How hybrid encryption works
Most explainers cover only the first meaning. Both are in use every day, often in the same connection.
Meaning 1: public-key plus symmetric
| Public-key | Symmetric | |
|---|---|---|
| Examples | RSA, X25519, ML-KEM | AES-256-GCM, ChaCha20-Poly1305 |
| Good at | Sharing a secret with someone you’ve never met | Encrypting lots of data fast |
| Weak at | Slow, and limited in how much it can encrypt | Both sides need the same key first |
So you use each for what it’s good at. The sender generates a random one-time key, encrypts the message with it using a symmetric cipher, then protects that small key with the recipient’s public key. The recipient unlocks the small key with their private key and uses it to decrypt the message. The IETF standardized this pattern as HPKE in RFC 9180.1 TLS, PGP and S/MIME all work this way.
Meaning 2: classical plus post-quantum
Here, “hybrid” means running two key exchanges at once, usually X25519 and ML-KEM, and feeding both results into a key derivation function to produce one key. An attacker has to break both. X25519 has decades of analysis behind it but falls to a quantum computer. ML-KEM resists quantum attacks but is newer. Together, a surprise weakness in either one isn’t enough.
Why it matters
Nearly all real-world encryption is hybrid in the first sense, because public-key math alone is too slow for whole files or video streams. The second sense is how the internet is moving to post-quantum security without betting everything on new math. It’s also the answer to harvest now, decrypt later: data sent over a hybrid key exchange today stays protected even after a quantum computer can break X25519.
Where you’ll see it
- Web browsing: Chrome has used the X25519MLKEM768 hybrid by default since Chrome 131 (November 2024),2 now standardized for TLS 1.3 in RFC 10024.3
- SSH: OpenSSH 10.0 defaults to mlkem768x25519-sha256.4
- Messaging: Signal’s PQXDH combines X25519 with a post-quantum KEM,5 and Apple’s iMessage PQ3 pairs elliptic-curve keys with Kyber.6
Hybrid encryption in Secria
Secria Mail is hybrid in both senses. Message bodies are encrypted with AES-256-GCM, and the key that unlocks them is protected by ML-KEM-1024 combined with X25519, joined with HKDF-SHA256. Someone would have to break both to read your mail. It’s on for every plan, free included. The full construction is in our whitepaper, and the plain-words version is on post-quantum email.
Related terms
Sources
- IETF, RFC 9180: Hybrid Public Key Encryption (February 2022).
- Google Security Blog, A new path for Kyber on the web (September 2024).
- IETF, RFC 10024: Post-quantum traditional hybrid key agreement for TLS 1.3.
- OpenSSH, Post-quantum cryptography.
- Signal, The PQXDH key agreement protocol.
- Apple Security Research, iMessage with PQ3 (February 2024).
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.