Skip to content
Review Open access

Post-Quantum Cryptography Migration in Internet Protocols: A Review of ML-KEM Hybrid Key Exchange in TLS and SSH

Aug 2026 · Applied and Computational Engineering · 0 citations

TL;DR

The review argues that readiness depends on protocol binding, implementation behavior, monitoring, and governance as much as on algorithm strength, and develops a deployment-readiness framework with four layers: security continuity, protocol integration, operational observability, and crypto-agility.

Abstract

Internet public-key cryptography faces long-term risk from quantum computers, especially when traffic can be collected now and decrypted later. After the NIST post-quantum cryptography standards, the deployment task has shifted from algorithm selection to protocol migration. This paper reviews ML-KEM hybrid key exchange in TLS and SSH through a standards-first narrative review and protocol comparison. It synthesizes NIST standards, RFCs and IETF drafts, experiments, measurements, and primary deployment reports. The paper develops a deployment-readiness framework with four layers: security continuity, protocol integration, operational observability, and crypto-agility. The analysis shows hybrid key exchange represents the most feasible short-term solution, as it introduces post-quantum confidentiality without discarding existing elliptic curve security guarantees. However, hybrid deployment does not provide full post-quantum security. The review argues that readiness depends on protocol binding, implementation behavior, monitoring, and governance as much as on algorithm strength. Handshake size, middlebox compatibility, implementation safety, telemetry, authentication migration, and organizational crypto-agility determine whether migration can progress without weakening current Internet security.

Read PDF

Similar papers

Review Open access Jul 2026

Post-Quantum Cryptography Migration for Enterprise Security

Large-scale quantum computers threaten the public-key cryptography that protects enterprise data, communications, and digital identity. Shor's algorithm solves integer factorization and discrete logarithms in polynomial time, which would break RSA, Diffie-Hellman, and elliptic-curve schemes once a cryptographically rel...

Mini T. V. · 0 citations
Review Open access Aug 2026

Toward practical migration to post-quantum SSH: system-level design and evaluation

The migration of remote-access and industrial communication systems from classical public-key cryptography to post-quantum cryptography (PQC) requires careful evaluation at both the protocol and system levels. This paper presents PQC-E2E-CA, a system-level evaluation framework for reviewing post-quantum and hybrid cryp...

Shahid Allah Bakhsh, Inam ul Haq, Tarek Helmy et al. · 0 citations
Preprint Aug 2026

A Hybrid Post-Quantum Encryption Architecture with Self-Hosted Key Management for SME Cloud Data Protection

Harvesting ciphertext from cloud storage needs no quantum computer; decrypting it later does. That gap is the harvest-now-decrypt-later exposure: anything protected by RSA or ECDH today that must stay secret for decades is already compromised. Small and medium-sized enterprises are least able to respond: they neither r...

Muhammad Shaheer Bin Junaid · 0 citations
Review Open access Jul 2026

Post-Quantum Security Frameworks for Internet of Things Systems: A Layered Narrative Review of Architectures, Protocols, Trust, and Emerging Challenges

The analysis indicates a significant prevalence of lattice-based schemes, hybrid strategies, and integrations with blockchain technology, zero-knowledge proofs, federated learning, homomorphic encryption, AI, and Zero Trust architectures, as well as key gaps remain in side-channel evaluation, migration pathways, deploy...

Rodrigo Jara Espinoza, Yohamin Nafit Pimentel Alarcon, Angelo Taco-Jimenez et al. · 0 citations
Open access Aug 2026

Beyond encryption: post-quantum cryptography and the future of quantum-safe networks

This analysis demonstrates that while hybrid PQC-QKD models reduce long-term key compromise probabilities to near 0%, they introduce a 15% to 40% increase in bandwidth overhead during initial cryptographic handshakes during initial cryptographic handshakes.

R. Delhibabu · 0 citations
Open access Sep 2026

The intersection of post-quantum cryptography and QaaS: architecting quantum-safe cloud infrastructures

By 2030, an estimated 40% of current cloud infrastructures may be rendered vulnerable by cryptanalytically relevant quantum computers (CRQCs). This paper introduces a 4-tier security framework tailored for Quantumas-a-Service (QaaS) deployments, focusing on securing data-in-transit. Integrating 3 NIST-standa...

Akshay Joseph, R. Delhibabu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.