Douglas Stebila
Post-quantum traditional (PQ/T) hybrid key agreement mechanisms for TLS 1.3
Abstract
This document defines three hybrid key agreement mechanisms for TLS 1.3 — X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 — that combine the post-quantum ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) with an ECDHE (Ephemeral Elliptic Curve Diffie-Hellman) exchange.
Keywords: key exchange, Transport Layer Security (TLS), post-quantum cryptography
Reference
Krzysztof Kwiatkowski, Panos Kampanakis, Bas Westerbaan, Douglas Stebila. Post-quantum traditional (PQ/T) hybrid key agreement mechanisms for TLS 1.3. RFC 10024. Internet Engineering Task Force, August 2026. © IETF Trust and the authors.