Score
Designs, implements, and evaluates cryptographic modules, protocols, and deployment strategies that integrate post-quantum cryptography algorithms (key-exchange, public-key encryption, and signatures) into existing systems and communication stacks, ensuring interoperability, performance constraints, and migration from classical primitives. Builds and analyzes secure implementations and hybrid schemes, including key management and testing for compatibility, side-channel risks, and preservation of quantum-resistant confidentiality and authentication guarantees.
Quantum computing poses an existential threat to public-key cryptography, necessitating timely adoption of NIST-standardized post-quantum cryptographic (PQC) algorithms—Kyber, Dilithium, FALCON, and SPHINCS+. Method: This paper systematically evaluates PQC support across nine major open-source cryptographic libraries—including OpenSSL and Bouncy Castle—through rigorous analysis of official documentation, release notes, and real-world deployment practices. Contribution/Results: We identify substantial disparities in implementation completeness, API maturity, and production readiness: only a minority offer stable, production-grade integrations, while most remain experimental or unimplemented. To address this gap, we propose the first multi-dimensional PQC support assessment framework, quantitatively pinpointing key standardization bottlenecks. Based on empirical findings, we recommend three actionable strategies: phased migration, cross-library interoperability coordination, and development of standardized PQC testing benchmarks. Our results provide evidence-based guidance for library developers, standards bodies, and system deployers navigating the transition to quantum-resilient cryptography.
Large-scale quantum computers threaten the public-key cryptographic foundations underpinning today's network security infrastructures. While significant progress has been made in standardizing post-quantum cryptographic (PQC) primitives and adapting individual protocols such as TLS and SSH, far less attention has been paid to the broader architectural consequences of the post-quantum transition for networked systems. In particular, many real-world deployments such as mobile networks, industrial control systems, IoT environments, and regulated infrastructures cannot assume the universal availability, deployability, or desirability of PQ public-key infrastructures. This paper presents the first comprehensive systematization of PQ-resistant network architectures, focusing on key distribution and management as a system-level design problem rather than a protocol-local substitution. We introduce a unified taxonomy spanning cryptographic foundations (symmetric-only, PQ-PKI, hybrid, and information-theoretic multi-path), key-distribution architectures (centralized, hierarchical, replicated, threshold, MPC-backed, and serverless), trust and threat models, key-management lifecycle, and deployment environments. Using this framework, we analyze the security, scalability, and operational trade-offs of a wide range of architectures under realistic PQ adversary assumptions, including harvest-now, decrypt-later attacks and partial infrastructure compromise. Our study highlights fundamental gaps in existing approaches, clarifies when PQ-PKI is necessary or avoidable, and identifies promising research directions for building cryptographically agile, quantum-resilient network infrastructures.
The NIST post-quantum cryptography (PQC) standardization marks a critical transition to deployment, yet a significant gap persists between standardized specifications and practical engineering implementation. This paper systematically constructs a comprehensive technical framework for quantum-resistant migration, covering security analysis, standardization status, performance, and communication overhead of six major PQC families: lattice-based, code-based, hash-based, multivariate, isogeny-based, and MPC-in-the-Head schemes. It further investigates hardware acceleration (AVX2/FPGA/ASIC), protocol integration (TLS/PKI), constrained-environment deployment, and synergies with QKD/QRNG. Innovatively, the work proposes an implementation pathway centered on cryptographic agility and hybrid transition, augmented with side-channel mitigation and domain-specific guidance—bridging the standard–implementation–operation divide. It delivers empirically grounded recommendations for algorithm selection, system integration, and migration strategy, while identifying parameter agility and leakage-resilient implementations as key future research directions.
Quantum computing poses a significant threat to classical cryptographic protocols based on RSA and elliptic curve cryptography, necessitating a systematic assessment of their vulnerabilities and post-quantum migration pathways. This study presents the first comprehensive comparison of structural barriers and deployment disparities across nine widely used protocols—including TLS, IPsec, and BGP—during post-quantum transitions. Drawing on both literature review and empirical analysis, it examines hybrid key exchange mechanisms, standardization progress, and real-world deployment cases. The findings reveal that key exchange generally proves more amenable to migration than authentication; TLS and Signal have already achieved large-scale hybrid deployments, whereas DNSSEC and BGP confront fundamental challenges due to signature size constraints. Crucially, message size and fragmentation limitations emerge as more critical bottlenecks than algorithmic performance.
This work addresses the threat posed by quantum computing to current public-key cryptography by designing and implementing a hybrid end-to-end encryption system that ensures messages are encrypted and decrypted exclusively on clients within a zero-trust architecture. The system integrates the NIST-standardized CRYSTALS-Kyber algorithm into real-world communication for the first time, combining it with AES-256-GCM and SHA-256 to achieve both post-quantum security and practical efficiency. Experimental results demonstrate that the proposed scheme provides robust protection against both classical and quantum attacks while maintaining acceptable performance overhead, thereby validating the feasibility of deploying NIST’s post-quantum cryptographic standards in real-world environments. The implementation is open-sourced to support reproducible research.
With quantum computing posing an emerging threat to telecommunications infrastructure, practical migration to post-quantum cryptography (PQC) faces significant challenges in performance, interoperability, and regulatory compliance. Method: This paper systematically evaluates the end-to-end performance of NIST-standardized PQC algorithms—CRYSTALS-Kyber (KEM) and Dilithium (signature)—in critical 5G authentication scenarios, providing the first empirical comparison against RSA-3072 and ECDSA-256 at equivalent security levels. We propose a pragmatic PQC migration framework addressing legacy interoperability, regulatory requirements, and phased deployment, and optimize implementations using AVX2 instructions. Contribution/Results: Kyber and Dilithium core operations achieve 3.2–5.8× higher throughput than RSA-3072; Dilithium signing speed improves by 41%. Pilot deployments across two live operator networks demonstrate feasibility of integrating PQC into 5G AKA, with authentication latency overhead <8 ms—confirming scalability for real-world adoption.
This study addresses the severe threat posed by quantum computing to conventional public-key cryptography, particularly undermining the security of key authentication and digital signatures in X.509-based Public Key Infrastructure (PKI). The work systematically analyzes the integration requirements of NIST-selected post-quantum cryptographic algorithms into X.509 certificates, Certificate Revocation Lists (CRLs), and the Online Certificate Status Protocol (OCSP). It presents the first comprehensive framework for structural and protocol-level adaptations necessary to support these algorithms within existing PKI components. Through rigorous compatibility and performance evaluations, the study identifies viable migration pathways and provides concrete technical guidance and standardization recommendations for transitioning to a quantum-resistant PKI.
This study addresses the usability challenges of post-quantum cryptography (PQC) APIs, which—due to their high complexity and developer-unfriendly documentation—often lead non-expert developers to misuse them and inadvertently introduce security vulnerabilities, thereby hindering real-world deployment. As the first systematic investigation into PQC API usability, this work empirically evaluates how developers interact with NIST-standardized PQC algorithms under minimal training, employing user studies, task observations, and cognitive analyses. The findings uncover critical issues including inconsistent terminology, a lack of canonical workflow examples, and insufficient interactive guidance. These insights provide empirical grounding and concrete design recommendations for building more usable PQC development support systems that better serve practitioners transitioning to quantum-resistant cryptography.
This study addresses the compounded security risks arising from multi-layer encryption in network protocol stacks under post-quantum threat models. It presents the first cross-layer cryptographic transformation framework based on lattice-theoretic structures, formally characterizing the quantum vulnerabilities of individual layers and their compositional effects on confidentiality and authentication. Leveraging quantum vulnerability classification, lattice operations (join and meet), and cross-platform protocol stack analysis (Linux/iOS), the work demonstrates that end-to-end confidentiality is dictated by the weakest (most quantum-vulnerable) layer, whereas authentication requires post-quantum security across the entire stack. Notably, WPA2-Personal exhibits stronger practical post-quantum security than both WPA3-Personal and WPA2-Enterprise. While single-layer post-quantum encryption suffices to protect payload confidentiality, metadata protection depends solely on the outermost layer.
This work addresses the challenge of achieving scalable, end-to-end post-quantum secure communication in multi-hop trusted-node quantum networks by proposing a hierarchical modular architecture that uniquely integrates quantum key distribution (QKD) with post-quantum cryptography (PQC). The approach leverages QKD to establish hop-by-hop secure tunnel keys while employing the Rosenpass protocol for end-to-end PQC key exchange. Crucially, this design achieves post-quantum forward secrecy and strong authentication without requiring modifications to existing QKD hardware or protocols, enabling seamless integration into current infrastructure. A prototype implementation—built using WireGuard tunnels, the ETSI GS QKD 014 interface, and open-source components—demonstrates low overhead, high availability, and fail-safe operation in multi-hop simulations and experiments, confirming the scheme’s practicality alongside its robust security guarantees.
This work addresses the limited visibility into TLS configurations within heterogeneous environments—a critical barrier to the secure and efficient deployment of post-quantum cryptography (PQC) in financial institutions. The authors propose an enterprise-grade framework for automated parsing and standardization of TLS configurations, which constructs a unified, auditable inventory of cryptographic assets. By doing so, it shifts the primary bottleneck of PQC migration from the algorithmic layer to the operational layer. The framework supports MLKEM and hybrid key exchange schemes, demonstrating effectiveness across 8,443 real-world Nginx configurations. Already deployed in production at financial institutions, it achieves zero application-layer modifications and incurs only manageable performance overhead, thereby substantially enhancing the operational feasibility and regulatory compliance of PQC transitions.