{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T02:49:49Z","timestamp":1777949389369,"version":"3.51.4"},"publisher-location":"Cham","reference-count":47,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032160881","type":"print"},{"value":"9783032160898","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-16089-8_30","type":"book-chapter","created":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T23:42:59Z","timestamp":1777851779000},"page":"503-522","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Using Dual Algorithm Certificates in\u00a0TLS: Enabling Rapid Transition to\u00a0Post-Quantum Cryptography with\u00a0Backward Compatibility"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-8063-1526","authenticated-orcid":false,"given":"Tobias","family":"Frauenschl\u00e4ger","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7727-2448","authenticated-orcid":false,"given":"J\u00fcrgen","family":"Mottok","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"30_CR1","doi-asserted-by":"publisher","unstructured":"Anastasova, M., Azarderakhsh, R., Kermani, M.M.: Fully Hybrid TLSv1.3 in WolfSSL on Cortex-M4. In: Applied Cryptography and Network Security Workshops, vol. 14586, pp. 376\u2013395. Springer Nature Switzerland, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-61486-6_22","DOI":"10.1007\/978-3-031-61486-6_22"},{"key":"30_CR2","unstructured":"Bernstein, D.J.: cr.yp.to: 2023.11.25: Another way to botch the security analysis of kyber-512 (2023). https:\/\/blog.cr.yp.to\/20231125-kyber.html, Accessed 25 Apr 2025"},{"key":"30_CR3","doi-asserted-by":"crossref","unstructured":"Beullens, W.: Breaking rainbow takes a weekend on a laptop. In: Advances in Cryptology \u2013 CRYPTO 2022, pp. 464\u2013479. Springer Nature Switzerland, Cham (2022)","DOI":"10.1007\/978-3-031-15979-4_16"},{"key":"30_CR4","doi-asserted-by":"publisher","unstructured":"Bindel, N., Braun, J., Gladiator, L., St\u00f6ckert, T., Wirth, J.: X.509-Compliant hybrid certificates for the post-quantum transition. J. Open Source Softw. p.\u00a01606 (2019). https:\/\/doi.org\/10.21105\/joss.01606","DOI":"10.21105\/joss.01606"},{"key":"30_CR5","unstructured":"Bindel, N., Hale, B., Connolly, D., D, F.: Hybrid signature spectrums. Internet-Draft Draft-Ietf-Pquip-Hybrid-Signature-spectrums-07, Internet Engineering Task Force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-pquip-hybrid-signature-spectrums\/07\/, Work in Progress"},{"key":"30_CR6","unstructured":"Bonnell, C., Gray, J., Hook, D., Okubo, T., Ounsworth, M.: A mechanism for encoding differences in paired certificates. Internet-Draft draft-bonnell-lamps-chameleon-certs-06, Internet Engineering Task Force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-bonnell-lamps-chameleon-certs\/06\/, Work in Progress"},{"key":"30_CR7","unstructured":"Chatziamanetoglou, D., Rantos, K.: On the implementation of x509-compliant quantum-safe hybrid certificates. IST-SET-198-RSY on Quantum Technology for Defence and Security (2023). https:\/\/www.sto.nato.int\/publications\/STO%20Meeting%20Proceedings\/STO-MP-IST-SET-198\/MP-IST-SET-198-A1-02.pdf"},{"key":"30_CR8","unstructured":"Chevignard, C., Fouque, P.A., Schrottenloher, A.: Reducing the number of qubits in quantum factoring. Cryptology ePrint Archive, Paper 2024\/222 (2024). https:\/\/eprint.iacr.org\/2024\/222"},{"key":"30_CR9","unstructured":"Cloudflare, Inc.: Post-quantum encryption adoption | cloudflare radar. https:\/\/radar.cloudflare.com\/adoption-and-usage#post-quantum-encryption-adoption, Accessed 12 Mar 2025"},{"key":"30_CR10","doi-asserted-by":"crossref","unstructured":"Driscoll, F., Parsons, M., Hale, B.: Terminology for post-quantum traditional hybrid schemes. Internet-draft, Internet Engineering Task Force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-pquip-pqt-hybrid-terminology\/06\/, Work in Progress","DOI":"10.17487\/RFC9794"},{"key":"30_CR11","unstructured":"EJBCA: Preparing for the migration to post-quantum public key algorithms with hybrid certificates (2023), https:\/\/www.ejbca.org\/resources\/preparing-for-the-migration-to-post-quantum-public-key-algorithms-with-hybrid-certificates\/, Accessed 23 Apr 2025-04-23"},{"key":"30_CR12","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2021.117887","author":"J Fan","year":"2021","unstructured":"Fan, J., et al.: Impact of post-quantum hybrid certificates on PKI, common libraries, and protocols. Int. J. Secure. Network. (2021). https:\/\/doi.org\/10.1504\/IJSN.2021.117887","journal-title":"Int. J. Secure. Network."},{"key":"30_CR13","unstructured":"Farisi, M.G.: Post-Quantum digital signatures \u2014 the benchmark of ML-DSA Against ECDSA and EdDSA (2025). https:\/\/blog.moeghifar.com\/post-quantum-digital-signatures-the-benchmark-of-ml-dsa-against-ecdsa-and-eddsa-d4406a5918d9, Accessed 06 Jun 2025"},{"key":"30_CR14","unstructured":"Fries, S., Falk, R.: Supporting cryptographic algorithm agility with attribute certificates. Int. J. Adv. Secur. 17 (1& 2) (2024). https:\/\/personales.upv.es\/thinkmind\/dl\/journals\/sec\/sec_v17_n12_2024\/sec_v17_n12_2024_8.pdf"},{"key":"30_CR15","doi-asserted-by":"publisher","unstructured":"Garcia-Morchon, O., Kumar, S., Sethi, M.: Internet of things (IoT) security: state of the art and challenges. Request for Comments RFC 8576, Internet Engineering Task Force (2019). https:\/\/doi.org\/10.17487\/RFC8576","DOI":"10.17487\/RFC8576"},{"key":"30_CR16","unstructured":"Geest, D.V., Bashiri, K., Fluhrer, S., Gazdag, S.L., Kousidis, S.: use of the HSS and XMSS hash-based signature algorithms in internet X.509 public key infrastructure. Internet-Draft draft-ietf-lamps-x509-shbs-13, Internet Engineering Task Force (2024). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-lamps-x509-shbs\/13\/, Work in Progress"},{"key":"30_CR17","doi-asserted-by":"publisher","unstructured":"Gidney, C.: How to factor 2048 bit RSA integers with less than a million noisy qubits (2025). https:\/\/doi.org\/10.48550\/arXiv.2505.15917, arXiv:2505.15917","DOI":"10.48550\/arXiv.2505.15917"},{"key":"30_CR18","unstructured":"Gladiator, L.: Hybrid certificates in OpenSSL (2019). https:\/\/github.com\/CROSSINGTUD\/openssl-hybrid-certificates\/blob\/OQS-OpenSSL_1_1_1-stable\/HybridCert_technical_documentation.pdf, Accessed 22 Apr 2025"},{"key":"30_CR19","doi-asserted-by":"publisher","unstructured":"Heinl, M.P., Pursche, M., Puch, N., Peters, S.N., Giehl, A.: From standard to practice: towards ISA\/IEC 62443-conform public key infrastructures. In: Computer Safety, Reliability, and Security. Springer Nature Switzerland (2023). https:\/\/doi.org\/10.1007\/978-3-031-40923-3_15","DOI":"10.1007\/978-3-031-40923-3_15"},{"key":"30_CR20","unstructured":"Hollebeek, T., Schmieg, S., Westerbaan, B.: Use of ML-DSA in TLS 1.3. internet-draft draft-tls-westerbaan-mldsa-00, internet engineering task force (2024). https:\/\/datatracker.ietf.org\/doc\/draft-tls-westerbaan-mldsa\/00\/, Work in Progress"},{"key":"30_CR21","unstructured":"Internet engineering task force: IPR details - ISARA corporation\u2019s statement about IPR related to draft-truskovsky-lamps-pq-hybrid-x509 (2022). https:\/\/datatracker.ietf.org\/ipr\/5829\/, Accessed 23 Apr 2025"},{"key":"30_CR22","unstructured":"ISARA corporation: ISARA dedicates four hybrid certificate patents to the public, easing path to quantum-safe security (2022). https:\/\/www.isara.com\/company\/newsroom\/isara-dedicates-four-hybrid-certificate-patents-to-the-public.html, Accessed 23 Apr 2025"},{"key":"30_CR23","unstructured":"ITU-T: Recommendation ITU-T X.509 (2019). https:\/\/www.itu.int\/rec\/T-REC-X.509-201910-I\/en"},{"key":"30_CR24","doi-asserted-by":"publisher","unstructured":"Kampanakis, P., Childs-Klein, W.: The impact of data-heavy, post-quantum TLS 1.3 on the time-to-last-byte of web connections. In: Proceedings 2024 Workshop on Measurements, Attacks, and Defenses for the Web. Internet Society, San Diego, CA, USA (2024). https:\/\/doi.org\/10.14722\/madweb.2024.23010","DOI":"10.14722\/madweb.2024.23010"},{"key":"30_CR25","unstructured":"Kampanakis, P., Stebila, D., Hansen, T.: PQ\/T hybrid key exchange in SSH. Internet-Draft draft-ietf-sshm-mlkem-hybrid-kex-02, Internet Engineering Task Force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-sshm-mlkem-hybrid-kex\/02\/, Work in Progress"},{"key":"30_CR26","unstructured":"Lytle, J.: Performance of hybrid signatures for public key infrastructure certificates. Master\u2019s thesis, Naval Postgraduate School (2021). https:\/\/apps.dtic.mil\/sti\/citations\/trecms\/AD1204814"},{"key":"30_CR27","doi-asserted-by":"publisher","unstructured":"Moody, D., Perlner, R., Regenscheid, A., Robinson, A., Cooper, D.: Transition to post-quantum cryptography standards. Tech. Rep. NIST IR 8547 ipd, National Institute of Standards and Technology, Gaithersburg, MD (2024). https:\/\/doi.org\/10.6028\/NIST.IR.8547.ipd","DOI":"10.6028\/NIST.IR.8547.ipd"},{"key":"30_CR28","unstructured":"National cyber security centre: timelines for migration to post-quantum cryptography (2025). https:\/\/www.ncsc.gov.uk\/guidance\/pqc-migration-timelines, Accessed 29 Apr 2025"},{"key":"30_CR29","unstructured":"National institute of standards and technology (NIST): FAQ on kyber512 (2023). https:\/\/csrc.nist.gov\/csrc\/media\/Projects\/post-quantum-cryptography\/documents\/faq\/Kyber-512-FAQ.pdf, Accessed 24 Apr 2025"},{"key":"30_CR30","unstructured":"OPC foundation: UA part 4: security - 6.1.4 creating a securechannel (2025). https:\/\/reference.opcfoundation.org\/Core\/Part4\/v105\/docs\/6.1.4, Accessed 29 Apr 2025"},{"key":"30_CR31","unstructured":"Ounsworth, M., Gray, J., Pala, M., Klau\u00dfner, J., Fluhrer, S.: Composite ML-DSA for use in X.509 public key infrastructure and CMS. Internet-Draft draft-ietf-lamps-pq-composite-sigs-07, Internet Engineering Task Force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-lamps-pq-composite-sigs\/07\/, Work in Progress"},{"key":"30_CR32","unstructured":"Patil, K.: Preparing for the quantum leap with hybrid certificates (2024). https:\/\/www.appviewx.com\/blogs\/preparing-for-the-quantum-leap-with-hybrid-certificates\/, Accessed 23 Apr 2025"},{"key":"30_CR33","doi-asserted-by":"publisher","unstructured":"Paul, S., Kuzovkova, Y., Lahr, N., Niederhagen, R.: Mixed certificate chains for the transition to post-quantum authentication in TLS 1.3. In: Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, pp. 727\u2013740. ACM (2022). https:\/\/doi.org\/10.1145\/3488932.3497755","DOI":"10.1145\/3488932.3497755"},{"key":"30_CR34","unstructured":"Reddy, T., Hollebeek, T., Gray, J., Fluhrer, S.: Use of composite ML-DSA in TLS 1.3. internet-draft draft-reddy-tls-composite-mldsa-01, internet engineering task force (2024). https:\/\/datatracker.ietf.org\/doc\/draft-reddy-tls-composite-mldsa\/01\/, Work In Progress"},{"key":"30_CR35","unstructured":"Reddy.K, T., Hollebeek, T., Gray, J., Fluhrer, S.: Use of SLH-DSA in TLS 1.3. internet-draft draft-reddy-tls-slhdsa-01, internet engineering task force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-reddy-tls-slhdsa\/01\/, Work in Progress"},{"key":"30_CR36","doi-asserted-by":"publisher","unstructured":"Rescorla, E.: The transport layer security (TLS) protocol version 1.3. RFC 8446 (2018). https:\/\/doi.org\/10.17487\/RFC8446","DOI":"10.17487\/RFC8446"},{"key":"30_CR37","unstructured":"Scheible, P.: Quantum resistant authenticated key exchange for OPC UA using hybrid X.509 certificates. Master\u2019s thesis, Universitat Polit\u00e8cnica de Catalunya (2020). https:\/\/upcommons.upc.edu\/handle\/2117\/191775"},{"key":"30_CR38","unstructured":"Shekh-Yusef, R., Tschofenig, H., Ounsworth, M., Sheffer, Y., Reddy.K, T., Rosomakho, Y.: Post-Quantum traditional (PQ\/T) hybrid authentication with dual certificates in TLS 1.3. internet-draft draft-yusef-tls-pqt-dual-certs-00, internet engineering task force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-yusef-tls-pqt-dual-certs\/00\/, Work in Progress"},{"key":"30_CR39","unstructured":"Shuzhou, S., He, Y., Lin, H.Y.: Convertible forms with multiple keys and signatures for use in internet X.509 certificates. Internet-Draft draft-sun-lamps-hybrid-scheme-01, Internet Engineering Task Force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-sun-lamps-hybrid-scheme\/01\/, Work in Progress"},{"key":"30_CR40","doi-asserted-by":"publisher","unstructured":"Sikeridis, D., Kampanakis, P., Devetsikiotis, M.: Assessing the overhead of post-quantum cryptography in TLS 1.3 and SSH. In: Proceedings of the 16th International Conference on emerging Networking EXperiments and Technologies, pp. 149\u2013156. ACM (2020). https:\/\/doi.org\/10.1145\/3386367.3431305","DOI":"10.1145\/3386367.3431305"},{"key":"30_CR41","doi-asserted-by":"publisher","unstructured":"Sikeridis, D., Kampanakis, P., Devetsikiotis, M.: Post-Quantum authentication in TLS 1.3: a performance study. In: Proceedings 2020 Network and Distributed System Security Symposium. Internet Society, San Diego, CA (2020). https:\/\/doi.org\/10.14722\/ndss.2020.24203","DOI":"10.14722\/ndss.2020.24203"},{"key":"30_CR42","unstructured":"Stapleton, J., Bordow, P., Rao, A., Hu, A., Hook, D., Stevens, S.: TLS certificate key selection (CKS) extension using x.509 hybrid certificates. E-Mail Attachment, IETF Mail Archive (2023). https:\/\/mailarchive.ietf.org\/arch\/msg\/tls-reg-review\/YleguOWXpJ8FaDisGHAHggNCr1U\/, Accessed 22 Apr 2025"},{"key":"30_CR43","unstructured":"Stebila, D., Fluhrer, S., Gueron, S.: Hybrid key exchange in TLS 1.3. internet-draft draft-ietf-tls-hybrid-design-12, internet engineering task force (2025). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-tls-hybrid-design\/12\/, Work in Progress"},{"key":"30_CR44","doi-asserted-by":"publisher","unstructured":"Tjhai, C., Tomlinson, M., Bartlett, G., Fluhrer, S., Geest, D.V., Garcia-Morchon, O., Smyslov, V.: Multiple key exchanges in the internet key exchange protocol version 2 (IKEv2). RFC 9370 (2023). https:\/\/doi.org\/10.17487\/RFC9370","DOI":"10.17487\/RFC9370"},{"key":"30_CR45","unstructured":"Truskovsky, A., Geest, D.V., Fluhrer, S., Kampanakis, P., Ounsworth, M., Mister, S.: Multiple public-key algorithm X.509 certificates. Internet-Draft draft-truskovsky-lamps-pq-hybrid-x509-00, Internet Engineering Task Force (2018). https:\/\/datatracker.ietf.org\/doc\/draft-truskovsky-lamps-pq-hybrid-x509\/00\/, Expired Internet-Draft"},{"key":"30_CR46","unstructured":"Truskovsky, A., Yamada, A., Brown, M.K., Gutoski, G.M.: Using a digital certificate with multiple cryptosystems. Patent (2017). https:\/\/patents.google.com\/patent\/US9660978B1\/en, Accessed 23 Apr 2025"},{"key":"30_CR47","unstructured":"WolfSSL: The new wolfSSL \u201cexperimental\u201d framework \u2013 wolfSSL (2024). https:\/\/www.wolfssl.com\/the-new-wolfssl-experimental-framework\/, Accessed 23 Apr 2025"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2025 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-16089-8_30","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T23:43:03Z","timestamp":1777851783000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-16089-8_30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032160881","9783032160898"],"references-count":47,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-16089-8_30","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}