Glossary

What is hybrid encryption?

Hybrid encryption combines two kinds of cryptography so each covers the other’s weakness. Classically, it means using public-key encryption to share a key and a fast symmetric cipher like AES to encrypt the data. In post-quantum security, it also means pairing a classical key exchange like X25519 with a quantum-resistant one like ML-KEM.

Also called: hybrid cryptography, hybrid key exchange, PQ/T hybrid

Updated September 2026. Sources are numbered and listed at the end.

How hybrid encryption works

Most explainers cover only the first meaning. Both are in use every day, often in the same connection.

Meaning 1: public-key plus symmetric

Public-keySymmetric
ExamplesRSA, X25519, ML-KEMAES-256-GCM, ChaCha20-Poly1305
Good atSharing a secret with someone you’ve never metEncrypting lots of data fast
Weak atSlow, and limited in how much it can encryptBoth sides need the same key first

So you use each for what it’s good at. The sender generates a random one-time key, encrypts the message with it using a symmetric cipher, then protects that small key with the recipient’s public key. The recipient unlocks the small key with their private key and uses it to decrypt the message. The IETF standardized this pattern as HPKE in RFC 9180.1 TLS, PGP and S/MIME all work this way.

Meaning 2: classical plus post-quantum

Here, “hybrid” means running two key exchanges at once, usually X25519 and ML-KEM, and feeding both results into a key derivation function to produce one key. An attacker has to break both. X25519 has decades of analysis behind it but falls to a quantum computer. ML-KEM resists quantum attacks but is newer. Together, a surprise weakness in either one isn’t enough.

Why it matters

Nearly all real-world encryption is hybrid in the first sense, because public-key math alone is too slow for whole files or video streams. The second sense is how the internet is moving to post-quantum security without betting everything on new math. It’s also the answer to harvest now, decrypt later: data sent over a hybrid key exchange today stays protected even after a quantum computer can break X25519.

Where you’ll see it

  • Web browsing: Chrome has used the X25519MLKEM768 hybrid by default since Chrome 131 (November 2024),2 now standardized for TLS 1.3 in RFC 10024.3
  • SSH: OpenSSH 10.0 defaults to mlkem768x25519-sha256.4
  • Messaging: Signal’s PQXDH combines X25519 with a post-quantum KEM,5 and Apple’s iMessage PQ3 pairs elliptic-curve keys with Kyber.6

Hybrid encryption in Secria

Secria Mail is hybrid in both senses. Message bodies are encrypted with AES-256-GCM, and the key that unlocks them is protected by ML-KEM-1024 combined with X25519, joined with HKDF-SHA256. Someone would have to break both to read your mail. It’s on for every plan, free included. The full construction is in our whitepaper, and the plain-words version is on post-quantum email.

Sources

  1. IETF, RFC 9180: Hybrid Public Key Encryption (February 2022).
  2. Google Security Blog, A new path for Kyber on the web (September 2024).
  3. IETF, RFC 10024: Post-quantum traditional hybrid key agreement for TLS 1.3.
  4. OpenSSH, Post-quantum cryptography.
  5. Signal, The PQXDH key agreement protocol.
  6. Apple Security Research, iMessage with PQ3 (February 2024).

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about hybrid encryption

Why not use only public-key encryption?+

It’s slow and can only encrypt small amounts of data at once. Hybrid encryption uses public-key cryptography just to protect a short symmetric key, then encrypts the real data quickly with that key.

Is hybrid post-quantum encryption safer than ML-KEM alone?+

It’s more conservative. If a flaw turns up in ML-KEM, X25519 still protects against today’s attackers. If a quantum computer breaks X25519, ML-KEM still holds. The cost is a little extra data per connection.

Is TLS hybrid encryption?+

Yes. TLS uses a key exchange to agree on keys and a symmetric cipher for the data. Modern browsers also use a hybrid post-quantum key exchange, X25519MLKEM768, by default.

What is the difference between hybrid and end-to-end encryption?+

Hybrid describes how the encryption is built. End-to-end describes who can read the result: only the sender and recipient. An end-to-end encrypted message is usually hybrid encrypted under the hood.

Email that’s ready for what comes next. Post-quantum encryption on every plan, free included.