{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T08:10:33Z","timestamp":1785831033048,"version":"3.56.0"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032325594","type":"print"},{"value":"9783032325600","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T00:00:00Z","timestamp":1784678400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T00:00:00Z","timestamp":1784678400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-32560-0_2","type":"book-chapter","created":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T12:04:31Z","timestamp":1784635471000},"page":"32-74","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["The Best of Both KEMs: Securely Combining KEMs in Post-quantum Hybrid Schemes"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0107-6037","authenticated-orcid":false,"given":"Gorjan","family":"Alagic","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-1990-5664","authenticated-orcid":false,"given":"Fahran","family":"Bajaj","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6687-6442","authenticated-orcid":false,"given":"Aybars","family":"Kocoglu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,22]]},"reference":[{"key":"2_CR1","unstructured":"The keyed-hash message authentication code (HMAC). FIPS PUB 198-1 (2008). https:\/\/nvlpubs.nist.gov\/nistpubs\/fips\/nist.fips.198-1.pdf"},{"key":"2_CR2","unstructured":"Classic McEliece: conservative code-based cryptography: cryptosystem specification (2022). https:\/\/classic.mceliece.org\/mceliece-spec-20221023.pdf"},{"key":"2_CR3","unstructured":"BIKE: Bit flipping key encapsulation (2024). https:\/\/bikesuite.org\/files\/v5.2\/BIKE_Spec.2024.10.10.1.pdf"},{"key":"2_CR4","unstructured":"Hamming quasi-cyclic (HQC) (2024). https:\/\/pqc-hqc.org\/doc\/archive_submissions.zip"},{"key":"2_CR5","unstructured":"Module-lattice-based key-encapsulation mechanism standard. FIPS 203 (2024). https:\/\/nvlpubs.nist.gov\/nistpubs\/FIPS\/NIST.FIPS.203.pdf"},{"key":"2_CR6","unstructured":"Hamming quasi-cyclic (HQC) (2025). https:\/\/pqc-hqc.org\/doc\/hqc_specifications_2025_08_22.pdf"},{"key":"2_CR7","doi-asserted-by":"publisher","unstructured":"Alagic, G., et al.: Status report on the fourth round of the NIST post-quantum cryptography standardization process (2025). https:\/\/doi.org\/10.6028\/NIST.IR.8545, https:\/\/tsapps.nist.gov\/publication\/get_pdf.cfm?pub_id=959556","DOI":"10.6028\/NIST.IR.8545"},{"key":"2_CR8","doi-asserted-by":"crossref","unstructured":"Alagic, G., Carolan, J., Majenz, C., Tokat, S.: The sponge is quantum indifferentiable. arXiv:2504.16887 (2025)","DOI":"10.1109\/FOCS63196.2025.00135"},{"key":"2_CR9","doi-asserted-by":"publisher","unstructured":"Alwen, J., Hartmann, D., Kiltz, E., Mularczyk, M., Schwabe, P.: Post-quantum multi-recipient public key encryption. In: CCS \u201923, Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp. 1108\u20131122. Association for Computing Machinery, New York, NY, USA (2023). https:\/\/doi.org\/10.1145\/3576915.3623185","DOI":"10.1145\/3576915.3623185"},{"key":"2_CR10","doi-asserted-by":"crossref","unstructured":"Ambainis, A., Hamburg, M., Unruh, D.: Quantum security proofs using semi-classical oracles. In: Advances in Cryptology \u2013 CRYPTO 2019 (2021)","DOI":"10.1007\/978-3-030-26951-7_10"},{"key":"2_CR11","unstructured":"Aviram, N., Dowling, B., Komargodski, I., Paterson, K.G., Ronen, E., Yogev, E.: Practical (post-quantum) key combiners from one-wayness and applications to TLS. Cryptology ePrint Archive, Paper 2022\/065 (2022). https:\/\/eprint.iacr.org\/2022\/065"},{"key":"2_CR12","doi-asserted-by":"publisher","unstructured":"Backendal, M., Bellare, M., G\u00fcnther, F., Scarlata, M.: When messages are keys: is hmac a dual-prf? In: Handschuh, H., Lysyanskaya, A. (eds.) Advances in Cryptology \u2013 CRYPTO 2023, pp. 661\u2013693. Springer Nature Switzerland, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_22","DOI":"10.1007\/978-3-031-38548-3_22"},{"key":"2_CR13","doi-asserted-by":"publisher","unstructured":"Barbosa, M., et al.: X-wing. IACR Commun. Cryptology 1(1) (2024). https:\/\/doi.org\/10.62056\/a3qj89n4e","DOI":"10.62056\/a3qj89n4e"},{"key":"2_CR14","doi-asserted-by":"publisher","unstructured":"Barker, E., Chen, L., Davis, R.: Recommendation for key-derivation methods in key-establishment schemes. NIST SP 800-56C Rev. 2 (2020). https:\/\/doi.org\/10.6028\/NIST.SP.800-56Cr2","DOI":"10.6028\/NIST.SP.800-56Cr2"},{"key":"2_CR15","doi-asserted-by":"publisher","first-page":"602","DOI":"10.1007\/11818175_36","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"M Bellare","year":"2006","unstructured":"Bellare, M.: New proofs for NMAC and HMAC: security without collision-resistance. In: Dwork, C. (ed.) Advances in Cryptology - CRYPTO 2006, pp. 602\u2013619. Springer, Berlin Heidelberg, Berlin, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_36"},{"key":"2_CR16","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-540-78967-3_11","volume-title":"Advances in Cryptology - EUROCRYPT 2008","author":"G Bertoni","year":"2008","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: On the indifferentiability of the sponge construction. In: Smart, N. (ed.) Advances in Cryptology - EUROCRYPT 2008, pp. 181\u2013197. Springer, Berlin Heidelberg, Berlin, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78967-3_11"},{"key":"2_CR17","unstructured":"Bhargavan, K., Jacomme, C., Kiefer, F., Schmidt, R.: Formal verification of the PQXDH post-quantum key agreement protocol for end-to-end secure messaging. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 469\u2013486. USENIX Association, Philadelphia, PA (2024). https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/bhargavan"},{"key":"2_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1007\/978-3-030-25510-7_12","volume-title":"Post-Quantum Cryptography","author":"N Bindel","year":"2019","unstructured":"Bindel, N., Brendel, J., Fischlin, M., Goncalves, B., Stebila, D.: Hybrid key encapsulation mechanisms and authenticated key exchange. In: Ding, J., Steinwandt, R. (eds.) PQCrypto 2019. LNCS, vol. 11505, pp. 206\u2013226. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-25510-7_12"},{"key":"2_CR19","unstructured":"Campagna, M., Petcher, A.: Security of hybrid key encapsulation. Cryptology ePrint Archive, Paper 2020\/1364 (2020). https:\/\/eprint.iacr.org\/2020\/1364"},{"key":"2_CR20","unstructured":"Chen, L.: Recommendation for key derivation using pseudorandom functions. NIST SP 800-108r1-upd1 (2022). https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-108r1-upd1.pdf"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Chevalier, C., Lebrun, G., Martinelli, A.: Spilling-cascade: an optimal PKE combiner for KEM hybridization. In: 23rd International Conference on Applied Cryptography and Network Security (ACNS\u201925). Munich, Germany (2025). https:\/\/hal.science\/hal-05027882","DOI":"10.1007\/978-3-031-95761-1_16"},{"key":"2_CR22","unstructured":"Connolly, D., H\u00f6velmanns, K., H\u00fclsing, A., Kousidis, S., Meijers, M.: Starfighters \u2014 on the general applicability of x-wing. Cryptology ePrint Archive, Paper 2025\/1397 (2025). https:\/\/eprint.iacr.org\/2025\/1397"},{"key":"2_CR23","doi-asserted-by":"publisher","unstructured":"Cremers, C., Dax, A., Medinger, N.: Keeping up with the KEMs: stronger security notions for KEMs and automated analysis of KEM-based protocols. In: CCS \u201924, Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp. 1046\u20131060. Association for Computing Machinery, New York, NY, USA (2024). https:\/\/doi.org\/10.1145\/3658644.3670283","DOI":"10.1145\/3658644.3670283"},{"key":"2_CR24","doi-asserted-by":"publisher","unstructured":"Don, J., Fehr, S., Huang, Y.H.: Adaptive versus static multi-oracle algorithms, and quantum security of a split-key PRF. In: Theory of Cryptography: 20th International Conference, TCC 2022, Chicago, IL, USA, November 7\u201310, 2022, Proceedings, Part I, pp. 33\u201351. Springer-Verlag, Berlin, Heidelberg (2022). https:\/\/doi.org\/10.1007\/978-3-031-22318-1_2","DOI":"10.1007\/978-3-031-22318-1_2"},{"key":"2_CR25","unstructured":"Federal Office for Information Security (BSI): Quantum-safe cryptography - fundamentals, current developments and recommendations (2022). https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/EN\/BSI\/Publications\/Brochure\/quantum-safe-cryptography.pdf?__blob=publicationFile&v=6"},{"key":"2_CR26","unstructured":"French Cybersecurity Agency (ANSSI) and Federal Office for Information Security (BSI) and Netherlands National Communications Security Agency (NLNCSA) and Swedish National Communications Security Authority, Swedish Armed Forces: Position paper on quantum key distribution (2024). https:\/\/cyber.gouv.fr\/sites\/default\/files\/document\/Quantum_Key_Distribution_Position_Paper.pdf"},{"key":"2_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"E Fujisaki","year":"1999","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 537\u2013554. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1_34"},{"issue":"1","key":"2_CR28","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/s00145-011-9114-1","volume":"26","author":"E Fujisaki","year":"2013","unstructured":"Fujisaki, E., Okamoto, T.: Secure integration of asymmetric and symmetric encryption schemes. J. Cryptol. 26(1), 80\u2013101 (2013). https:\/\/doi.org\/10.1007\/s00145-011-9114-1","journal-title":"J. Cryptol."},{"key":"2_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1007\/978-3-662-44371-2_7","volume-title":"Advances in Cryptology \u2013 CRYPTO 2014","author":"P Ga\u017ei","year":"2014","unstructured":"Ga\u017ei, P., Pietrzak, K., Ryb\u00e1r, M.: The exact PRF-security of NMAC and HMAC. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014. LNCS, vol. 8616, pp. 113\u2013130. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44371-2_7"},{"key":"2_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/978-3-319-76578-5_7","volume-title":"Public-Key Cryptography \u2013 PKC 2018","author":"F Giacon","year":"2018","unstructured":"Giacon, F., Heuer, F., Poettering, B.: KEM combiners. In: Abdalla, M., Dahab, R. (eds.) PKC 2018. LNCS, vol. 10769, pp. 190\u2013218. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-76578-5_7"},{"key":"2_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/11426639_6","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"D Harnik","year":"2005","unstructured":"Harnik, D., Kilian, J., Naor, M., Reingold, O., Rosen, A.: On robust combiners for oblivious transfer and other primitives. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 96\u2013113. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_6"},{"key":"2_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/978-3-319-70500-2_12","volume-title":"Theory of Cryptography","author":"D Hofheinz","year":"2017","unstructured":"Hofheinz, D., H\u00f6velmanns, K., Kiltz, E.: A modular analysis of the Fujisaki-Okamoto transformation. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017. LNCS, vol. 10677, pp. 341\u2013371. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_12"},{"key":"2_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"585","DOI":"10.1007\/978-3-030-84242-0_21","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"A Hosoyamada","year":"2021","unstructured":"Hosoyamada, A., Iwata, T.: On tight quantum security of HMAC and NMAC in the quantum random oracle model. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12825, pp. 585\u2013615. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84242-0_21"},{"key":"2_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/978-3-030-92548-2_12","volume-title":"Cryptology and Network Security","author":"L Huguenin-Dumittan","year":"2021","unstructured":"Huguenin-Dumittan, L., Vaudenay, S.: FO-like combiners and\u00a0hybrid post-quantum cryptography. In: Conti, M., Stevens, M., Krenn, S. (eds.) CANS 2021. LNCS, vol. 13099, pp. 225\u2013244. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92548-2_12"},{"key":"2_CR35","doi-asserted-by":"crossref","unstructured":"Katz, J., Lindell, Y.: Introduction to Modern Cryptography, Third edn. CRC Press (2021)","DOI":"10.1201\/9781351133036"},{"key":"2_CR36","doi-asserted-by":"crossref","unstructured":"Kelsey, J., Chang, S.j., Perlner, R.: SHA-3 derived functions: cSHAKE, KMAC, TupleHash, and ParallelHash . NIST SP 800-185 (2016). https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-185.pdf","DOI":"10.6028\/NIST.SP.800-185"},{"key":"2_CR37","doi-asserted-by":"publisher","unstructured":"Krawczyk, H., Eronen, P.: HMAC-based extract-and-expand key derivation function (HKDF). RFC 5869 (2010). https:\/\/doi.org\/10.17487\/RFC5869, https:\/\/www.rfc-editor.org\/info\/rfc5869","DOI":"10.17487\/RFC5869"},{"key":"2_CR38","doi-asserted-by":"crossref","unstructured":"Kr\u00e4mer, J., Struck, P., Weish\u00e4upl, M.: Binding security of implicitly-rejecting KEMs and application to BIKE and HQC. Cryptology ePrint Archive, Paper 2024\/1233 (2024). https:\/\/eprint.iacr.org\/2024\/1233","DOI":"10.62056\/ak2i893y6"},{"key":"2_CR39","doi-asserted-by":"publisher","unstructured":"Liu, Y., Zhou, B., Jiang, H.: CuKEM: a concise and unified hybrid key encapsulation mechanism. Cryptology ePrint Archive, Paper 2025\/1862 (2025). https:\/\/doi.org\/10.1145\/3719027.3744863, https:\/\/eprint.iacr.org\/2025\/1862","DOI":"10.1145\/3719027.3744863"},{"key":"2_CR40","unstructured":"O\u2019Brien, D.: Protecting chrome traffic with hybrid kyber KEM. Chromium blog (2023). https:\/\/blog.chromium.org\/2023\/08\/protecting-chrome-traffic-with-hybrid.html"},{"key":"2_CR41","unstructured":"Shen, Y., Wang, L., Gu, D.: Security analysis of NIST key derivation using pseudorandom functions. Cryptology ePrint Archive, Paper 2025\/815 (2025). https:\/\/eprint.iacr.org\/2025\/815"},{"key":"2_CR42","unstructured":"Xu, J., Gao, Y., Lim, H.W., Wang, H., Chang, E.C.: Stateful KEM: towards optimal robust combiner for key encapsulation mechanism. Cryptology ePrint Archive, Paper 2021\/989 (2021). https:\/\/eprint.iacr.org\/2021\/989"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-32560-0_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T12:04:39Z","timestamp":1784635479000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-32560-0_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,22]]},"ISBN":["9783032325594","9783032325600"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-32560-0_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,22]]},"assertion":[{"value":"22 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","label":"Disclosure of Interests","group":{"name":"EthicsHeading","label":"Ethics"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Stony Brook, WI","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 June 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 June 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/acns2026.github.io\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}