Resource-Aware Post-Quantum Hybrid Key Establishment with Forward-Secure Session Management
Authors: Seema Agrawal, Rahul Kumar
Certificate: View Certificate
Abstract
The transition to post-quantum cryptography (PQC) has become an immediate systems-engineering requirement because classical public-key mechanisms based on integer factorization and elliptic-curve discrete logarithms are vulnerable to sufficiently capable quantum computers. The harvest-now-decrypt-later threat further increases the urgency for long-lived confidential information. At the same time, post-quantum mechanisms introduce larger communication objects and different computational and memory requirements, making direct replacement difficult in heterogeneous and resource-constrained environments. This paper proposes a resource-aware hybrid key-establishment and session-management framework based entirely on established cryptographic primitives. The framework combines ephemeral X25519 with ML-KEM-768, binds the resulting secrets to the protocol transcript through a domain-separated HKDF-based key-combination procedure, and introduces a policy layer that selects rekey intervals according to measured resource conditions and application sensitivity. The work deliberately does not claim novelty for the X25519/ML-KEM combination itself; hybrid ECDHE-MLKEM key agreement was already being standardized in the IETF in 2024–early 2025. The research contribution is instead the experimentally testable resource-aware session-management layer. A precise threat model, protocol description, security rationale, overhead model, and reproducible evaluation methodology are provided. The manuscript does not fabricate experimental measurements; numerical results are to be obtained from the proposed implementation before submission as an empirical article.
Introduction
Public-key cryptography is a core component of secure Internet communication, cloud services, healthcare systems, industrial networks, financial applications, and the Internet of Things (IoT). Classical systems such as RSA and elliptic-curve cryptography rely on mathematical problems that are believed to be difficult for classical computers. Shor's algorithm demonstrates that sufficiently capable quantum computers would solve integer factorization and discrete logarithm problems in polynomial time, threatening widely deployed public-key mechanisms.
The risk is not limited to the time at which a cryptographically relevant quantum computer becomes available. Adversaries can collect encrypted traffic today and attempt decryption later, making long-lived information particularly exposed. This motivates migration toward post-quantum mechanisms whose security is based on problems for which efficient quantum attacks are not currently known.
NIST finalized ML-KEM, ML-DSA, and SLH-DSA as FIPS 203, FIPS 204, and FIPS 205 in August 2024. The same year, the IETF published successive Internet-Draft versions defining hybrid TLS 1.3 key-agreement groups including X25519MLKEM768, SecP256r1MLKEM768, and later SecP384r1MLKEM1024. The March 2025 draft explicitly described these groups as combinations of ML-KEM and ECDH for TLS 1.3. Thus, by April 2025, hybrid classical/PQC key establishment was already an active standardization direction rather than an unexplored concept.
Research on PQC in IoT similarly identifies resource constraints as a major deployment issue. Surveys published before May 2025 report that computational cost, memory, communication overhead, and lack of coordinated optimization remain important barriers. Recent work on IoT communication protocols has also begun evaluating PQC integration beyond TLS, including CoAP and MQTT-SN. These observations motivate a research problem focused not on inventing another KEM, but on managing standardized hybrid cryptography efficiently across heterogeneous devices.
Conclusion
The proposed research direction is intentionally conservative in its cryptographic claims. X25519/ML-KEM hybrid exchange was already described in IETF drafts by 2024 and early 2025, so it should not be presented as a new cryptographic primitive. The research novelty is the resource-aware management layer and its experimentally testable effect on long-lived secure sessions. This distinction is important for an authentic journal submission and avoids overstating novelty. The framework is particularly relevant to IoT, industrial IoT, healthcare sensors, wireless sensor networks, and other environments in which cryptographic overhead varies substantially across devices. Its principal limitation is that the adaptive policy must be implemented and benchmarked before claims of performance improvement can be made. No experimental values are fabricated in this manuscript. The completed article should report reproducible measurements, statistical analysis, implementation details, and a formal security argument for the exact protocol instantiation. In conclusion, this paper presents a resource-aware framework for deploying standardized post-quantum hybrid key establishment with controlled forward-secure session management. By treating cryptographic migration as a systems optimization problem rather than merely an algorithm-selection problem, the proposed approach provides a defensible research direction for practical PQC deployment while remaining aligned with the standards and literature available before May 2025.
References
1. National Institute of Standards and Technology, “Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM),” FIPS 203, Aug. 2024, doi: 10.6028/NIST.FIPS.203. 2. National Institute of Standards and Technology, “Module-Lattice-Based Digital Signature Standard (ML-DSA),” FIPS 204, Aug. 2024, doi: 10.6028/NIST.FIPS.204. 3. National Institute of Standards and Technology, “Stateless Hash-Based Digital Signature Standard (SLH-DSA),” FIPS 205, Aug. 2024, doi: 10.6028/NIST.FIPS.205. 4. D. Moody, R. Perlner, A. Regenscheid, A. Robinson, and D. Cooper, “Transition to Post-Quantum Cryptography Standards,” NIST IR 8547, 2024. 5. G. Alagic et al., “Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process,” NIST IR 8545, 2024. 6. K. Kwiatkowski, P. Kampanakis, B. E. Westerbaan, and D. Stebila, “Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3,” Internet-Draft, draft-kwiatkowski-tls-ecdhe-mlkem-01, Aug. 2024. 7. K. Kwiatkowski, P. Kampanakis, B. E. Westerbaan, and D. Stebila, “Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3,” Internet-Draft, draft-kwiatkowski-tls-ecdhe-mlkem-02, Sept. 2024. 8. K. Kwiatkowski, P. Kampanakis, B. E. Westerbaan, and D. Stebila, “Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3,” Internet-Draft, draft-kwiatkowski-tls-ecdhe-mlkem-03, Dec. 2024. 9. K. Kwiatkowski, P. Kampanakis, B. E. Westerbaan, and D. Stebila, “Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3,” Internet-Draft, draft-ietf-tls-ecdhe-mlkem-00, Mar. 2025. 10. E. Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.3,” RFC 8446, IETF, Aug. 2018. 11. A. Langley, M. Hamburg, and S. Turner, “Elliptic Curves for Security,” RFC 7748, IETF, Jan. 2016. 12. H. Krawczyk and P. Eronen, “HMAC-based Extract-and-Expand Key Derivation Function (HKDF),” RFC 5869, IETF, May 2010. 13. E. Barker, L. Chen, and R. Davis, “Recommendation for Key-Derivation Methods in Key-Establishment Schemes,” NIST SP 800-56C Rev. 2, Aug. 2020. 14. T. Liu, G. S. Ramachandran, and R. Jurdak, “Post-Quantum Cryptography for Internet of Things: A Survey on Performance and Optimization,” arXiv:2401.17538, 2024. 15. S. Kumari, M. Singh, R. Singh, and H. Tewari, “Post-quantum cryptography techniques for secure communication in resource-constrained Internet of Things devices: A comprehensive survey,” Software: Practice and Experience, vol. 52, no. 10, pp. 2047–2076, 2022, doi: 10.1002/spe.3121. 16. N. Mishra, S. K. Hafizul Islam, and S. Zeadally, “A survey on security and cryptographic perspective of Industrial-Internet-of-Things,” Internet of Things, vol. 25, 101037, 2024, doi: 10.1016/j.iot.2023.101037. 17. P. R. Babu, S. A. P. Kumar, A. G. Reddy, and A. K. Das, “Quantum secure authentication and key agreement protocols for IoT-enabled applications: A comprehensive survey and open challenges,” Computer Science Review, vol. 54, 100676, 2024, doi: 10.1016/j.cosrev.2024.100676. 18. J. R. Jency, B. L. R., E. E. Nithila, C. S. Shibi, and A. Rosi, “A Survey about Post Quantum Cryptography Methods,” EAI Endorsed Transactions on Internet of Things, vol. 10, no. 1, 2024, doi: 10.4108/eetiot.5099. 19. “Integrating Post-Quantum Cryptography into CoAP and MQTT-SN Protocols,” Proc. IEEE Symposium on Computers and Communications (ISCC), 2024, doi: 10.1109/ISCC61673.2024.10733716. 20. Meta Engineering, “Post-quantum readiness for TLS at Meta,” May 2024. 21. Amazon Web Services, “How to tune TLS for hybrid post-quantum cryptography with Kyber,” 2022.
Copyright
Copyright © 2025 Seema Agrawal. This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.