Professional experience

PQShield
Staff Cryptography Architect
Oxford, UK
Dec 2019 - present

Developed multiple products providing FIPS 140-3 certified and CNSA 2.0 compliant post-quantum key exchange for protocols such as TLS v1.3. Led software implementation of cryptographic schemes, optimized memory and performance across diverse CPU architectures, and implemented security hardening against side-channel attacks.

Cloudflare
Cryptography Engineer
London, UK
Feb 2018 - Dec 2019

Deployed post-quantum cryptography in TLS on production servers using BoringSSL, collaborating with Google to advance CECPQ2 adoption. Co-authored CIRCL, Cloudflare’s high-performance cryptographic library, and contributed to the implementation and optimization of TLS 1.3.

Trustonic
Security Engineer
Cambridge, UK
May 2015 - Jan 2018

Contributed to the development of a Trusted Execution Environment (TEE) based on ARM TrustZone technology. Responsible for implementing cryptographic components and performing security validation across multiple system modules.

Amadeus
Software Engineer
Sophia-Antipolis, France
Jun 2008 – May 2015

Responsible for maintaining and implementing various functionalities in the Amadeus core system security and communication framework (C++ based). Focusing mainly on security and stability of TLS connections, performance optimization, improvements to failure resilience of high-availability components.

Tieto, BenQ
Project Manager
Wrocław, Poland
Dec 2005 – May 2008

Started as a Software Engineer and grew to a manager position. I’ve been managing teams developing PC software tools for Nokia/Symbian based mobile phones. Products were used in Nokia’s customer care centres for device reparation as well as end-users for firmware update. I’ve built a team of 20 developers and testers located in Poland, the Czech Republic and China working on multiple software projects for Nokia.

Projects

Below I have outlined the project examples that truly spark my interest and enthusiasm for collaboration.

PQCryptoLib
|
PQShield

Original author, principal investigator and designer. A cryptographic library implementing post-quantum schemes together with everything needed to sit behind a TLS 1.3 stack as its cryptographic engine, with PQ/T hybrid key exchange as the focus. Led development end to end over five years, from concept to production: implemented the schemes in software, optimized memory and performance across multiple CPU architectures, and hardened the code against side-channel attacks.

FIPS 140-3 Validation
|
PQShield

CMVP validation of PQCryptoLib - single-handedly and from scratch: defined the module boundary and its approved and non-approved services, wrote the security policy, produced the algorithm test evidence and ran the CAVP submissions, and worked the module through the lab and the certification queue to completion as a Level 1 software module.

The ML-KEM wasn’t yet FIPS-approved function, hence most of the work was done by carefully constructing ML-KEM with P-256 (according t SP800-56Cr2), so that it fits within what the standard permits, and describing it in terms the lab and CMVP would accept. The result was the first validated module offering PQ/T hybrid key agreement with ML-KEM and ECDH/P-256.

RFC 10024
|
IETF / TLS Working Group

Co-author of the IETF standard for PQ/T hybrid key exchange in TLS 1.3, combining a post-quantum KEM with elliptic curve Diffie-Hellman (ECDHE). It is what allows a FIPS-validated, cryptogrphic library such as PQCryptoLib to be used by any TLS implementation for post-quantum key agreement.

RFC is already deployed by major browsers (Chrome, Firefox) as well as cloud service providers (Cloudflare, Google, AWS).

PQMicroLib
|
PQShield

Fork of the PQCryptoLib codebase redesigned for constrained devices, focsing on ARM profile-M MCUs, where the binding limit is RAM rather than throughput. Runs bare metal or under an RTOS in as little as 5 KB of RAM, with optional DPA protection alongside the timing and remote-attack hardening.

Covers ML-KEM, ML-DSA, SHA3, SHAKE, SLH-DSA and the stateful hash-based LMS (verification), for secure boot, firmware updates, attestation and provisioning. Algorithms are CAVP certified. The library is deployed on multiple embedded environments.

draft-pqc-hsm-constrained

IETF / PQUIP Working Group
(ongoing effort)

IETF draft Adapting Constrained Devices for Post-Quantum Cryptography. Guidance for putting PQC on constrained devices and Edge IoT nodes. Draft describes some ideas implemented in PQMicroLib. Co-authored with T.Reddy, D. Wing and B. Salter.

CIRCL |
Cloudflare

It is a collection of cryptographic primitives written in Go. The goal of this library is to be used as a tool for experimental deployment of cryptographic algorithms targeting Post-Quantum (PQ). Project is open-source and was co-inveted with Armando Faz-Hernández.

Kinibi TEE
Trustonic

I was part of the team implementing, Trustonic’s Trusted Execution Environment - Kinibi.

Publications

  • Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3 |
    P. Kampanakis, K. Kwiatkowski, D. Stebila, B. E. Westerbaan
  • NIST SP 1800-38C: Migration to Post-Quantum Cryptography - Quantum Readiness |
    W. Newhouse, M. Souppaya, J. Prat, R. Larrieu, R. Burns, W. Barker, J. Gray, M. Ounsworth, C. Viana, J. Gilbert, G. Scinta, C. Brown, H. Le Van Gong, P. Kampanakis, K. Kwiatkowski, E. Kim, J. Goodman, A. Hu, V. Krummel
  • An Efficient and Generic Construction for Signal’s Handshake (X3DH): Post-Quantum, State Leakage Secure, and Deniable |
    Keitaro Hashimoto, Shuichi Katsumata, Kris Kwiatkowski, Thomas Prest
  • Scalable Ciphertext Compression Techniques for Post-Quantum KEMs with Applications |
    Shuichi Katsumata, Kris Kwiatkowski, Federico Pintore, Thomas Prest
  • Measuring TLS key exchange with post-quantum KEM |
    Adam Langley, Dave Levin, Kris Kwiatkowski, Alan Mislove, Nick Sullivan, Luke Valenta
  • The TLS Post-Quantum Experiment |
    Kris Kwiatkowski, Luke Valenta
  • Towards Post-Quantum Cryptography in TLS |
    Kris Kwiatkowski

Talks

  • Post-Quantum Cryptography in Practice: Migration Strategies for Constrained and Embedded Systems |
    London Crypto, Imperial College London | London, UK | Nov, 2025
  • Post-Quantum Cryptography for IoT Edge |
    IPSoC Days Silicon Valley | Santa Clara, USA | Apr, 2025
  • Post-Quantum Cryptography for IoT Edge. Implementation tradeoffs and security pitfalls |
    TPM.dev | Cambridge, UK | Sep, 2024
  • PQC Implementations, Tradeoffs and Pitfalls
    GlobalPlatform Workshop | Virtual | Feb, 2024
  • Cryptographic interfaces for secure IoT devices |
    International Cryptographic Module Conference (ICMC 2022) | Washington D.C., USA | Sep, 2022
  • Implementing a FIPS-Certifiable Crypto Module for Post-Quantum TLS |
    CryptoMod 2022 | Brussels, Belgium | May, 2021
  • Report on IETF and ETSI activities around Post-Quantum systems |
    GlobalPlatform Workshop | Virtual | Nov, 2021
  • Post-Quantum cryptography for C++ developers |
    WroC++ | Virtual | Nov, 2021
  • Ciphertext Compression Techniques for Post-Quantum KEMs |
    University of Waterloo | Virtual | Oct, 2020
  • Measuring post-quantum TLS
    International Cryptographic Module Conference (ICMC 2020) | Virtual | Sep, 2020
  • Towards Post-Quantum Cryptography in TLS |
    Workshop on Elliptic Curve Cryptography (ECC) | Ruhr-University, Germany | Dec, 2019

Volunteering

  • CHES 2026 - Member of artifact review committee | []
  • CHES 2025 - Member of artifact review committee | []
  • CHES 2024 - Member of artifact review committee | []
  • PETS 2024 - Member of artifact review committee
  • PETS 2023 - Member of artifact review committee
  • CHES 2021 - Member of artifact review committee
  • IETF 115 - …
  • CARDIS 2020 - Additional reviewer
  • COSADE 2020 - Additional reviewer
  • 17th IMA International Conference on Cryptography and Coding, 2019 - Additional reviewer
  • Technical reviewer for a book Demystifying Cryptography with OpenSSL 3.0 by Alexei Khlebnikov