π€ AI Summary
This work addresses the threat posed by quantum computing to current public-key cryptography by designing and implementing a hybrid end-to-end encryption system that ensures messages are encrypted and decrypted exclusively on clients within a zero-trust architecture. The system integrates the NIST-standardized CRYSTALS-Kyber algorithm into real-world communication for the first time, combining it with AES-256-GCM and SHA-256 to achieve both post-quantum security and practical efficiency. Experimental results demonstrate that the proposed scheme provides robust protection against both classical and quantum attacks while maintaining acceptable performance overhead, thereby validating the feasibility of deploying NISTβs post-quantum cryptographic standards in real-world environments. The implementation is open-sourced to support reproducible research.
π Abstract
The emergence of quantum computing poses a fundamental threat to current public key cryptographic systems. This threat is necessitating a transition to quantum resistant cryptographic alternatives in all the applications. In this work, we present the implementation of a practical hybrid end-to-end encryption system that combines classical and post-quantum cryptographic primitives to achieve both security and efficiency. Our system employs CRYSTALS-Kyber, a NIST-standardized lattice-based key encapsulation mechanism, for quantum-safe key exchange, coupled with AES-256-GCM for efficient authenticated symmetric encryption and SHA-256 for deterministic key derivation. The architecture follows a zero-trust model where a relay server facilitates communication without accessing plaintext messages or cryptographic keys. All encryption and decryption operations occur exclusively at client endpoints. The system demonstrates that NIST standardized post-quantum cryptography can be effectively integrated into practical messaging systems with acceptable performance characteristics, offering protection against both classical and quantum adversaries. As our focus is on implementation rather than on novelty, we also provide an open-source implementation to facilitate reproducibility and further research in post quantum secure communication systems.