On Implementing Hybrid Post-Quantum End-to-End Encryption

πŸ“… 2026-01-21
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the threat posed by quantum computing to current public-key cryptography by designing and implementing a hybrid end-to-end encryption system that ensures messages are encrypted and decrypted exclusively on clients within a zero-trust architecture. The system integrates the NIST-standardized CRYSTALS-Kyber algorithm into real-world communication for the first time, combining it with AES-256-GCM and SHA-256 to achieve both post-quantum security and practical efficiency. Experimental results demonstrate that the proposed scheme provides robust protection against both classical and quantum attacks while maintaining acceptable performance overhead, thereby validating the feasibility of deploying NIST’s post-quantum cryptographic standards in real-world environments. The implementation is open-sourced to support reproducible research.

Technology Category

Machine Learning: Quantum Machine LearningComputer Vision: Adversarial Attacks & RobustnessSearch and Optimization: Non-convex Optimization

Application Category

Security and Privacy: Applications of cryptographyEconomics, Online Markets and Human Computation: Economic aspects of blockchain and cryptocurrenciesSystems and Infrastructure for Web, Mobile and WoT: Experiences and lessons learnt from Web-based algorithms and system deployments
πŸ“ Abstract
The emergence of quantum computing poses a fundamental threat to current public key cryptographic systems. This threat is necessitating a transition to quantum resistant cryptographic alternatives in all the applications. In this work, we present the implementation of a practical hybrid end-to-end encryption system that combines classical and post-quantum cryptographic primitives to achieve both security and efficiency. Our system employs CRYSTALS-Kyber, a NIST-standardized lattice-based key encapsulation mechanism, for quantum-safe key exchange, coupled with AES-256-GCM for efficient authenticated symmetric encryption and SHA-256 for deterministic key derivation. The architecture follows a zero-trust model where a relay server facilitates communication without accessing plaintext messages or cryptographic keys. All encryption and decryption operations occur exclusively at client endpoints. The system demonstrates that NIST standardized post-quantum cryptography can be effectively integrated into practical messaging systems with acceptable performance characteristics, offering protection against both classical and quantum adversaries. As our focus is on implementation rather than on novelty, we also provide an open-source implementation to facilitate reproducibility and further research in post quantum secure communication systems.
Problem

Research questions and friction points this paper is trying to address.

post-quantum cryptography
end-to-end encryption
quantum threat
hybrid cryptography
secure communication
Innovation

Methods, ideas, or system contributions that make the work stand out.

hybrid post-quantum cryptography
CRYSTALS-Kyber
end-to-end encryption
zero-trust architecture
NIST standardization
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
A
Aditi Gandhi
School of Computer Science Engineering & Information Systems, Vellore Institute of Technology, Vellore 632014, India
A
Aakankshya Das
School of Computer Science Engineering & Information Systems, Vellore Institute of Technology, Vellore 632014, India
A
A. Cherukuri
School of Computer Science Engineering & Information Systems, Vellore Institute of Technology, Vellore 632014, India