Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment: Definition, Proof, and Embedded-Device Cost

A game-based definition and two-sided separation showing that binding the session key and confirmation tag to a transcript hash makes downgrade resilience a local property of the combiner, at negligible embedded-device cost.
Bhanwar Gupta; Sanjeev Ranaยท 2026ยท DOI 10.48550/arXiv.2609.21273

The core problem

Hybrid key establishment runs a post-quantum key-encapsulation mechanism (KEM) alongside a classical Diffie-Hellman primitive, so that the session key stays secure while either component resists attack. This design is now standardized in the Transport Layer Security protocol, Secure Shell, and the Internet Key Exchange, with the standardized module-lattice KEM (ML-KEM) as the post-quantum component.

A hybrid KEM secures the derived key, but not the integrity of the negotiation that selects which primitives are used. Full protocols authenticate that negotiation through a handshake transcript; a hybrid KEM deployed as a standalone drop-in primitive, or inside a minimal handshake without transcript authentication, inherits no such guarantee, and an active attacker can strip the post-quantum option.

The authors ask what the key schedule alone must contain to make downgrade resilience a local property of the combiner. They give a game-based definition at the combiner layer and prove a two-sided separation: a combiner that ignores the transcript is downgraded with certainty, whereas one that binds the session key and the confirmation tag to a hash of the transcript blocks every such at

Innovation

The authors report both security and performance results.

**Security.** The two-sided separation is the central result. A combiner that ignores the transcript is downgraded with certainty, meaning an active attacker can always strip the post-quantum option. In contrast, a combiner that binds the session key and the confirmation tag to a hash of the transcript blocks every such attempt, up to a term negligible for a 256-bit transcript hash. The explicit strongest-link security bound shows that the hybrid remains at least as strong as its strongest component.

**Performance.** Using a calibrated cost model composed from published Cortex-M4 measurements, transcript binding adds one hash per party. This amounts to about 11.8% of handshake computation but only 1.5% of radio-inclusive energy. Importantly, it adds no messages or bytes on the wire, so there is no increase in communication overhead.

**Validation.** Every reported number is produced by a released harness that passes a 30-check validation gate, ensuring reproducibility and reliability of the measurements.

The security guarantee can be expressed as:


\text{Adv}^{\text{downgrade}}_{\mathcal{A}} \leq \text{Adv}^{\text{hash

Hybrid key establishment runs a post-quantum key-encapsulation mechanism (KEM) alongside a classical Diffie-Hellman primitive, so that the session key stays secure while either component resists attack. This design is now standardized in the Transport Layer Security protocol, Secure Shell, and the Internet Key Exchange, with the standardized module-lattice KEM (ML-KEM) as the post-quantum component.
A hybrid KEM secures the derived key, but not the integrity of the negotiation that selects which primitives are used. Full protocols authenticate that negotiation through a handshake transcript; a hybrid KEM deployed as a standalone drop-in primitive, or inside a minimal handshake without transcript authentication, inherits no such guarantee, and an active attacker can strip the post-quantum option.

Why it matters

The results have several implications for the deployment of hybrid post-quantum key establishment.

First, downgrade resilience can be made a local property of the combiner. This means that even when a hybrid KEM is used as a standalone drop-in primitive or inside a minimal handshake without transcript authentication, the combiner itself can provide the necessary protection. This is important because many deployments may not have full protocol support for transcript authentication.

Second, the cost of transcript binding is low. The addition of one hash per party is a small price to pay for blocking downgrade attacks. The fact that it adds no messages or bytes on the wire is particularly attractive for constrained environments where bandwidth is limited.

Third, the explicit strongest-link security bound provides a clear security argument. It shows that the hybrid remains at least as strong as its strongest component, which is the desired property for hybrid key establishment.

The authors also note that the standardized module-lattice KEM (ML-KEM) is the post-quantum component in current standards. Their definition and proof are general and can be applied to other KEMs as well.

Overall, the work provides a rigorous foundation for making hybrid key establishment resilient to downgrade attacks at the combiner layer, with practical and efficient solutions for embedded devices.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ