-KEM construction, prove IND-CCA2 security via a Split-Key PRF combiner, and integrate it into the Hybrid Public-Key Encryption (HPKE) framework. Our implementation demonstrates that composite schemes enable quantum-resistant encryption while preserving existing RSA key infrastructure, though with measurable throughput trade-offs that inform migration timelines. We analyze protocol-specific integration for JWE, SAML, and OIDC encryption use cases, providing decision frameworks for transitioning from RSA-OAEP through composite approaches to pure post-quantum encryption. This work contributes a formally analyzed transition mechanism and practical migration guidance for organizations seeking to adopt quantum-resistant encryption in RSA-dependent systems, validated through application to identity and access management protocols.

Note: Fixed incorrect table heading

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Preprint.
Keywords
Post-quantum migrationHPKERSA encryptionML-KEMIdentity protocols
Contact author(s)
hwupathum @ gmail com
desilva ashen3 @ gmail com
History
2026-06-24: revised
2026-06-04: received
See all versions
Short URL
https://ia.cr/2026/1172
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1172,
      author = {Udara Pathum and Ashen De Silva},
      title = {Post-Quantum Migration Strategy for {RSA} Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1172},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1172}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.