AN AUTHENTICATED HYBRID KEY EXCHANGE: EPHEMERAL DIFFIE-HELLMAN, RSA, NON-LINEAR AFFINE CIPHER AND HMAC-BASED INTEGRITY
DOI:
https://doi.org/10.70917/ijcisim-2026-5117Keywords:
Ephemeral Diffie-Hellman, RSA, Non-linear Affine Cipher, HMAC-SHA256, HKDF, Forward Secrecy, Avalanche EffectAbstract
Modern data networks now carry every kind of traffic that matters to a person or a business. Keeping that traffic safe is no longer an option but a real need. Our earlier work joined Diffie-Hellman, RSA and a refined Affine Cipher to block the Man-in-the-Middle attack and to hide the RSA prime-factor key. That model worked well for confidentiality. It still left three open gaps. The Affine layer was a linear map. The session key had no forward secrecy. The system had no way to detect tampering. This research paper closes all three. We replace static Diffie-Hellman with the ephemeral form. We add a non-linear S-box ahead of the Affine step. We also add an HMAC-SHA256 tag for integrity. The key derivation now uses HKDF as defined in RFC 5869 [1]. We test the new model on the same byte streams used in our earlier research paper titled “A Hybrid Approach to Enhance Key Exchange: Twofold Secured Diffie Hellman, RSA and Add-on SHA 256 Algorithms”. We compare it on five fronts: Risk Score, Throughput, Latency, Shannon Entropy and Avalanche Effect. The Authenticated Hybrid scheme drops the Risk Score from 3 to 2. It lifts Throughput from 18.6 to 24.1 Kbps. It cuts Latency from 461 ms to 405 ms. The Shannon Entropy reaches 7.994 bits per byte. The Avalanche Effect lands at 49.6 percent. That last figure is very close to the ideal 50 percent line of a strong cipher [2].