Research

Watch · narrated whiteboard episodesL3

Migrating to Post-Quantum: Crypto-Agility in Real Protocols

The hard part of post-quantum cryptography is not the math - it is swapping primitives inside protocols, certificates, and hardware without breaking interoperability. This series is the engineering playbook: hybrid key exchange, PQC in TLS 1.3, certificate and PKI bloat, crypto-agility as an architecture property, and a repeatable migration methodology. Grounded in NIST SP 800-56C, IETF hybrid drafts, and NIST IR 8547.

Murali Chillakuru·5 episodes
  1. 22 min Episode 1Hybrid Key Exchange, Done Right: Combining Classical and Post-Quantum So Either Can FailA moderator and a cryptography expert explain the workhorse of the post-quantum transition — running a classical and a post-quantum key exchange together, why a proper key-derivation function combines them, the exact robustness guarantee it buys, the pitfalls that forfeit it, why hybrid is needed now, and how it's actually deployed.
  2. 22 min Episode 2Post-Quantum in TLS 1.3: The X25519MLKEM768 Group and the MTU RealitiesA moderator and a networking-security expert examine what it takes to deploy hybrid post-quantum key exchange in TLS 1.3 — how the hybrid group slots into the handshake, why the larger ClientHello can exceed a network packet, the middlebox and MTU realities that break, the downgrade and retry costs, and the current deployment guidance.
  3. 22 min Episode 3Certificates and PKI Under Post-Quantum: Signature Bloat and Chain StrategiesA moderator and a security expert tackle the harder side of the transition — where signatures live in the certificate chain, how badly post-quantum signatures bloat the handshake, why the chain multiplies the problem, the crucial urgency asymmetry between confidentiality and authentication, strategies to tame the bloat, and the mutual-authentication case.
  4. 23 min Episode 4Crypto-Agility as an Architecture Property: Escaping the Hard-Coded-Primitive TrapA moderator and a software-architecture expert explain how to build systems that survive cryptographic change — what crypto-agility really is, the hard-coded-primitive trap, negotiation and algorithm identifiers and safe versioning, why agility is an ongoing property, the anti-patterns to avoid, and what it all means for AI agents.
  5. 23 min Episode 5A Migration Methodology: Inventory, Shelf-Life Risk, Hybridize, and MeasureIn the migration finale, a moderator and a security-program expert lay out how to actually run a post-quantum migration — inventory your cryptography, risk-rank by data shelf-life and Mosca's inequality, hybridize and measure, treat it as a continuous loop, govern it with gates, and adapt it for AI-agent infrastructure.