{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T16:11:06Z","timestamp":1778256666027,"version":"3.51.4"},"reference-count":60,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,10,6]],"date-time":"2023-10-06T00:00:00Z","timestamp":1696550400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>Using multiple, individual encryption schemes is a well-established method to increase the overall security of encrypted data. These so-called multiple encryption or hybrid schemes have regained traction in the context of public-key cryptography due to the rise of quantum computers, since it allows the combination of well-known classical encryption schemes with novel post-quantum schemes. In this paper, we conduct a survey of the state-of-the-art public-key multiple encryption (M-PKE) schemes. For the first time, we describe the most relevant M-PKE schemes in detail and discuss their security in a unified model, which allows better comparison between the schemes. Hence, we compare the security, efficiency, and complexity of the schemes and offer recommendations for usage based on common use cases. Our survey emphasizes the importance of being deliberate when combining encryption schemes, as small nuances can easily break security.<\/jats:p>","DOI":"10.3390\/cryptography7040049","type":"journal-article","created":{"date-parts":[[2023,10,6]],"date-time":"2023-10-06T07:49:29Z","timestamp":1696578569000},"page":"49","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["On Multiple Encryption for Public-Key Cryptography"],"prefix":"10.3390","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8372-4503","authenticated-orcid":false,"given":"Tudor","family":"Soroceanu","sequence":"first","affiliation":[{"name":"Secure Systems Engineering, Fraunhofer AISEC, 14199 Berlin, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8388-6059","authenticated-orcid":false,"given":"Nicolas","family":"Buchmann","sequence":"additional","affiliation":[{"name":"Secure Systems Engineering, Fraunhofer AISEC, 14199 Berlin, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marian","family":"Margraf","sequence":"additional","affiliation":[{"name":"Secure Systems Engineering, Fraunhofer AISEC, 14199 Berlin, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,10,6]]},"reference":[{"key":"ref_1","first-page":"120","article-title":"A Method for Obtaining Digital Signatures and Public-Key Cryptosystems","volume":"21","author":"Rivest","year":"1978","journal-title":"Commun. Assoc. Comput. Mach."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","article-title":"New Directions in Cryptography","volume":"22","author":"Diffie","year":"1976","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"505","DOI":"10.1038\/s41586-019-1666-5","article-title":"Quantum Supremacy Using a Programmable Superconducting Processor","volume":"574","author":"Arute","year":"2019","journal-title":"Nature"},{"key":"ref_4","unstructured":"IBM (2023, September 02). IBM Unveils 400 Qubit-Plus Quantum Processor and Next-Generation IBM Quantum System Two. Available online: https:\/\/newsroom.ibm.com\/2022-11-09-IBM-Unveils-400-Qubit-Plus-Quantum-Processor-and-Next-Generation-IBM-Quantum-System-Two."},{"key":"ref_5","unstructured":"NIST (2023, August 25). Selected Algorithms 2022\u2014Post-Quantum Cryptography|CSRC|CSRC, Available online: https:\/\/csrc.nist.gov\/Projects\/post-quantum-cryptography\/selected-algorithms-2022."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Dodis, Y., and Shrimpton, T. (2022). Advances in Cryptology\u2014CRYPTO 2022, Springer Nature. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-031-15979-4"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Hazay, C., and Stam, M. (2023). Advances in Cryptology\u2013EUROCRYPT 2023, Springer Nature. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-031-30620-4"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1007\/s13389-022-00288-9","article-title":"Post-Quantum Hybrid Key Exchange: A Systematic Mapping Study","volume":"13","author":"Giron","year":"2022","journal-title":"J. Cryptogr. Eng."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"656","DOI":"10.1002\/j.1538-7305.1949.tb00928.x","article-title":"Communication Theory of Secrecy Systems","volume":"28","author":"Shannon","year":"1949","journal-title":"Bell Syst. Tech. J."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Chaum, D. (1984). Advances in Cryptology: Proceedings of Crypto 83, Springer.","DOI":"10.1007\/978-1-4684-4730-9"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1007\/BF02620231","article-title":"Cascade Ciphers: The Importance of Being First","volume":"6","author":"Maurer","year":"1993","journal-title":"J. Cryptol."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Krawczyk, H. (1998). Advances in Cryptology\u2014CRYPTO \u201998, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/BFb0055715"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1145\/358699.358718","article-title":"On the Security of Multiple Encryption","volume":"24","author":"Merkle","year":"1981","journal-title":"Commun. Acm"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1016\/0898-1221(81)90029-8","article-title":"An Efficient Algorithm for Constructing a Cryptosystem Which Is Harder to Break than Two Other Cryptosystems","volume":"7","author":"Asmuth","year":"1981","journal-title":"Comput. Math. Appl."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"159","DOI":"10.3233\/JCS-2009-0336","article-title":"Folklore, Practice and Theory of Robust Combiners","volume":"17","author":"Herzberg","year":"2009","journal-title":"J. Comput. Secur."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Zhang, R., Hanaoka, G., Shikata, J., and Imai (2023, July 06). On the Security of Multiple Encryption or CCA-security+CCA-security=CCA-security?. Available online: https:\/\/eprint.iacr.org\/2003\/181.","DOI":"10.1007\/978-3-540-24632-9_26"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"188","DOI":"10.1007\/978-3-540-30576-7_11","article-title":"Chosen-Ciphertext Security of Multiple Encryption","volume":"Volume 3378","author":"Hutchison","year":"2005","journal-title":"Theory of Cryptography"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Abdalla, M., and Barreto, P.S.L.M. (2010). Progress in Cryptology\u2014LATINCRYPT 2010, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-642-14712-8"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"663","DOI":"10.1007\/978-3-642-29011-4_39","article-title":"Detecting Dangerous Queries: A New Approach for Chosen Ciphertext Security","volume":"Volume 7237","author":"Hutchison","year":"2012","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2012"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Goncalves, B., and Mashatan, A. (2022). Tightly Secure PKE Combiner in the Quantum Random Oracle Model. Cryptography, 6.","DOI":"10.3390\/cryptography6020015"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1007\/11426639_6","article-title":"On Robust Combiners for Oblivious Transfer and Other Primitives","volume":"Volume 3494","author":"Hutchison","year":"2005","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2005"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Bao, F., Deng, R., and Zhou, J. (2004). Public Key Cryptography\u2014PKC 2004, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/b95631"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1007\/978-3-662-53008-5_18","article-title":"Obfuscation Combiners","volume":"Volume 9815","author":"Robshaw","year":"2016","journal-title":"Advances in Cryptology\u2014 CRYPTO 2016"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1007\/978-3-030-45721-1_6","article-title":"Combiners for Functional Encryption, Unconditionally","volume":"Volume 12105","author":"Canteaut","year":"2020","journal-title":"Advances in Cryptology\u2014 EUROCRYPT 2020"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"190","DOI":"10.1007\/978-3-319-76578-5_7","article-title":"KEM Combiners","volume":"Volume 10769","author":"Abdalla","year":"2018","journal-title":"Public-Key Cryptography\u2014 PKC 2018"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"206","DOI":"10.1007\/978-3-030-25510-7_12","article-title":"Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange","volume":"Volume 11505","author":"Ding","year":"2019","journal-title":"Post-Quantum Cryptography"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1007\/978-3-030-92548-2_12","article-title":"FO-like Combiners and Hybrid Post-Quantum Cryptography","volume":"Volume 13099","author":"Conti","year":"2021","journal-title":"Cryptology and Network Security"},{"key":"ref_28","unstructured":"Braithwaite, M. (2023, January 30). Experimenting with Post-Quantum Cryptography. Available online: https:\/\/security.googleblog.com\/2016\/07\/experimenting-with-post-quantum.html."},{"key":"ref_29","unstructured":"Alkim, E., Ducas, L., P\u00f6ppelmann, T., and Schwabe, P. (2016, January 10\u201312). Post-Quantum Key Exchange: A New Hope. Proceedings of the 25th USENIX Conference on Security Symposium, SEC\u201916, Austin, TX, USA."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Fischer, W., and Homma, N. (2017). Cryptographic Hardware and Embedded Systems \u2014CHES 2017, Springer International Publishing. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-319-66787-4"},{"key":"ref_31","unstructured":"K\u00f6lbl, S., Misoczki, R., and Schmieg, S. (2023, January 30). Why Google Now Uses Post-Quantum Cryptography for Internal Comms. Available online: https:\/\/cloud.google.com\/blog\/products\/identity-security\/why-google-now-uses-post-quantum-cryptography-for-internal-comms."},{"key":"ref_32","unstructured":"Kwiatkowski, K., and Valenta, L. (2023, April 23). TLS Post-Quantum Experiment. Available online: http:\/\/blog.cloudflare.com\/the-tls-post-quantum-experiment\/."},{"key":"ref_33","unstructured":"Easterbrook, K., and Paquin, C. (2023, April 26). Post-Quantum TLS. Available online: https:\/\/www.microsoft.com\/en-us\/research\/project\/post-quantum-tls."},{"key":"ref_34","unstructured":"Anastasova, M., Kampanakis, P., and Massimo, J. (2022, January 3\u20139). PQ-HPKE: Post quantum hybrid public key encryption. Proceedings of the ICMC 2022, Limerick, Ireland."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1007\/BFb0055718","article-title":"Relations among Notions of Security for Public-Key Encryption Schemes","volume":"Volume 1462","author":"Goos","year":"1998","journal-title":"Advances in Cryptology\u2014CRYPTO \u201998"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1007\/s00145-005-0310-8","article-title":"Characterization of Security Notions for Probabilistic Private-Key Encryption","volume":"19","author":"Katz","year":"2006","journal-title":"J. Cryptol."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Boneh, D. (2003). the Advances in Cryptology\u2014CRYPTO 2003, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/b11817"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1007\/3-540-46035-7_6","article-title":"On the Security of Joint Signature and Encryption","volume":"Volume 2332","author":"Goos","year":"2002","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2002"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1007\/978-3-319-42634-1_21","article-title":"Combiners for Chosen-Ciphertext Security","volume":"Volume 9797","author":"Dinh","year":"2016","journal-title":"Computing and Combinatorics"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1007\/s00145-011-9114-1","article-title":"Secure Integration of Asymmetric and Symmetric Encryption Schemes","volume":"26","author":"Fujisaki","year":"2013","journal-title":"J. Cryptol."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Biham, E. (1997). Fast Software Encryption, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/BFb0052329"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"503","DOI":"10.1007\/3-540-48405-1_32","article-title":"On the Security Properties of OAEP as an All-or-Nothing Transform","volume":"Volume 1666","author":"Goos","year":"1999","journal-title":"Advances in Cryptology\u2014CRYPTO\u2019 99"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Bellare, M. (2000). Advances in Cryptology\u2014CRYPTO 2000, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/3-540-44598-6"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Filipe, J., and Obaidat, M.S. (2008). E-Business and Telecommunication Networks, Springer. Communications in Computer and Information Science.","DOI":"10.1007\/978-3-540-70760-8"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Blakley, G.R. (1979, January 4\u20137). Safeguarding Cryptographic Keys. Proceedings of the 1979 International Workshop on Managing Requirements Knowledge (MARK), New York, NY, USA.","DOI":"10.1109\/MARK.1979.8817296"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"612","DOI":"10.1145\/359168.359176","article-title":"How to Share a Secret","volume":"22","author":"Shamir","year":"1979","journal-title":"Commun. ACM"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Park, J.J., Lopez, J., Yeo, S.S., Shon, T., and Taniar, D. (2011). Secure and Trust Computing, Data Management and Applications, Springer. Communications in Computer and Information Science.","DOI":"10.1007\/978-3-642-22339-6"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Wang, Y., and Desmedt, Y. (2014, January 2\u20135). Efficient Secret Sharing Schemes Achieving Optimal Information Rate. Proceedings of the 2014 IEEE Information Theory Workshop (ITW 2014), Hobart, TAS, Australia.","DOI":"10.1109\/ITW.2014.6970885"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"659","DOI":"10.1109\/TIT.2021.3123692","article-title":"Communication Efficient Secret Sharing With Small Share Size","volume":"68","author":"Ding","year":"2022","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_50","unstructured":"(2006). Information Technology\u2014Security Techniques\u2014Encryption Algorithms\u2014Part 2: Asymmetric Ciphers (Standard No. ISO\/IEC 18033-2:2006)."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1137\/S0097539702403773","article-title":"Design and Analysis of Practical Public-Key Encryption Schemes Secure against Adaptive Chosen Ciphertext Attack","volume":"33","author":"Cramer","year":"2004","journal-title":"SIAM J. Comput."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1007\/978-3-540-40974-8_12","article-title":"A Designer\u2019s Guide to KEMs","volume":"Volume 2898","author":"Goos","year":"2003","journal-title":"Cryptography and Coding"},{"key":"ref_53","first-page":"341","article-title":"A Modular Analysis of the Fujisaki-Okamoto Transformation","volume":"Volume 10677","author":"Kalai","year":"2017","journal-title":"Theory of Cryptography"},{"key":"ref_54","unstructured":"Goncalves, B., Mashatan, A., Fallah, J., Byrne, K., and Siddavaatam, P. (2022). Quantum-Augmentable Hybrid Encryption System and Method. (11,431,498), U.S. Patent."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Rahman, M., Rokon, I.R., and Rahman, M. (2009, January 20\u201322). Efficient Hardware Implementation of RSA Cryptography. Proceedings of the 2009 3rd International Conference on Anti-Counterfeiting, Security, and Identification in Communication, Hong Kong, China.","DOI":"10.1109\/ICASID.2009.5276895"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"525","DOI":"10.1016\/j.procs.2020.01.024","article-title":"Fast and Area Efficient Implementation of RSA Algorithm","volume":"165","author":"Thabah","year":"2019","journal-title":"Procedia Comput. Sci."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"228","DOI":"10.1016\/j.micpro.2010.04.006","article-title":"A High Performance ECC Hardware Implementation with Instruction-Level Parallelism over GF(2163)","volume":"34","author":"Zhang","year":"2010","journal-title":"Microprocess Microsystems"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"MuthuKumar, B., and Jeevananthan, S. (2010, January 17\u201319). High Speed Hardware Implementation of an Elliptic Curve Cryptography (ECC) Co-Processor. Proceedings of the Trendz in Information Sciences & Computing (TISC2010), Chennai, India.","DOI":"10.1109\/TISC.2010.5714634"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"328","DOI":"10.46586\/tches.v2021.i2.328-356","article-title":"A Compact Hardware Implementation of CCA-Secure Key Exchange Mechanism CRYSTALS-KYBER on FPGA","volume":"2021","author":"Xing","year":"2021","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Jati, A., Gupta, N., Chattopadhyay, A., and Sanadhya, S.K. (2023). A Configurable CRYSTALS-Kyber Hardware Implementation with Side-Channel Protection. ACM Trans. Embed. Comput. Syst.","DOI":"10.1145\/3587037"}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/7\/4\/49\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:02:04Z","timestamp":1760130124000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/7\/4\/49"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,6]]},"references-count":60,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["cryptography7040049"],"URL":"https:\/\/doi.org\/10.3390\/cryptography7040049","relation":{},"ISSN":["2410-387X"],"issn-type":[{"value":"2410-387X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,6]]}}}