Skip to content
Open access

BB84 with ML-KEM Decapsulation-Failure-Based Security Parameters

Sep 2026 · Cryptography · 0 citations · 63 references

TL;DR

This paper suggests that as a key exchange mechanism, BB84 should be run with security parameters comparable to those of ML-KEM, and analyzes performance implications if this choice is taken, and offers general guidelines for BB84 parameter selection.

Abstract

With the advent of quantum computers, traditional key exchange mechanisms are under threat, necessitating the development of new methods. Recently, Module-Lattice-Based Key Encapsulation Mechanism (ML-KEM) has been standardized as a quantum-safe key exchange method. Another emerging technique is Quantum Key Distribution (QKD) and its most famous protocol, BB84, which relies on the principles of quantum physics to exchange key information. Both techniques are considered secure against attacks by quantum computers, but their security is based on different principles. However, both key exchange types include a statistical component which, if an attacker were lucky, could allow circumventing these underlying hard problems. In this paper, we suggest that as a key exchange mechanism, BB84 should be run with security parameters comparable to those of ML-KEM, and analyze performance implications if this choice is taken. We illustrate the impact by estimating the number of raw bits required to generate a 256-bit symmetric key using BB84 and assessing the resulting performance implications. We further show how the BB84 finite-size security parameter can be chosen such that the post-processing failure probability is of the same order as the cumulative decapsulation-failure probability of ML-KEM. According to our results, the security parameter in BB84 should be at most 2−75.8 if statistical failure probability comparable to the ML-KEM decapsulation-failure target is desired. These findings offer general guidelines for BB84 parameter selection, with hybrid protocol design representing one potential application context.

Read PDF

Similar papers

Open access Aug 2026

Quantum-Resistant Diffie-Hellman Key Exchange Protocol

A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.

A. K. M. Fakhrul Hossain · 0 citations

The Morphological Side of

A new software stack allows for agnostic integration, monitoring, and management of QKD, independent from a specific vendor or technology, and a QKD simulator is presented, designed, and tested.

Ignazio Pedone, Andrea S. Atzeni, D. Canavese et al. · 0 citations

SUST Journal of Science and Technology

A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.

A. K. M. Fakhrul Hossain, Article Info · 0 citations
2026

Multi-Instance Security Degradation of Code-Based KEMs

It is shown that in a BIKE multi-instance setting an attacker can construct a DOOM instance with nM syndromes, and multi-instance security of code-based KEMs degrades as a function of M.

Alexander May, Gabriel Sá Diogo · 0 citations
Sep 2026

Zero Knowledge Arguments for the Post-Quantum Era

This paper presents concrete implementations of Zero-Knowledge Arguments (ZKAs), analogous to but distinct from traditional Σ-protocols, and describes two variants: one with dynamic public key encapsulation (CPA-DE) and another that is non-interactive (CPA-NI).

Randy Kuang, Daniel Johnson, D. Panario · 0 citations
Open access Sep 2026

The Kyber encryption algorithm and its implementation in .NET

The practical implementation of the post-quantum Kyber algorithm was implemented through the development of a custom cryptographic library on the .NET platform, which successfully reproduces the full key exchange cycle, comprising key generation, encapsulation, and decapsulation.

Danylo S. Zolotopupov, Lesia Bulatetska, V. Bulatetskyi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.