Migrating to Hybrid Cryptography in Practice: The TutaCrypt Protocol and Its Security

In this work, we study the hybrid key establishment protocol TutaCrypt as a concrete case of post-quantum cryptographic migration in practice. The protocol was developed by the end-to-end encrypted email provider Tuta and has been deployed to more than ten million users worldwide. We present the protocol in a form that enables rigorous cryptographic analysis and define two Bellare–Rogaway-style security models that precisely characterize the provided security guarantees. The two models capture that the security properties achieved in the pre-quantum setting are slightly stronger than in the post-quantum setting. We then give reduction-based security proofs that clarify under which assumptions the construction achieves security, and how its guarantees degrade if either the classical or the post-quantum component is compromised. Our results illustrate how formally grounded cryptographic models can capture real-world migration strategies and hybrid deployments. Such analyses help to understand the security properties of deployed cryptographic systems and help move cryptographic migration from best practice toward principled, verifiable design.

Authors

Institutions

Publication Details

Journal
IACR Communications in Cryptology
Published
2026-08-03
DOI
https://doi.org/10.62056/ab89n5qiu
Primary Topic
Cryptography and Data Security
Type
article
Field-Weighted Citation Impact
0.00

Funders

Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Migrating to Hybrid Cryptography in Practice: The TutaCrypt Protocol and Its Security

Tom Neuschulten, Tibor Jager, Christian Holler
IACR Communications in Cryptology
Cryptography and Data Security
article

Migrating to Hybrid Cryptography in Practice: The TutaCrypt Protocol and Its Security

Tom Neuschulten, Tibor Jager, Christian Holler
article en

Abstract

In this work, we study the hybrid key establishment protocol TutaCrypt as a concrete case of post-quantum cryptographic migration in practice. The protocol was developed by the end-to-end encrypted email provider Tuta and has been deployed to more than ten million users worldwide. We present the protocol in a form that enables rigorous cryptographic analysis and define two Bellare–Rogaway-style security models that precisely characterize the provided security guarantees. The two models capture that the security properties achieved in the pre-quantum setting are slightly stronger than in the post-quantum setting. We then give reduction-based security proofs that clarify under which assumptions the construction achieves security, and how its guarantees degrade if either the classical or the post-quantum component is compromised. Our results illustrate how formally grounded cryptographic models can capture real-world migration strategies and hybrid deployments. Such analyses help to understand the security properties of deployed cryptographic systems and help move cryptographic migration from best practice toward principled, verifiable design.

IACR Communications in CryptologyVol. 3(2)
University of Wuppertal (DE)
Bundesministerium für Bildung und Forschung
Reduced inequalities
Openalex Percentile: Top 7%
Cryptography and Data Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.