The Engineering of Transition-Period Cryptography
Hybrid cryptography, running classical and post-quantum algorithms together so that the combination is secure if either remains unbroken, is the consensus transition strategy. But hybrid implementation is genuinely difficult engineering, with multiple approaches that have different security properties, performance characteristics, and operational implications. This course covers the engineering of hybrid cryptography in depth.
Course Outline
Module 1. Hybrid Cryptography Foundations
Why hybrid is the consensus transition approach. The security rationale, which is that a sound combiner keeps the construction secure while either component holds, and what the combiner has to guarantee for that to be true. Where NIST, BSI, ANSSI and NCSC each stand, what each one’s guidance actually covers, and why NIST leaves the deployment decision to a case-by-case analysis. The different hybrid approaches and how they differ. When hybrid is necessary versus when post-quantum-only is acceptable.
Module 2. Hybrid Key Exchange
Hybrid key exchange in detail. Concatenation approaches (as deployed in TLS 1.3). KDF-based combiners with formal security proofs. Performance and bandwidth implications. Negotiation and fallback handling. Hands-on configuration of hybrid TLS.
Module 3. Hybrid Signatures
Hybrid signature schemes. Nested and composite signature approaches. Dual-certificate strategies. The size and performance implications of hybrid signatures. Use cases where hybrid signatures matter: code signing, document signing, and long-lived trust.
Module 4. Protocol Integration and Exit Planning
Integrating hybrid cryptography into TLS, SSH, IPsec, and application protocols. Performance measurement methodology. Operational considerations for hybrid deployments. Exit planning: how and when to remove the classical algorithm once confidence in post-quantum algorithms is established.
Prerequisites
A working understanding of PQC fundamentals is recommended. Consider Post-Quantum Foundation or PQCS certification for background. Some courses assume security engineering experience.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. CPE credits earned may apply toward Quantum Academy certification maintenance.
Who this course is for
Cryptography engineers, protocol implementers, and security architects making hybrid deployment decisions in TLS, SSH, VPN, and code signing. Working familiarity with the protocols is assumed.
If you want the design principles rather than the implementation detail, Cryptographic Agility covers the design principles one level up.
What you’ll be able to do afterward
- Implement hybrid key exchange in TLS 1.3 using the concatenation and combiner approaches
- Choose between hybrid signature options and defend the choice against the maturity of each
- Size the performance and message-length cost of hybrid deployment on your own protocols
- Sequence a hybrid rollout so classical fallback never silently becomes the permanent state
- Plan the exit: the criteria and steps for retiring the classical half later
What you leave with
You leave with the course handbook, a PDF of the full material with the instructor notes written out in place of the slides’ bullet points, and a PDF copy of Quantum Ready, included at no extra cost. The handbook is yours to keep. For most organizations, that shared reference is the clearest return on a training budget.
Enrollment includes 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
Where this course fits
Post-Quantum Foundation or PQCS Specialist Training give the grounding this course builds on. Neither is enforced. PKI Modernization for Post-Quantum for certificate infrastructure, and Cryptographic Agility for the design principles underneath.
Why we teach this
The course is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org and written by the practitioners who teach here. The people who teach this course are running migration programs inside organizations now, and the course covers what those programs hit.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.