Comment by nmadden
Are there? I’ve advocated for such constructions in the past, but I’ve never seen an actual proposal. Do you have a link?
Are there? I’ve advocated for such constructions in the past, but I’ve never seen an actual proposal. Do you have a link?
Google's post-quantum TLS experiments that were done in public via Android Chrome are such; basically you just do normal TLS handshake but stack the key derivation from the traditional DH-type perfect-forward-secrecy exchange with a post-quantum-perfect-forward-secrecy exchange that you all seal under the same handshake authentication, and where you make sure to only use post quantum symmetric primitives to fuse the traditional session key material with the PQ session key material such that you don't rely on either one's resistance to keep your secrets secret.
Sorry I don't have a link quite on hand right now.