Douglas Stebila
Hybrid key exchange in TLS 1.3
Abstract
Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum cryptography. This document provides a construction for hybrid key exchange in the Transport Layer Security (TLS) protocol version 1.3.
Keywords: key exchange, Transport Layer Security (TLS), post-quantum cryptography
Reference
Douglas Stebila, Scott Fluhrer, Shay Gueron. Hybrid key exchange in TLS 1.3. RFC 9954. Internet Engineering Task Force, July 2026. © IETF Trust and the authors.
Download
Presentations
- 2022-06-27: European Space Agency workshop on Secure Communications for Space Missions in the Post-Quantum Era. (PDF slides)
- 2021-07-28: IETF 111. (PDF slides)
- 2019-07-25: IETF 105, Montreal, Canada. (PDF slides)