Post-Quantum TLS with KEMs

We investigate alternate ways to bring TLS into the post-quantum age. Notably, we try to get rid of the expensive signature schemes in the online handshake, by authenticating using only KEMs.

Thom Wiggers
