Imagine you need to prove your identity at a border checkpoint, but instead of showing a passport (a signature), you and the guard each lock a shared secret inside boxes only the other can open. If both boxes open correctly, you've authenticated each other without ever flashing a credential. That's the core mechanism of HPQ-AKE: replace digital signatures — which in the post-quantum world are enormous and slow — with two interlocking key-encapsulation operations, one classical (RSA-OAEP) and one post-quantum (ML-KEM-768). The committed claim: HPQ-AKE is a provably secure, sign-less hybrid authenticated key exchange that achieves post-quantum session secrecy and forward secrecy while cutting handshake transmission by 56.4% versus Hybrid TLS 1.3, specifically for bandwidth-constrained IoT and edge networks that already have RSA infrastructure. This is not a new cryptographic primitive — it's a protocol-level architectural choice that sidesteps the biggest pain point in post-quantum migration: bloated certificate chains. The ladder matters here. The baseline is a Hybrid TLS 1.3 Full handshake combining ML-KEM-768 with ML-DSA-65 signatures, which requires 13,009 bytes of handshake data. HPQ-AKE brings that to 5,668 bytes. Under a simulated 50 kbps satellite link with 600 ms RTT, median handshake latency drops from 2,791 ms to 1,914 ms — a 31.4% reduction. The break-even bandwidth at 20 ms RTT is 0.31 Mbps against the pre-cached baseline and 4.08 Mbps against the full baseline. These are meaningful numbers for constrained links, but they're entirely modeled on x86 hardware, not measured on actual IoT gateways or ARM microcontrollers. Architecturally, HPQ-AKE sits in the hybrid KEM family — combining a lattice-based KEM (ML-KEM-768, Module-LWE hardness) with RSA-OAEP for implicit authentication. The key design choice is eliminating transcript signatures entirely, which removes ML-DSA verification from the handshake critical path. The security proof operates in an extended Bellare-Rogaway model, splitting classical authentication (Random Oracle Model) from session-key secrecy (Quantum Random Oracle Model). The protocol achieves AKE security, forward secrecy, and conditional KCI resistance under long-term-key-only exposure assumptions — a reasonable but not maximal threat model. Integrity is the weak point. All performance numbers come from x86 micro-benchmarks, analytical latency models, and 10,000-iteration Monte Carlo simulation of network conditions. There is no real IoT hardware test, no real network deployment, no independent replication. The authors are admirably honest about this — the abstract itself states 'performance on ARM gateways and unaccelerated microcontrollers remains unvalidated' — but the gap between simulated satellite links on a desktop and an actual LoRaWAN gateway is significant. The security proof is formal and structured, which is a genuine strength, but the performance claims are entirely synthetic. The milestone question is straightforward: HPQ-AKE needs to be benchmarked on real gateway-class hardware (ARM Cortex-A, RISC-V) and validated over real constrained links (LoRa, NB-IoT, satellite). The 7.11 ms local computation figure on x86 will likely be 5-20× slower on a resource-constrained gateway. If the protocol holds its bandwidth advantage and stays under, say, 100 ms of local computation on a Cortex-A53, it becomes a practical candidate for real deployment. That's a 12-18 month experiment away. The obvious experiment the authors did not run: ARM gateway benchmarking. The paper explicitly acknowledges this gap and frames the x86 results as 'motivating' such evaluation. The honest read is (a) — they ran out of hardware access or time, not that the results were bad. The protocol's bandwidth advantage is structural (fewer bytes on the wire), so it should survive the platform transition. The latency advantage is less certain, because RSA-OAEP decryption on constrained ARM hardware without acceleration could be painful. The second missing experiment is a comparison against KEMTLS and other sign-less TLS variants that use a single KEM for authentication — the paper cites these but doesn't benchmark head-to-head.