Paper 2026/1754

SoK: Why Optimal Cryptographic Combiners Do Not Get Deployed: Security, Complexity, and Adoption of Hybrid KEMs

Merland Chrislain Chadrel BAFOUETILA, IRT SYSTEMX , Palaiseau, FRANCE
Anis BKAKRIA, IRT SYSTEMX, Palaiseau, FRANCE
Abstract

XtM (XOR-then-MAC) is provably optimal against quantum adversaries. As of March 2025, no production cryptographic library implements it. HKDF, with weaker security guarantees, is deployed in 91% of the 44 libraries we examined. This gap is not accidental.This Systematization of Knowledge (SoK) introduces the (A, P, φ) framework to explain it: A measures authentication strength, P measures IETF standardization maturity, and φ measures implementation complexity. To our knowledge, this is the first falsifiable, quantitative model predicting cryptographic adoption grounded in observable software engineering indicators. We apply this framework to seven combiner families and 44 cryptographic libraries, validate φ against measured integration LOC across 9 real-world repositories, and derive predictions verifiable by 2028.Our evidence suggests that implementation complexity is a first-order explanatory factor in cryptographic adoption. The most deployable construction is not the most secure one in isolation: it is the most secure one engineers can integrate, audit, and maintain at scale.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
hybrid KEMpost-quantum cryptographycryptographic combinersHKDFXTMTLS 1.3systematization of knowledge
Contact author(s)
chadrelbafouetila @ gmail com
anisbkakria @ irt-systemx fr
History
2026-08-22: revised
2026-08-20: received
See all versions
Short URL
https://ia.cr/2026/1754
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1754,
      author = {Merland Chrislain Chadrel BAFOUETILA and Anis BKAKRIA},
      title = {{SoK}: Why Optimal Cryptographic Combiners Do Not Get Deployed: Security, Complexity, and Adoption of Hybrid {KEMs}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1754},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1754}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.