Paper 2026/1231

The Best of Both Worlds: Hybrid Authenticated Key Exchange for QKD(N) without Signatures

Sebastian Clermont, TU Darmstadt
Johanna Henrich, Darmstadt University of Applied Sciences
Abstract

Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) are both contenders for securing communication against quantum adversaries, but are at different stages of maturity. For hedging security risks, hybridization is the default approach. Unlike previous research on classical–post-quantum hybrids, we propose a QKD-PQC hybrid for Authenticated Key Exchange (AKE). To minimize the attack surface, we completely remove the requirement for digital signature schemes and propose a Hybrid Authenticated Key Exchange (HAKE) that combines Post-Quantum (PQ) AKE and QKD key agreement, leveraging Key Encapsulation Mechanisms (KEMs) for both key exchange and authentication. Our fully modular security analysis, based on the recent multi-input Key Derivation Function (KDF) framework by Backendal et al. (Eurocrypt 2025), establishes AKE security in the CK01 model and yields a conditional information-theoretic security guarantee when the QKD component is uncompromised; a property not achieved by prior hybrid protocols. We demonstrate the protocol’s practical feasibility with benchmarks using ML-KEM, FrodoKEM, and Classic McEliece.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. Africacrypt 2026
Keywords
Hybrid Authenticated Key ExchangeKey CombinerQuantum Key Distribution
Contact author(s)
sebastian clermont @ tu-darmstadt de
johanna henrich @ h-da de
History
2026-06-11: approved
2026-06-10: received
See all versions
Short URL
https://ia.cr/2026/1231
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/1231,
      author = {Sebastian Clermont and Johanna Henrich},
      title = {The Best of Both Worlds: Hybrid Authenticated Key Exchange for {QKD}(N) without Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1231},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1231}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.