arrow
Return

Integrating code-based post-quantum cryptography into SSL TLS protocols through an interoperable hybrid framework

delete2025-09-21
delete0
PRE
AI
Z
Zafar, Aasim
S
Syed Shamikh Iqbal *
DOI:10.1007/s10791-025-09735-7delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The advancement of quantum computing creates a big threat to classical cryptographic protocols, including TLS, which is responsible for secure internet communications. While recent industry and academic efforts have focused on integrating lattice-based post-quantum key encapsulation mechanisms (KEMs) such as Kyber+X25519 into hybrid TLS handshakes, these approaches often prioritize performance at the cost of cryptanalytic diversity. Code-based KEMs, despite their proven security measure they remain underexplored in hybrid frameworks due to some limitations like large key sizes and integration complexity. This paper proposes a novel hybrid TLS framework that explicitly incorporates code-based post-quantum cryptography-specifically McEliece-alongside classical key exchange mechanisms. The framework introduces a dual-handshake mechanism, adaptive parameter selection, and seamless fallback negotiation, enabling flexible deployment across heterogeneous networks while ensuring backward compatibility. Integration with Quantum Random Number Generators (QRNGs) and multifactor authentication further increases entropy quality and session security. We implemented and evaluated the framework using an OpenSSL-OQS integration. We measure handshake latency, CPU utilization, memory usage, and throughput across emulated and real-world testbeds. Results show that the proposed hybrid approach achieves up to 30% lower latency and significantly reduced resource overhead compared to pure post-quantum TLS variants, while maintaining near-classical efficiency levels. Mathematical modeling formalizes these trade-offs which offers a foundation for optimizing deployment in both resource-constrained IoT devices and high-performance servers. By advancing cryptographic diversity and aligning with emerging NIST and IETF standardization efforts, the proposed framework provides a practical pathway toward quantum-resilient secure communication.It shows that code-based post-quantum cryptography can be added to current TLS systems without any problems, keeping security, performance, and compatibility in mind as we get ready for the quantum age.
Keywords:
Post-quantum cryptography (PQC)
Code-Based Cryptography
Hybrid Cryptographic Framework
SSL/TLS Protocols
Quantum-Resistant Communication
Quantum Random Number Generators (QRNGs)
Multifactor Authentication (MFA)

Journal

D
Discover Computing
IF:
0
Papers:
430
Citations:
8

Organization

No organization information available
Cited Papers

Cited Papers

Status report on the third round of the NIST Post-Quantum Cryptography Standardization process
err
IF0
err2022-09-29
err0
errOAAI
errGorjan Alagic; Daniel Apon; David Cooper; Quynh Dang; Thinh Dang; John Kelsey; Jacob Lichtinger; Yi-Kai Liu; Carl Miller; Dustin Moody; Rene Peralta; Ray Perlner; Angela Robinson; Daniel Smith-Tone
errShare
errSave
err
IF0
err
err0
PREAI
err
errShare
errSave
errShare
errSave
Evaluating integration methods of a quantum random number generator in OpenSSL for TLS
err2024-12-01
err0
PREAI
errBlanco-Romero,Javier; Lorenzo,Vicente; Almenares,Florina; Díaz-Sánchez,Daniel; Rubio,Carlos García; Campo,Celeste; Marín,Andrés
errShare
errSave
errShare
errSave
Efficient and Side-Channel Resistant Ed25519 on ARM Cortex-M4
err2024-06-01
err3
PREAI
errOwens, Daniel; Khatib, Rabih El; Bisheh-Niasar, Mojtaba; Azarderakhsh, Reza; Kermani, Mehran Mozaffari
errShare
errSave
err
IF0
err
err0
PREAI
err
errShare
errSave
researcher View more