Pith. sign in

REVIEW 3 cited by

Quantum-Safe Hybrid Key Exchanges with KEM-Based Authentication

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2411.04030 v2 pith:ISIHHZ5P submitted 2024-11-06 cs.CR quant-ph

classification cs.CRquant-ph
keywords mucklehakepost-quantumauthenticationhybridlargenetworksnovel
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Authenticated Key Exchange (AKE) between any two entities is one of the most important security protocols available for securing our digital networks and infrastructures. In PQCrypto 2023, Bruckner, Ramacher and Striecks proposed a novel hybrid AKE (HAKE) protocol, dubbed Muckle+, that is particularly useful in large quantum-safe networks consisting of a large number of nodes. Their protocol is hybrid in the sense that it allows key material from conventional and post-quantum primitives, as well as from quantum key distribution, to be incorporated into a single end-to-end shared key. To achieve the desired authentication properties, Muckle+ utilizes post-quantum digital signatures. However, available instantiations of such signatures schemes are not yet efficient enough compared to their post-quantum key-encapsulation mechanism (KEM) counterparts, particularly in large networks with potentially several connections in a short period of time. To mitigate this gap, we propose Muckle# that pushes the efficiency boundaries of currently known HAKE constructions. Muckle# uses post-quantum key-encapsulating mechanisms for implicit authentication inspired by recent works done in the area of Transport Layer Security (TLS) protocols, particularly, in KEMTLS (CCS'20). We port those ideas to the HAKE framework and develop novel proof techniques on the way. Due to our novel KEM-based approach, the resulting protocol has a slightly different message flow compared to prior work that we carefully align with the HAKE framework and which makes our changes to the Muckle+ non-trivial.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. On Post-Quantum Cryptography Authentication for Quantum Key Distribution

    quant-ph 2025-07 conditional novelty 6.0 of 10

    PQC-based authentication protocols for QKD are proven secure in a hybrid adversary model, yielding information-theoretic keys only against a restricted adversary.

  2. Versatile Quantum-Safe Hybrid Key Exchange and Its Application to MACsec

    quant-ph 2025-05 conditional novelty 5.0 of 10

    VMuckle adapts the Muckle+ hybrid authenticated key exchange so a single run can use PSK, post-quantum signatures, or both, and uses this to give MACsec a quantum-safe root key.

  3. Are Enterprises Ready for Quantum-Safe Cybersecurity?

    cs.CR 2025-09 conditional novelty 3.0 of 10

    A survey-based review concludes that enterprise readiness for quantum-safe cryptography is uneven and generally insufficient, with fewer than 5% having transition plans.

Pith tools