freenode
Internet & Protocols

CFRG last call opens on hybrid PQ/T KEM drafts

Bernstein objects to multiple combiners as needless complexity; MLS implementers plan immediate use of the concrete hybrids.

The IRTF Crypto Forum Research Group has opened a two-week research group last call on a pair of drafts that specify hybrid post-quantum and traditional key encapsulation mechanisms, work intended for publication as Informational RFCs to guide the combination of classical and quantum-resistant cryptography during post-quantum migration.

One draft sets out generic hybrid KEM constructions and security reductions. The other gives concrete instantiations, including ML-KEM paired with X25519 and with NIST elliptic curves. Both were reviewed ahead of the call by the CFRG Crypto Review Panel; Thomas Pornin, Virendra Kumar, and Russ Housley found the constructions sound, with their comments already folded into the current revisions. Chairs asked for clear positions (ready as-is, ready with specific changes, or not ready) grounded in technical problems, with the call closing 22 July 2026.

Rohan Mahy reported that Messaging Layer Security will use the three concrete hybrids immediately, calling ML-KEM-768 plus X25519 a strong default and noting demand from operators who want PQ hybrids without abandoning existing P-256 or P-384 infrastructure.

D. J. Bernstein objected to the decision to specify more than one combiner. Multiple options, he argued, feed anti-hybrid claims that the classical-plus-PQ choice is too hard to settle, while also enlarging the implementation surface. He pointed to a study of crypto-library CVEs that found roughly one new CVE per thousand lines of new code and about one severe cryptographic CVE in eight, and warned that CFRG should avoid the appearance of conflict when leadership includes advocates of solo post-quantum designs. Peter Gutmann endorsed the complexity concern, arguing that security standards too often accumulate bloat that implementers must learn to ignore.

Other reviewers asked for a clearer account of the "nominal group" abstraction used in the proofs, urged alignment with the NIST SP 800-227 definition that a hybrid must preserve the security properties of its components, and debated whether the documents should also cover PQ-plus-PQ or three-way hybrids. Wang Guilin held that the present classical-plus-PQ scope remains the right target given migration urgency, leaving broader key-combiner work to separate efforts.