NoisePQC++ is presented, a unified C++23 implementation of the Noise Protocol framework augmented with post-quantum Key Encapsulation Mechanisms and Hybrid Forward Secrecy, indicating that NIST-standardized post-quantum and hybrid Noise handshakes are practical and provide a credible basis for future deployment.
Abstract
The threat of quantum computers to classical public-key cryptography has created an urgent need to evolve secure communication protocols with post-quantum cryptographic (PQC) primitives. The Noise Protocol Framework, widely used in systems such as WireGuard and WhatsApp, traditionally relies on the Elliptic Curve Diffie-Hellman (ECDH) public-key exchange scheme, which is vulnerable to quantum threats. In this paper, we present NoisePQC++, a unified C++23 implementation of the Noise Protocol framework augmented with post-quantum Key Encapsulation Mechanisms and Hybrid Forward Secrecy. Our design integrates the National Institute of Standards and Technology (NIST) standardized ML-KEM algorithm alongside classical ECDH, enabling full PQC, hybrid ECDH+PQC handshakes, and unified support for all 57 classical Noise handshake pattern variants, 13 post-quantum Noise handshakes, and their hybrid variants. Compared with prior work, NoisePQC++ offers broader protocol coverage, more complete implementation support, and greater flexibility. Our evaluation shows minimal overhead under normal network conditions and acceptable overhead in adverse cases, while significantly improving resistance against quantum adversaries. These results indicate that NIST-standardized post-quantum and hybrid Noise handshakes are practical and provide a credible basis for future deployment.
Results demonstrate that, compared with standalone ECDHE-P256 and standalone ML-KEM-768, the proposed hybrid framework introduces only minimal computational overhead while maintaining stable resource utilization, indicating that the integration of classical and post-quantum cryptographic mechanisms does not constitute...
W. Maya, Teuku Yuliar Arif, Hammam Riza et al.· IEEE Access· 0 citations
The review argues that readiness depends on protocol binding, implementation behavior, monitoring, and governance as much as on algorithm strength, and develops a deployment-readiness framework with four layers: security continuity, protocol integration, operational observability, and crypto-agility.
Yan Zhang· Applied and Computational En...· 0 citations
A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.
A. K. M. Fakhrul Hossain· SUST Journal of Science and...· 0 citations
This work presents a comprehensive Soft-Analytical Side-Channel Attack (SASCA) targeting the implementation of the iterative Karatsuba algorithm, and presents the optimized factor graph and algorithm tailored to the binary values and sparsity of HQC to make the SASCA more practical.
Yi-Kang Guo, Yu-Chang Hu, Yan-Bin Li et al.· IACR Transactions on Cryptog...· 0 citations