Paper 2026/1231
The Best of Both Worlds: Hybrid Authenticated Key Exchange for QKD(N) without Signatures
Abstract
Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) are both contenders for securing communication against quantum adversaries, but are at different stages of maturity. For hedging security risks, hybridization is the default approach. Unlike previous research on classical–post-quantum hybrids, we propose a QKD-PQC hybrid for Authenticated Key Exchange (AKE). To minimize the attack surface, we completely remove the requirement for digital signature schemes and propose a Hybrid Authenticated Key Exchange (HAKE) that combines Post-Quantum (PQ) AKE and QKD key agreement, leveraging Key Encapsulation Mechanisms (KEMs) for both key exchange and authentication. Our fully modular security analysis, based on the recent multi-input Key Derivation Function (KDF) framework by Backendal et al. (Eurocrypt 2025), establishes AKE security in the CK01 model and yields a conditional information-theoretic security guarantee when the QKD component is uncompromised; a property not achieved by prior hybrid protocols. We demonstrate the protocol’s practical feasibility with benchmarks using ML-KEM, FrodoKEM, and Classic McEliece.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Minor revision. Africacrypt 2026
- Keywords
- Hybrid Authenticated Key ExchangeKey CombinerQuantum Key Distribution
- Contact author(s)
-
sebastian clermont @ tu-darmstadt de
johanna henrich @ h-da de - History
- 2026-06-11: approved
- 2026-06-10: received
- See all versions
- Short URL
- https://ia.cr/2026/1231
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2026/1231,
author = {Sebastian Clermont and Johanna Henrich},
title = {The Best of Both Worlds: Hybrid Authenticated Key Exchange for {QKD}(N) without Signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1231},
year = {2026},
url = {https://eprint.iacr.org/2026/1231}
}