{ "draft": "draft-ietf-tls-hybrid-design-16", "doc_id": "RFC9954", "title": "Hybrid Key Exchange in TLS 1.3", "authors": [ "D. Stebila", "S. Fluhrer", "S. Gueron" ], "format": [ "XML", "TEXT", "HTML", "PDF" ], "page_count": "18", "pub_status": "INFORMATIONAL", "status": "INFORMATIONAL", "source": "Transport Layer Security", "abstract": "Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum cryptography. This document provides a construction for hybrid key exchange in the Transport Layer Security (TLS) protocol version 1.3.", "pub_date": "July 2026", "keywords": [ "Post-Quantum" ], "obsoletes": [], "obsoleted_by": [], "updates": [], "updated_by": [], "see_also": [], "doi": "10.17487/RFC9954", "errata_url": null }