01/01/2024 | Carlos Rubio García, Simon Rommel, Sofiane Takarabt, Juan Jose Vegas Olmos, Sylvain Guilley, Philippe Nguyen, Idelfonso Tafur Monroy
The paper "Quantum-resistant Transport Layer Security" by Rubio Garcia et al. (2024) addresses the growing threat of quantum computing to current cybersecurity practices, particularly in telecommunication networks. The authors propose two novel hybrid solutions, "Concatenation" and "Exclusively-OR (XOR)," that integrate Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) into the Transport Layer Security (TLS) protocol to enhance quantum-resistant authenticated key exchange. The study evaluates the complexity and security improvements of these hybrid solutions in a practical, industry-ready TLS implementation using Mbed TLS. Key findings include a 9% performance enhancement in the TLS handshake with PQC-only approaches and a 117% increase in the key establishment process with the hybrid PQC-QKD solution, which significantly boosts the security of the handshake. The paper also discusses the challenges and trade-offs associated with integrating QKD and PQC, emphasizing the need for further research to address potential vulnerabilities and ensure the long-term security of quantum-resistant communications.The paper "Quantum-resistant Transport Layer Security" by Rubio Garcia et al. (2024) addresses the growing threat of quantum computing to current cybersecurity practices, particularly in telecommunication networks. The authors propose two novel hybrid solutions, "Concatenation" and "Exclusively-OR (XOR)," that integrate Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) into the Transport Layer Security (TLS) protocol to enhance quantum-resistant authenticated key exchange. The study evaluates the complexity and security improvements of these hybrid solutions in a practical, industry-ready TLS implementation using Mbed TLS. Key findings include a 9% performance enhancement in the TLS handshake with PQC-only approaches and a 117% increase in the key establishment process with the hybrid PQC-QKD solution, which significantly boosts the security of the handshake. The paper also discusses the challenges and trade-offs associated with integrating QKD and PQC, emphasizing the need for further research to address potential vulnerabilities and ensure the long-term security of quantum-resistant communications.