Next Article in Journal
Secure and Efficient Block Cipher Mode Design for Parallel Processing and Reliable Security
Next Article in Special Issue
A Hybrid Module-LWE and Hash-Based Framework for Memory-Efficient Post-Quantum Key Encapsulation
Previous Article in Journal / Special Issue
Post-Quantum PKI: A Survey of Applications and Benchmarking Practices
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Review

Post-Quantum Cryptography in Networking Protocols: Challenges, Solutions, and Future Directions

Computer Science Department, University of Colorado Colorado Springs, 1420 Austin Bluffs Pkwy, Colorado Springs, CO 80918, USA
*
Author to whom correspondence should be addressed.
Cryptography 2026, 10(1), 12; https://doi.org/10.3390/cryptography10010012
Submission received: 24 December 2025 / Revised: 28 January 2026 / Accepted: 9 February 2026 / Published: 12 February 2026
(This article belongs to the Special Issue Advances in Post-Quantum Cryptography)

Abstract

Post-quantum cryptography (PQC) provides the essential cryptographic algorithms needed to secure digital networking systems against future adversaries equipped with quantum computing. This paper reviews the PQC research landscape and identifies open challenges and future directions for the critical transition to PQC in digital networking systems. Building on the NIST standardization process which has hardened the PQC cipher algorithm security, this paper analyzes and describes the recent research on PQC implementations and integrations into scalable and standardized networking systems (Internet, web and cellular networks). We review research on the security, side-channel threats, performances, overheads, and compatibility of PQC ciphers. We also study the research incorporating PQC into the standardized web and cellular networking protocols, ranging from testing the PQC feasibility to proposing protocol solutions and mechanisms to enable PQC. Our study highlights the PQC challenge of large parameter sizes, common across the PQC cipher algorithms, and the research proposing protocol- and system-level mechanisms to address them. Informed by the survey, this paper identifies and highlights the research gaps and future directions to facilitate further research and development for PQC and to secure next-generation digital networking systems.

1. Introduction

Public-key cryptography underpins the security of modern digital networking, enabling secure key exchange (to set up symmetric cryptography or other keyed mechanisms), authentication, and data confidentiality across inherently untrusted networks. From securing web transactions and protecting sensitive financial and medical records to enabling trusted software updates, safeguarding critical infrastructure, and securing 5G and Internet of Things based in mobile environments, public-key cryptographic ciphers provide the foundational mechanisms that allow billions of devices and users to interact and communicate securely. Although the initial public-key cipher algorithms such as RSA and Diffie–Hellman Key Exchange have remained robust since 1976, recent advancements in quantum computing pose unprecedented threats against the existing public-key cryptography.
Post-quantum cryptography (PQC) ciphers are designed to replace the current classical post-quantum cipher algorithms, as the latter are vulnerable against adversaries capable of quantum computing. Shor’s algorithm [1], assuming quantum computing and qubit processing, breaks the prime factorization problem and discrete logarithm problems by reducing them to polynomial time complexity, in contrast to the non-polynomial time complexity if there is no quantum computing. These mathematical problems anchor the widely used public-key ciphers, such as RSA (prime factorization problem) and Diffie–Hellman Key Exchange, ElGamal Encryption, Digital Signature Algorithm, and Elliptic Curve Cryptography (discrete logarithm problem). These ciphers are widely used as building blocks of digital networking protocols requiring security protection.
National Institute of Standards and Technology (NIST) has conducted multiple-year and multiple-round standardization process since 2016. NIST invites the cryptographers around the world to analyze, crypt-analyze, and inform the cryptographic algorithms and has a solid track record of standardizing ciphers adopted pervasively for real-world use. Examples of NIST’s track record include Data Encryption Standard (DES) which got standardized in the 1970s, Advanced Encryption Standard (AES) in the 1990s, and Secure Hash Algorithms (SHA) in the 2000s and 2010s. These standardized cryptographic functions and algorithms are pervasively used in practice across the globe to anchor the secure digital protocols across computing and networking applications. After three rounds of crypt-analyzing and advancing the cipher algorithmic designs, NIST standardized three cipher families for digital signature (CRYSTALS-Dilithium, Falcon, and SPHINCS+) and two for key encapsulation mechanism (CRYSTALS-Kyber and HQC, although the standardization for the latter HQC is currently undergoing and planned for 2027). Recognizing the significance of PQC and empowered by NIST’s standardization of PQC ciphers, governmental, industrial, and standardization communities are transitioning from classical public-key ciphers to post-quantum ciphers. These efforts and initiatives include mandates/legislation (e.g., Quantum Computing Cybersecurity Preparedness Act in USA in 2022 [2]), education and workforce development, and open-source projects (e.g., Open Quantum Safe or OQS [3]).
This review paper surveys the state of the research landscape and identifies research gaps, open challenges, and future directions for PQC when applied and integrated into digital networking systems. As PQC ciphers are getting standardized by NIST and other networking standardization bodies, this paper provides a timely research review to inform and facilitate the research and development of PQC on networking protocols and systems.

1.1. Scope, Focuses, and Differentiation from Prior Reviews

This review paper focuses on the PQC implementation and integration into digital networking protocols and systems. This paper focus on the PQC ciphers standardized by NIST, whose history and standardization process are described in Section 2 to establish their maturity and the confidence in the ciphers. While Section 3 provides a higher level overview of the security research done in the past to shape and select the NIST standardization cipher algorithms, the rest of the paper focuses on PQC incorporation and integration into the digital networking protocols and systems, ranging from prototyping for proof-of-concept feasibility to updates and mechanisms to better support PQC. As such research is currently undergoing, we further discuss future directions to identify the research gaps and inform the future R&D in PQC and post-quantum networking protocols and systems.
We focus on scalable network which spans across geographical locations and are designed to support multiple user devices. Widely used scalable networks, such as the Internet, web, and cellular systems, involve multiple standardization bodies whose key roles are to ensure interoperability across governments and nations. The scalable networks of Internet/web and cellular provide the dominant, fundamental technologies for digital networking and continue to increase in their use and deployment.
These focuses are intentional to enhance the impact of this paper and to differentiate from other existing survey papers in PQC, e.g., [4,5,6,7,8,9,10]. For example, Joseph et al. [4] focuses more on the organization and managerial perspectives, such as compliance and strategies, which has high synergy with our focus on the standardized protocols due to the standardization’s impacts on the organizations across the globe. Ahmed et al. [5] studies across widely used open-source libraries (those implementing the PQC algorithms and the networking protocols) and their readiness for PQC development, which can complement this paper focusing on the research contributions and solutions. Other papers have sharper focuses on networking applications, such as IP networks (related to our focus on Internet/web) [9] and automotive vehicles (related to our focus on cellular, c.f., cellular V2X) [10]; our work is more general in networking applications and particularly focus on one of the most critical challenges of PQC, the larger parameter sizes and the resulting impacts on protocol standardizations.

1.2. Paper Organization and Research Topics

The rest of the paper is organized as follows. We begin with a background on PQC, including its motivation to prepare for quantum adversary and the NIST standardization process, in Section 2 before proceeding with more recent research on PQC. Section 3 provides an overview of the security research done in the past to shape and select the NIST standardization cipher algorithms. We provide a high level overview of the algorithmic evolutions and selections leveraging the NIST standardization process. Section 4 continues with the focus on the PQC cipher algorithms themselves and studies their performance, overhead, and compatibility. We survey the experimental demonstrations of PQC ciphers to show the feasibility of existing networking protocols for scalable network of web/Internet and cellular in Section 5. In some of those networking protocols, previous research began studying the incorporation and adoption challenges, particularly due to the larger parameter sizes, which are presented in Section 6. To inform and facilitate future research and development, we identify and discuss research gaps and potential future directions in Section 7 before concluding our paper in Section 8.
The research-oriented sections (Section 3, Section 4, Section 5 and Section 6) are organized according to the major research topics addressed in this paper. The organization of these research-oriented sections is illustrated in Figure 1 where the horizontal axis represents across scalable networking protocols and the protocol-focused research (Section 5 and Section 6) are built on top of the PQC cipher algorithm-focused research (Section 3 and Section 4). Section 6 for the solutions to address large parameters builds on the feasibility studies of Section 5 and targets a narrower set of protocols; to capture that, Section 6 is illustrated within Section 5 with narrower width than in Figure 1. The research review in these sections builds on the NIST PQC standardization process, which process and history are described in Section 2. While PQC cipher algorithms and security in Section 3 analyze the research that took place during the PQC standardization process, the other Section 4, Section 5 and Section 6 occurred later in or after the PQC standardization. Due to the practical relevance of the NIST PQC standardization, we prioritize the research studying and analyzing the PQC ciphers resulting from the standardization.

1.3. Survey Methodology

This review paper adopts a research-oriented narrative review and synthesis methodology, rather than a systematic review or meta-analysis framework. It provides a conceptual and technical synthesis of existing research focusing on the PQC incorporation and integration into scalable network protocols/systems, rather than a PRISMA-guided exhaustive coverage or statistical aggregation of prior work. For the research literature selection, we identified the literature through targeted searches of peer-reviewed journals, conference proceedings, and other preprint articles to match our topics identified in Figure 1. We prioritize technical relevance, originality, and contribution to the evolving PQC research landscape when selecting the literature. Based on our experience conducting research in PQC, we use informed expert judgment to guide literature selection, with the goal of maximizing the relevance and impact of this article. Table 1 lists the standardized acronyms that are used multiple times throughout this paper for ease of reference.

2. Background on Post-Quantum Cryptography

2.1. PQC Motivation: Preparing for Quantum Adversary

Public-key ciphers have their security based on mathematical hardness assumptions, which are problems believed to be computationally difficult to solve within practical time, i.e., non-polynomial time complexity. These problems are the prime factorization problem (e.g., for RSA) and discrete logarithm problem (for Diffie–Hellman Key Exchange, ElGamal Encryption, Elliptic Curve Cryptography, etc). The mathematical hardness assumptions have remained steadfast for decades since the invention of public-key cryptography (Diffie–Hellman Key Exchange) in 1976. Public-key ciphers built on these assumptions have been widely trusted and deployed, embodying the popular mantra among cryptographers and practitioners: “In Math We Trust.”
The emergence and advancement of quantum computing break such mathematical hardness assumptions. Shor’s algorithm [11], invented in 1994, provides a polynomial-time algorithm assuming quantum computing for solving the prime factorization and discrete log problem. For example, in 2001, as a proof-of-concept, a seven-qubit nuclear magnetic resonance (NMR) quantum computer applied Shor’s algorithm to find the prime factors of the number fifteen [12]. While the limited qubit counts of today’s quantum computers make it impractical to break the currently deployed public-key ciphers, the field of quantum computing is rapidly advancing. The latest developments in 2025 involve major tech companies building quantum computers which can support more than 1000 qubits, e.g., D-Wave Advantage2 [13] and IBM Condor [14]. Furthermore, IBM provides an open-source and publicly available software for accessing its quantum computers to enable research and development to broader public [15,16]. Motivated by the continuing advancements in quantum computing, PQC is designed to withstand attackers with quantum computing, as they build on new sets of hardness assumptions which remain secure against quantum computers.

2.2. NIST PQC Standardization

NIST facilitated PQC research and development through its global standardization process, actively soliciting cipher proposals and feedback, including those studying cryptanalysis to break the cipher designs and advance the overall PQC security. The NIST standardization is an international and unclassified effort, involving 25 distinct countries across the six continents. While NIST is a governmental agency in the US, its role was largely limited to facilitation and organization. The resulting standardized PQC ciphers will be utilized globally, as has been demonstrated by the past NIST standardizations for other non-post-quantum cryptographic primitives, e.g., DES, AES, and SHA.
NIST standardized PQC ciphers supporting two functionalities: key encapsulation mechanisms (KEM) for confidentiality/secrecy and digital signature for authenticity. These two functionalities are how public-key cryptography are used in the real-world practice; for example, while KEM can be used for data message encryption for its confidentiality protection, real-world practice uses symmetric-key encryption (while KEM or key exchange is used beforehand to establish and set up the symmetric key).
In response to the advancing threat posed by quantum computers, NIST announced in 2016 [17] the initiative to migrate from classical cryptography standards based on the discrete logarithm problem and integer factorization to quantum-resistant alternatives. This transition directly impacts the previous NIST standards, such as the key establishment specified in NIST SP 800-56 [18] and the digital signature defined in Federal Information Processing Standards (FIPS) 186-4 [19]. Unlike previous AES and SHA-3, NIST standardizes multiple cipher schemes spanning security levels 1 through 5, corresponding to classical and post-quantum strengths from AES-128 to AES-256. The NIST PQC standardization process involves multiple rounds. During these rounds, NIST publishes detailed reports, advances selected schemes toward standardization, and issues corresponding Federal Information Processing Standards (FIPS). For example, FIPS 203 covers Kyber (ML-KEM), FIPS 204 covers Dilithium (ML-DSA), FIPS 205 covers SPHINCS+ (SLH-DSA), and FIPS 206 covers Falcon (FN-DSA). These FIPS documents formally define the standardized algorithms and the PQC process timeline, as shown in Figure 2.
  • First Round: The first round of NIST PQC standardization concluded in January 2019. NIST received 82 submissions and evaluated them for security, performance, and practicality of implementation. This stage included an initial screening followed by a detailed technical analysis. Of these, 26 candidates advanced to the next round. The selected schemes represented diverse key encapsulation, signature, and key-agreement mechanisms (in contrast to the later rounds focusing on only two of them, key encapsulation and signature).
  • Second Round: The second round of the NIST PQC standardization process ran from January 2019 to July 2020 and focused on a detailed evaluation of the 26 cipher algorithms which advanced from the first round. This phase aimed to assess each candidate’s security, performance, and suitability for various applications. NIST conducted extensive testing, including software and hardware implementations, to measure resistance against multiple attack vectors, computational efficiency, and flexibility across key sizes and security levels. Based on these evaluations, NIST selected seven finalists and eight alternates to move forward to the third round for deeper analysis and testing before final standardization [20].
  • Third Round: The third round of the NIST PQC standardization process began in July 2020 and lasted 18 months, evaluating 15 candidate algorithms from the second round. This phase focused on thorough security analysis and performance assessment across both software and hardware platforms. In June 2021, the Third PQC Standardization Conference provided a forum for candidates and researchers to present experimental results and updates. Following evaluation, NIST selected seven finalists, including four KEM/PKE schemes: Classic McEliece, CRYSTALS-Kyber, NTRU and Saber, and three digital signature schemes: CRYSTALS-Dilithium, Falcon and Rainbow, along with eight alternate candidates. Significantly, the Rainbow digital signature was later broken using a classical attack [21]. At the conclusion of this round, four algorithms were chosen for immediate standardization, CRYSTALS-Kyber (Kyber) for KEM, and CRYSTALS-Dilithium (Dilithium), Falcon, and SPHINCS+ for digital signatures, with Dilithium designated as the primary signature scheme. In addition to Kyber, four additional KEM candidates, BIKE, Classic McEliece, HQC, and SIKE, advanced to the fourth round for further evaluation and potential future standardization, although not yet selected for the standardization.
  • Fourth Round: In the fourth round of the NIST PQC standardization process, in addition to the selected Kyber, four KEM algorithms moved forward. However, SIKE got removed after researchers broke it using a classical computer [22]. This left three remaining candidates. From 29 November to 1 December 2022, NIST held its fourth online PQC conference [23], where experts discussed candidate algorithms, reviewed new security and performance results, and shared implementation updates. The results of these sessions helped NIST move closer to choosing the final algorithms for standardization. Insights from these sessions guided NIST toward final algorithm selections, and the fourth-round report, published in March 2025, confirmed HQC for standardization [24]. HQC standardization is planned to be finalized and published in 2027.
  • NIST PQC Standardized Ciphers: NIST selected and standardized CRYSTALS-Kyber (Kyber) for KEM, and CRYSTALS-Dilithium 192 (Dilithium), Falcon, and SPHINCS+ for digital signature in the third round. In the fourth round, NIST selected HQC for an additional PQC KEM cipher and its standardization is ongoing and planned to be finalized in 2027.

3. PQC Cipher Security

The NIST standardization process was a global effort to research and develop PQC ciphers, particularly on the security effectiveness of the PQC ciphers, which often decided whether a cipher candidate survives and advances to the next round. In the multi-year and multi-round process, cryptographers and security researchers around the world studied them, including the cipher algorithm security, cryptanalysis, and side-channel vulnerabilities and threats.

3.1. PQC Algorithm Security and Hardness Problems

PQC includes diverse techniques, each relying on distinct mathematical structures or hard problems to ensure security. Hash-based cryptography utilizes secure hash functions, while lattice-based cryptography is founded on the computational difficulty of lattice problems. Multivariate cryptography employs systems of polynomial equations to address cryptographic challenges, and code-based cryptography relies on the properties of error-correcting codes. Isogeny-based cryptography, in contrast, exploits the structural characteristics of elliptic curves and isogenies. Each of these approaches is designed to provide robust security against both classical and quantum adversaries, offering unique advantages while also presenting specific implementation and performance challenges.

3.1.1. Security and Practicality in PQC KEM Ciphers

During NIST standardization Rounds 1 and 2, several lattice-based and non-lattice KEMs were eliminated due to concrete cryptanalytic threats and structural vulnerabilities. For example, the Round 3 alternative candidate, SIKE, was ultimately broken by a polynomial-time classical attack exploiting weaknesses in supersingular isogeny computations, leading to its removal despite prior confidence in its quantum resistance [22].
For structured lattice schemes assessed during Round 2 and Round 3, Kyber and Saber both resisted known primal and dual lattice attacks, whose costs are typically estimated using lattice basis reduction techniques such as BKZ [25,26]. However, NIST favored Kyber because its security is based on the Module Learning With Errors (MLWE) assumption, which benefits from a broader body of cryptanalytic analysis and reductions [27], while Saber is entirely based on Module Learning With Rounding (MLWR), a related but less widely studied assumption [28]. Although in practice no concrete attack currently distinguishes MLWR from MLWE, this difference in research maturity provides less confidence in the security of MLWR compared to MLWE.
Similarly, the alternative candidate NTRU Prime in Round 2 claims improved resistance to potential future algebraic attacks by avoiding cyclotomic rings; however, this advantage remains largely theoretical, as no published attacks have revealed concrete vulnerabilities in schemes based on MLWE or RLWE such as Kyber or NTRU [29,30].

3.1.2. Security and Practicality in PQC Digital Signature Ciphers

Like KEMs, several digital signature candidates were removed from the NIST PQC process due to critical cryptanalytic vulnerabilities, primarily during NIST Round 3, including Rainbow, GeMSS, and PICNIC. GeMSS, a multivariate Hidden Field Equations (HFE) scheme with vinegar and minus modifiers, was broken by a polynomial-time key-recovery attack that exposed the private key structure [31]. While GeMSS produced relatively small signatures, its large public keys and slow signing further limited practical deployment. PICNIC, a symmetric zero-knowledge signature based on the LowMC block cipher and MPC-in-the-head technique, was vulnerable to key-recovery attacks on LowMC using a single plaintext–ciphertext pair, enabling practical forgeries and highlighting unresolved concerns about LowMC’s concrete security, which contributed to PICNIC not being advanced [32].
Dilithium is a lattice-based signature scheme with strong security and good performance, and NIST selected it as the main signature standard. FALCON provides similar security with much smaller keys and signatures, making it suitable for bandwidth-limited scenarios, but it is harder to implement securely. SPHINCS+ relies solely on hash-function security, offering algorithmic diversity, but it has large signatures and lower performance than lattice-based schemes.

3.2. Side-Channel Threats

Cryptographic algorithms are mathematically secure, but physical implementations can leak secrets through side channels. Side-channel attacks encompass a variety of techniques that exploit different forms of leakage. Timing attacks exploit non-constant-time execution paths to recover secret values. Power and electromagnetic analysis techniques, including Simple Power Analysis (SPA), Differential Power Analysis (DPA), and Correlation Power Analysis (CPA), use direct observation or statistical processing of multiple measurements to extract secret information when leakage cannot be interpreted visually [33]. More advanced approaches, such as Template Attack (TA) [34] and Deep Learning-based Attacks (DL-SCA) [35], further enhance the attacker’s ability to distinguish secret-dependent patterns in noisy measurements. In this section, we focus on the side-channel vulnerabilities and threats against the PQC ciphers which got standardized by NIST as well as candidates that advanced to the fourth round, excluding those that did not advance.

Side-Channel Attacks on PQC KEMs

Polynomial pointwise multiplication is a fundamental operation in lattice-based KEMs and is highly vulnerable to side-channel leakage that can reveal secret polynomials. These operations primarily target using CPA and are amplified by malicious or chosen-ciphertext polynomials, with demonstrated breaks on software [36,37] and hardware [38] implementations. Both software attacks use the Hamming weight leakage model to target pointwise multiplication in Kyber. Karlov et al. [36] recovered secrets with 80 traces at the lowest security level, while Mujdei et al. [37] broke Kyber using 200 traces by jointly guessing coefficient pairs with the highest correlation. Zhao et al. [38] demonstrated a hardware side-channel attack using the Hamming distance model with specially designed ciphertexts. Their correlation-based attack significantly reduced the effort, requiring only about 1–2 thousand traces for key recovery.
The Fujisaki–Okamoto transform [39] prevents chosen-ciphertext attacks by outputting messages only for valid ciphertexts, but side-channel leakage during re-encryption and comparison can downgrade indistinguishability under chosen ciphertext attack (IND-CCA) to indistinguishability under chosen plaintext attack (IND-CPA). Such leakage enables oracle-based attacks that exploit information about decrypted messages to recover secret keys via chosen ciphertexts. Significantly, decryption-failure oracles exploiting timing or power leakage during ciphertext comparison have been shown to enable full key recovery [40]. Plaintext-checking oracles distinguish decrypted messages with only two possible values, and Ravi et al. [41] demonstrated this using electromagnetic leakage and a Welch’s t-test-based approach on Kyber, Saber, and Frodo. Ueno et al. [42] extended this approach to code- and isogeny-based schemes, successfully recovering the full secret key for HQC and a partial key for BIKE using neural-network-based trace classification.
Primas et al. [43] introduced the first single-trace side-channel attack on lattice-based schemes using electromagnetic leakage from Number Theoretic Transform (NTT), recovering the secret key through soft analytical side-channel attacks (template matching, belief propagation, and lattice decoding). Building on this, Pessl et al. [44] optimized this attack for practical constant-time implementations, reducing templates from 100 million to 213 and targeting only the session key, with proposed countermeasures including NTT coefficient shuffling or dummy operations.

3.3. Side-Channel Attacks on PQC Digital Signatures

Lattice-based digital signature algorithms rely on secret-dependent polynomial multiplications that introduce exploitable side-channel leakage during operations such as integer multiplication and modular reduction. Prior work has demonstrated practical attacks on Dilithium across software, hardware, and FPGA implementations using correlation analysis, classical CPA, and deep-learning-based profiling, achieving partial or full secret-key recovery with a feasible number of traces [45,46,47]. Although Dilithium’s large modulus significantly enlarges the key-guessing space, recent studies show that combining multiple leakage sources and employing refined points-of-interest (PoI) selection techniques can substantially enhance attack efficiency, even on resource-constrained platforms [45,47].
Lattice-based cryptanalysis is provided in [48,49]. Dachman-Soled et al. [48] provided a software toolkit named Sage 9.0, to perform side-channel attacks on lattice-based cryptography. They also proposed a cryptanalysis framework that can take advantage of side information or hints to perform lattice reduction attacks. Their analysis shows a significant cost reduction in performing cryptanalysis that utilizes hints. In [49], the authors performed cryptanalysis based on skip-addition fault attacks. They made use of the determinism in the signature algorithm and inject a single fault targeting the signing operation. A portion of the secret key was extracted and used by the proposed forgery algorithm to generate signatures. Their analyses included the skip-addition attacks on Dilithium and zero-cost mitigations.
Matthias et al. [50] analyzed DPA attacks on hash-based signature schemes (XMSS and SPHINCS), showing that leakage from hash and PRNG computations can reveal secret information under realistic leakage models. They demonstrated key recovery on BLAKE-256 in SPHINCS using EM traces and proposed countermeasures, such as partial DPA with more traces and randomizing the Mix procedure order.

4. Performance, Overhead, and Compatibility

This section focuses on the performance and overhead costs of PQC cipher algorithms themselves, while the following sections consider their integrations into the broader networking and systems.

4.1. Efficiency and Processing Overhead

Previous studies focused on comparing between the standardized PQC digital signature algorithms with same security objectives and levels, as there is one KEM cipher (NIST plans to standardize another KEM cipher in HQC, but the standardization and publication are ongoing as of November 2025) but multiple digital signature cipher algorithms. Basu et al. [51] presented one of the earliest such empirical PQC analyses on hardware implementations, although their study is based on NIST round two candidate ciphers, including Kyber, Dilithium, and SPHINCS+ in their precursor forms. Using more recent ciphers, Raavi et al. [52,53] conducted empirical studies to compare the PQC digital signature ciphers selected for NIST standardization. Their results demonstrate that the lattice-based PQC ciphers can provide comparable processing speed and efficiency as the classical RSA cipher, with Dilithium even outperforming RSA at equivalent security levels in some settings.
Other studies in both KEM and signature targeted applications involving lightweight and resource-constrained devices, presenting more stringent performance requirements and heightened sensitivity to computational overhead than other applications, such as Internet of Things (IoT) nodes and sensor networks. They evaluated the PQC performances and efficiency while simulating such resource-constrained devices using single-board computers (Raspberry Pi) [54,55,56,57] and microcontrollers (ARM Cortex-M processors) [57,58,59] and measuring the mobile-critical electrical power consumption performances [54,55,56,57].
PQC research advanced the efficiency and speed of PQC cipher executions by building specialized hardware to speed up the underlying arithmetic operations of the lattice-based and hash-based ciphers. The previous research include hardware-based design and accelerations specifically targeting PQC KEM of Kyber [60,61,62] as well as the PQC digital signatures of Dilithium [63,64,65,66,67,68], Falcon [69,70,71,72], and SPHINCS+ [73,74,75,76,77].

4.2. Large Parameter Sizes Affect Memory and Bandwidth

While efficiency and speed continue to advance for PQC, the major tradeoff and challenge of PQC are due to the their inherently large parameter sizes. Table 2 and Table 3 list the parameter sizes in Bytes (B) of the PQC KEM and digital signature ciphers, respectively. The parameter sizes depend on their security levels. The security levels (the “Security” column) correspond to the brute-force difficulty of finding the key from the attacker’s perspective where the security level one corresponds to the difficulty comparable to breaking AES-128; three corresponds to AES-192; and five corresponds to AES-256. In contrast to the performance and overhead measurement studies in Section 4.1, which measurement values vary across the computing platforms/hardware/operating systems (OS), these parameter sizes are given by the design of the ciphers and applicable across computing platforms.
The increased parameter sizes result in increased costs in memory and bandwidth consumption. The key sizes increase from classical to PQC affecting the memory overhead requirements. For example, PQC KEM of Kyber in Table 2 has a longer key length than the classical ciphers, although they stay within an order of magnitude compared to its classical equivalent of RSA and Diffie–Hellman Key Exchange, as their public key lengths range from 256 B to 960 B. The impacts on memory and bandwidth consumption have largely been studied in specific protocol contexts, which research we will later describe in Section 5.
In PQC digital signature cipher algorithms, digital signature sizes from classical ciphers to PQC have grown even more compared to public key. The classical digital signature algorithm (DSA) has a signature size ranging from 40 B to 64 B (or from 320 bits to 512 bits). The signature lengths for PQC, as shown in Table 3, increase by two to three orders of magnitude, except for Falcon 512 supporting security level one which has a signature of 666 B. This is in stark contrast to the classical DSA using the cryptographic hash function of SHA to make the signature length compact, as the digital signature depends on the message payload. When the message payload (the subject of the signing and verification) changes, the signature value changes, and thus the delivery of the message-dependent signatures increase the bandwidth overhead.

4.3. Compatibility and Compliance

To facilitate and enable compatibility, hybrid schemes combine classical/pre-quantum and PQC algorithms and use both of them. Prior research designed such hybrid schemes for KEM [78,79,80] and digital signature [81,82] to provide an intermediate step in the transition to quantum-resistant security, ensuring continued protection against both current and future quantum threats and facilitating backward compatibility with the legacy systems which have yet to deploy PQC. Furthermore, the redundancy of using both classical and PQC provides defense-by-depth, i.e., as long as at least one of the combined algorithms remains secure, the overall system retains its cryptographic strength. Industries beyond academia are also adopting such hybrid schemes, e.g., Microsoft [83], Google [84], and Amazon [85].
To facilitate compliance, research surveying PQC deployment challenges called for software-level enforcement to facilitate and verify PQC practice [86,87]. Existing mechanisms for software in general (beyond PQC) such as remote attestation, software assurance, or software bill of materials (SBOM) can provide the foundational technologies for such software enforcements of PQC. Code attestation provides a technical, cryptographic mechanism to attest the software installment and execution, e.g., [88,89,90,91]. For devices with more limited computing or connectivity resources, distributed software assurance can verify the software installment without attesting the execution, e.g., [92,93]. As a less engineering technical solution, SBOM can facilitate transparency and responsible deployment in the software supply chain [92,94,95].

5. Research on Feasibility in Scalable Network Protocols

While Section 4 surveys the research on the individual algorithms to analyze the PQC ciphers or identify mechanisms and solutions for transitioning to PQC, this section focuses on the research incorporating and integrating the PQC ciphers and relevant solutions to the existing networking protocols and systems. More specifically, this section focuses on the feasibility studies of PQC into networking protocols and systems.
The PQC research presented in this section demonstrates a shared high-level unifying trend across them. They provide the proof-of-concept prototypes including empirical hardware and software implementations to validate the feasibility of PQC transition. The research described in this section aligns with the modularity principle in cybersecurity and software development, enabling the PQC cipher module to replace the classical cipher module with relatively minor changes and updates on the other parts of the system. Given the high-level conclusion corroborated across the research studies, this section focuses on where and how post-quantum cryptography (PQC) can be applied and integrated within each networking protocol and analyzes the relevance of PQC to the corresponding networking systems.
We focus on the scalable and standardized network protocols and systems, as described in Section 1. Table 4 lists the networking protocols, applications, and identifies which PQC functionality is needed (between KEM vs. digital signature) as well as the section in this paper treating the research. These research works incorporate the NIST-standardized ciphers, more specifically, Kyber for KEM and Dilithium, Falcon, and SPHINCS+ for digital signature, described in Section 2.2.

5.1. Public Key Infrastructure

Securing digital networking in scalable networks requires the certification of the public keys to authenticate them, i.e., to securely bind the keys to their owners. The requirement was motivated by a vulnerability discovered at the time of public-key invention [96], as Diffie and Hellman explicitly acknowledged the omission of active spoofing-based adversaries, resulting in man-in-the-middle threat. To address such vulnerability is to use public key infrastructure (PKI) as the networking roots of trust to authenticate the public key via a trusted third party authority called certificate authority (CA). The CA digitally signs the payload including both the entity and its public key, e.g., the server and its public key. The most widely used PKI is the X.509 PKI/certificate framework, which got standardized by NIST [97] as well as global standardization organizations such as International Telecommunication Unit-Telecommunication Standardization Sector (ITU-T) [98] and Internet Engineering Task Force (IETF) [99]. Its applications are pervasive in the web, e.g., TCP/TLS and HTTPS, and beyond for other networking applications. Previous research studied and analyzed the PQC transition for such a X.509 certificate based on digital signatures, e.g., [100,101,102,103,104], and demonstrated the feasibility of post-quantum X.509 certificates by incorporating the NIST PQC ciphers.

5.2. Internet, Web and Server Networking

Public-key cryptography underpins the secure networking in Internet and the World Wide Web. Its transitions to PQC to defend against future quantum adversary have been tested and analyzed in network layer and transport layer building on Transmission Control Protocol (TCP) built on Internet Protocol (IP) or TCP/IP. Widely used to secure web traffic between clients and servers (e.g., HTTPS) is TCP/TLS. PQC has been tested through proof-of-concept prototypes in transport layer security (TLS) during its handshake phase involving digital-signature-based authentication and KEM for symmetric key establishment, e.g., [52,79,100,102,105]. QUIC protocol, designed for faster and more reliable connectivity than the traditional TLS over TCP, integrates UDP and TLS 1.3, including its handshake involving the public-key cryptographic operations of signature-based authentication and KEM; PQC has been tested and the feasibility demonstrated in the TLS 1.3 handshake in QUIC e.g., [106,107,108].
Other networking protocols on the Internet serve specific functionalities. To resolve the domain names and identify the corresponding IP address, Domain Name System SECurity Extensions (DNSSEC) protects the integrity of the domain name records and distributions by digitally signing the DNS payloads of the DNS records (which resolve the IP addresses of the domain names). Previous research builds proof-of-concept PQC implementations for DNSSEC, e.g., [109,110,111,112]. Internet Protocol Security (IPSec) implements a layer of encapsulation to build an authenticated and private tunnel channel, for example, for enterprise network. IPSec uses Internet Key Exchange (IKE) protocol to share the key. Prior research has applied PQC ciphers to IKE. While IKE can optionally include digital signature-based authentication of the peers (using PKI or directly to the peer), which practice is typical in real-world implementations, PQC research focuses on KEM within IKE, e.g., [113,114]. While there are numerous other web protocols, the first waves of PQC integration research focused on these, as they provide the foundations for Internet and web networking. For example, IKE is used less widely than TCP/TLS and DNSSEC and thus has more limited number of PQC research in it.

5.3. Cellular Networks

Cellular networking is standardized by 3rd Generation Partnership Project (3GPP), such as 4G LTE, 5G New Radio, and the previous generations of cellular technologies. The global 3GPP standardization enables interoperability across the mobile network operator and phone vendor companies across nations. 4G and 5G use TCP/TLS (for 5G Service-Based Architecture) and IKE/IPSec (to build a virtual tunnel) on the backend from the base station to the core network for the intra-networking within a mobile network operator. However, this section better distinguishes with Section 5.2 by focusing on the unique aspects of cellular communication which is on the user equipment, e.g., a smartphone. Furthermore, this section focuses on Subscription Concealed Identifier (SUCI) and eSIM provisioning, which precede and enable the 5G authentication and key agreement (AKA).
User privacy to prevent the passive adversary to track the user equipment’s ID and behaviors are critical in cellular networking, as the device tracking can compromise the privacy of the human user. Therefore, 5G uses public-key encryption to encrypt the user equipment’s ID called International Mobile Subscriber Identity (IMSI) to generate Subscription Concealed Identifier (SUCI), while the older 4G does not use such protection but rather relies on temporary IDs. Previous research transitioned such SUCI encryption to PQC KEM, e.g., [115,116,117,118], including the PQC SUCI’s use in 5G authentication and key agreement (AKA) protocol, e.g., [115,116].
In cellular networking, the embedded Subscriber Identity Module (eSIM) enables us to activate a cellular service provision without a physical Subscriber Identity Module (SIM) card. While the traditional SIM card enables hardware-based security, acting like a secure hardware module and pre-including the cellular service provider network’s public key. In contrast, with eSIM, there is no such physical hardware to share the public key and exchange the public keys. Therefore, eSIM uses the X.509 PKI to certify and exchange the public key between the user equipment and the cellular service provider network. While Section 5.1 described the research on PQC incorporation for X.509 PKI, which can be generally applied across applications, other PQC research specifically focused on the eSIM protocol. They utilized the PQC digital signature algorithms and analyzed the overheads of the certificate exchange in time efficiency, packet size, and bandwidth consumption overheads, e.g., [119,120].

6. Solutions to Address Large Parameters

Section 5 presents the research on proof-of-concept transitions to PQC across different networking protocols. This section focuses on the issues and challenges of the protocol transitions and treats the protocols and applications requiring greater technical changes and solution additions. It therefore has a narrower scope (less protocols) than Section 5.
More specifically, a major challenge to PQC from classical pre-quantum ciphers stem from the larger parameter sizes (key sizes and digital signature sizes), which are described in Section 4.2. The larger parameter sizes challenge the PQC transition, as the current protocols targeted and supported the classical ciphers with smaller sizes. While Section 4.2 focuses on the larger parameter size and the resulting increased overheads in processing/memory and bandwidth, this section treats and analyzes the research which propose solutions to integrate PQC ciphers.

6.1. Compression for Lattice-Based Ciphers

PQC research introduced lossy compression and reduced encodings to address PQC’s large parameter sizes in lattice-based ciphers while maintaining the security. Such research has progressed in complementary directions. Previous research identified structural properties to enable compression and proposed algebraic/quantization-based coefficient compression (practical parameter rounding and packing), e.g., [121,122], while the more recent Liu et al. adapted coding to improve packing density or add lightweight error correction so that either more payload fits the same ciphertext length or ciphertexts can be safely compressed further without unacceptable decryption failure rates [123].

6.2. Signature Replacement in TLS

Post-quantum TLS building on the current handshake protocols while replacing the classical ciphers with PQC have been tested in lab or reliable networking environments, as described in Section 5.2. While the existing TLS involves both key exchange and digital signature to achieve key exchange authenticated by digital signature, research proposed replacing the digital signature with key exchange to reduce the packet size and bandwidth, as the PQC signature size is greater than the PQC key exchange size. Schwabe et al. [124] introduced KEMTLS, a TLS handshake variant that authenticates peers using long-term PQC KEM keys rather than signatures. This approach significantly reduces bandwidth and CPU cycles compared to post-quantum-TLS with signatures, and its efficiency can increase even more with pre-distributed public keys [125]. Subsequent work further implemented and validated KEMTLS in real network conditions [126] and in embedded systems [127]. More recently, a similar approach to replace digital signature with KEM has been tested on DNSSEC [128].

6.3. Packet Fragmentation for PQC

Packet fragmentation is an existing technique to fragment the packet into multiple packets when its size becomes too large for delivery. To deliver larger parameters, PQC can cause greater packet fragmentation than the classical, pre-quantum ciphers. Such fragmentation can particularly challenge the stateless networking protocols which do not keep track of packets from the existing session, such as UDP. Previous research identified such a fragmentation challenge due to PQC on DNSSEC [110,111,112], as DNS and DNSSEC build on UDP. To address such fragmentation challenge, one can avoid the stateless protocol of UDP and build on stateful protocols such as TCP. DNS over TCP (DoT) or DNS over HTTPS (DoH) present such options for DNS, which are separate technologies from DNSSEC and cause significantly greater overheads and scalability challenges. Other research provided alternative methods to build on and advance DNSSEC. Goertzen et al. [111] proposed request-based fragmentation which uses an application-layer request to enhanced reliability and efficiency. Raavi et al. [110] incorporated cryptographic commit-and-reveal and blockchain to build dependency across the fragments to defend against the existing security threat against fragmentation [129] based on injections to cause mis-association and error in processing the fragments.

6.4. Offloading Public Keys

A prominent direction to mitigate the communication overhead of PQC in network handshakes is to offload or pre-distribute public keys and other voluminous PQC parameters so that they need not be transmitted on every connection, e.g., [126]. Building on KEMTLS, a TLS 1.3 handshake design that replaces signatures with KEM which we described in Section 6.2, the KEMTLS-PDK variant [125] proposes pre-distributed (cached or out-of-band) public keys that eliminate the need to repeatedly transmit these keys during the handshake, reducing bandwidth and round trips across the PQC ciphers; it even shows that schemes with relatively larger public keys (e.g., Classic McEliece) prohibitive in KEMTLS can become viable with KEMTLS-PDK. In DNSSEC, a different protocol from TLS (targeted by KEMTLS), Raavi et al. [110], uses blockchain to implement such out-of-band channel to offload and pre-distribute public keys to reduce the in-band online DNS resolution communications.

7. Discussions and Future Directions

7.1. More Networking Protocols

The protocols treated in this review paper are not exhaustive of the protocols in such networking environment. Instead, we focus on protocols with substantial PQC-related research, which often correlates with their popularity. We also focus on scalable, standardized networking protocols that extend beyond geographically local boundaries, which are pervasively used. As research in PQC and cryptography continues to grow and new networking protocols and systems emerge, we anticipate future studies evaluating the feasibility and security of PQC in additional networking protocols.
There are networking systems and protocols which are used in the local network with a limited number of routers/hops in between the source and destination nodes. Particularly interesting for PQC are those which are wireless and involve resource-constrained devices for the nodes. Section 3 and Section 4 focusing on the cipher algorithms themselves without the integration to the networking systems can apply to these networking environments, providing a informative baseline for such research. For example, hardware- or software-based accelerations described in Section 4.1 can be adapted to the hardware in mobile networking. While such research exist, this review paper excludes these networking systems and focuses on the scalable networks as described in Section 1.

7.2. Advancing Solutions to Address Large PQC Parameters

The PQC research to accommodate the large parameter sizes of PQC in Section 6 remain in its early stage. Greater R&D is needed to advance these existing research works. Related to Section 6.1 is the exploration of additional compression techniques for lattice-based ciphers as well as the incorporation and analyzing of the integration of the lattice-based PQC ciphers after compression into protocols. Exploring compressions on hash-based PQC ciphers, such as an innovative data structure for verification, also presents a future direction. Section 6.2 describes and analyzes the existing research which replaces the longer PQC digial signature with KEM. Protocol adaptations of such replacement, deviating from the existing pre-quantum protocol’s use of digital signature, for networking applications beyond TCP/TLS and DNSSEC are lacking, as the current research exists on those two protocols. Research in Section 6.3 can advance by updating and adapting the handshake mechanisms to minimize retransmission when packets fragment and by building greater security by considering other threats beyond fragmentation mis-association threat. Related to Section 6.4, which focus on offloading and pre-distributing public keys and other PQC parameters, are future research directions to build the networking architecture to enable and support the offloading of the parameters as well as continued advancements in blockchain and other out-of-band channel design.

7.3. Security Challenges Arising from Incorporation and Integration

Section 3 surveys the current and past research in the security of the PQC cipher algorithms, including side-channel threats which can be caused by implementations. Other security vulnerabilities and issues can emerge from the incorporation and integration of the PQC ciphers into the networking systems, as the network systems as well as the security technologies evolve and change. For example, when adapting the protocols to replace digital signature, resolve fragmentation, or offload public keys and other PQC parameters to address the larger PQC parameter sizes, which research is described in Section 6, there can be misuse of the PQC ciphers or additional side-channel vulnerabilities caused specifically due to the application and integration implementations of the PQC ciphers. Security analyses of the PQC-updated networking protocols and systems can provide impactful research directions to ensure security. For example, symbolic verification tools, such as Tamarin Prover or ProVerif, can be used for formal analyses.

7.4. Networking Applications with Small Devices or Long Operational Lifetime

As reflected in the concept of the Internet of Things (IoT), an increasing number of devices are being interconnected to support a rapidly expanding range of applications. Some of these applications impose more stringent constraints and present one of the most extreme conditions due to their application nature, such as small hardware sizes (e.g., wearable computing), prolonged mission or operational lifetime (e.g., space network and satellite communications), or both (e.g., implantable devices). These constraints can be even greater than some other mobile devices getting connected to cellular networks as a user equipment. Even though there are PQC research works using single-board computers or microcontrollers to simulate resource-constrained devices, described in Section 4.1, modeling these extreme networking applications and analyzing the feasibility of PQC on them in more realistic and application-specific simulations and environments present a future R&D direction.

7.5. Accelerating Deployment and Standardization Updates

PQC transition not only involves engineering/technical research advancements but also the corresponding development, standardization, and actual practice in real-world deployments. To better measure the latter, future research can measure the deployment degree of PQC ciphers in the real-world networking systems and identify the potential application-specific challenges and barriers to PQC deployment. Furthermore, the technical solutions enabling verification of the software compliance described in Section 4.3 or accelerating the PQC performances and reducing their overheads described in Section 4.1 can promote and facilitate the PQC deployment.
Standardization initiatives and updates to incorporate PQC can play major roles with the industry adopting PQC. This is particularly relevant to the protocols emphasized in this review, given our focus on Internet/web and cellular protocols, e.g., in Section 5, which are strongly influenced by standardization bodies to ensure interoperability across vendors and service providers. For example, standardization bodies like Internet Engineering Task Force (IETF) and World Wide Web Consortium (W3C) play major roles for Internet/web protocols and 3rd Generation Partnership Project (3GPP) and International Telecommunication Union (ITU) for cellular systems and protocols, such as 4G and 5G. These standardization communities in the past built on the NIST standardized cryptographic functions, e.g., symmetric ciphers like Advanced Encryption Standard (AES) and Data Encryption Standard (DES) and the cryptographic hash functions like the Secure Hash Algorithm (SHA) families. They will similarly build on the NIST standardizations of the PQC ciphers to secure the future standardized protocols.

8. Conclusions

Digital security and cryptography are rapidly evolving disciplines characterized by continuous innovation. One of the most disruptive recent developments in these fields is the emergence of quantum computing, which has driven the need for quantum-safe and post-quantum cryptography. NIST has been preparing for it since 2016 and published the PQC standardizations in 2024 and 2025 (and plan to finalize another KEM in 2027). Over those years and through four rounds, the ciphers were strengthened through a global effort involving years of study and extensive cryptanalysis. After providing an overview of the NIST standardization and PQC algorithms’ security, this review paper studies the cipher algorithms’ implementations and protocol integrations. This paper analyzes the performances, overheads, and compatibility of the PQC cipher algorithms, including when compared to the pre-quantum classical ciphers we currently use. It surveys the PQC cipher feasibility research focusing on the protocols and systems for scalable networks of Internet/web and cellular/4G/5G. We also review and analyze the research which addresses and resolves the larger parameter sizes of PQC, which is one of the most critical challenges when transitioning to PQC from the current classical ciphers with smaller key and digital signature sizes. Lastly, this paper identifies and highlights impactful future research directions aimed at accelerating PQC integration and enabling quantum-safe, next-generation networking protocols and systems.

Author Contributions

Conceptualization, S.-Y.C. and Q.K.; methodology, S.-Y.C.; software, S.-Y.C.; validation, S.-Y.C. and Q.K.; investigation, S.-Y.C. and Q.K.; resources, S.-Y.C.; data curation, S.-Y.C. and Q.K.; writing—original draft preparation, S.-Y.C. and Q.K.; writing—review and editing, S.-Y.C.; visualization, Q.K.; supervision, S.-Y.C.; project administration, S.-Y.C.; funding acquisition, S.-Y.C. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

No new data were created or analyzed in this study.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Shor, P.W. Algorithms for Quantum Computation: Discrete Logarithms and Factoring. In Proceedings of the 35th Annual Symposium on Foundations of Computer Science (FOCS), Santa Fe, NM, USA, 20–22 November 1994; pp. 124–134. [Google Scholar] [CrossRef] [Scilit]
  2. U.S. Congress. Quantum Computing Cybersecurity Preparedness Act (Public Law 117–260). 117th Congress, 21 December 2022. Available online: https://www.govinfo.gov/app/details/PLAW-117publ260 (accessed on 10 December 2025).
  3. Open Quantum Safe. Liboqs Version 0.15.0 Release. 2025. Available online: https://github.com/open-quantum-safe/liboqs/releases/tag/0.15.0 (accessed on 10 December 2025).
  4. Joseph, D.; Misoczki, R.; Manzano, M.; Tricot, J.; Dominguez Pinuaga, F.; Lacombe, O.; Leichenauer, S.; Hidary, J.; Venables, P.; Hansen, R. Transitioning Organizations to Post-Quantum Cryptography. Nature 2022, 605, 237–243. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  5. Ahmed, N.; Zhang, L.; Gangopadhyay, A. A Survey of Post-Quantum Cryptography Support in Cryptographic Libraries. arXiv 2025, arXiv:2508.16078. [Google Scholar] [CrossRef] [Scilit]
  6. Dam, D.T.; Tran, T.H.; Hoang, V.P.; Pham, C.K.; Hoang, T.T. A Survey of Post-Quantum Cryptography: Start of a New Race. Cryptography 2023, 7, 40. [Google Scholar] [CrossRef] [Scilit]
  7. Singh, M.; Sood, S.K.; Bhatia, M. Post-quantum Cryptography: A Review on Cryptographic Solutions for the Era of Quantum Computing. Arch. Comput. Methods Eng. 2025, 1–42. [Google Scholar] [CrossRef] [Scilit]
  8. de la Puente Secades, F.J.; Esteban-Costales, G.; Campazas-Vega, A.; Álvarez Aparicio, C.; Matellán-Olivera, V.; Guerrero-Higueras, Á.M. Analysis of Post-Quantum Cryptographic Algorithms: A Systematic Literature Review. In Proceedings of the International Joint Conferences (ICEUTE 2024, CISIS 2024), Salamanca, Spain, 8–10 October 2024; Lecture Notes in Networks and Systems; Springer: Cham, Switzerland, 2024; Volume 957, pp. 212–223. [Google Scholar] [CrossRef] [Scilit]
  9. Näther, C.; Herzinger, D.; Gazdag, S.L.; Steghöfer, J.P.; Daum, S.; Loebenberger, D. Migrating Software Systems Toward Post-Quantum Cryptography-A Systematic Literature Review. IEEE Access 2024, 12, 132107–132126. [Google Scholar] [CrossRef] [Scilit]
  10. Lohmiller, N.; Kaniewski, S.; Menth, M.; Heer, T. A Survey of Post-Quantum Cryptography Migration in Vehicles. IEEE Access 2025, 13, 10160–10176. [Google Scholar] [CrossRef] [Scilit]
  11. Shor, P.W. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM Rev. 1999, 41, 303–332. [Google Scholar] [CrossRef] [Scilit]
  12. Vandersypen, L.M.K.; Steffen, M.; Breyta, G.; Yannoni, C.S.; Sherwood, M.H.; Chuang, I.L. Experimental realization of Shor’s quantum factoring algorithm using nuclear magnetic resonance. Nature 2001, 414, 883–887. [Google Scholar] [CrossRef] [Scilit]
  13. D-Wave Quantum Inc. Performance Gains in the D-Wave Advantage2 System at the 4400-Qubit Scale. 2025. Available online: https://www.dwavequantum.com/media/wakjcpsf/adv2_4400q_whitepaper-1.pdf (accessed on 23 November 2025).
  14. IBM Quantum. IBM Quantum Roadmap Through 2033: Advancing Toward Quantum-Centric Supercomputing. 2023. Available online: https://www.ibm.com/quantum/blog/quantum-roadmap-2033 (accessed on 23 November 2025).
  15. IBM Quantum. Qiskit. 2025. Available online: https://www.ibm.com/quantum/qiskit (accessed on 15 February 2025).
  16. Javadi-Abhari, A.; Treinish, M.; Krsulich, K.; Wood, C.J.; Lishman, J.; Gacon, J.; Martiel, S.; Nation, P.D.; Bishop, L.S.; Cross, A.W.; et al. Quantum Computing with Qiskit. arXiv 2024, arXiv:2405.08810. [Google Scholar] [CrossRef] [Scilit]
  17. National Institute of Standards and Technology (NIST). Post-Quantum Cryptography Standardization Process: Call for Proposals. 2016. Available online: https://csrc.nist.gov/csrc/media/projects/post-quantum-cryptography/documents/call-for-proposals-final-dec-2016.pdf (accessed on 22 January 2026).
  18. Barker, E.; Chen, L.; Keller, S.; Roginsky, A.; Vassilev, A.; Davis, R. Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography; Technical Report; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2017.
  19. National Institute of Standards and Technology. Digital Signature Standard (DSS); Technical Report FIPS PUB 186-4; U.S. Department of Commerce: Gaithersburg, MD, USA, 2013. Available online: https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.186-4.pdf (accessed on 12 December 2025).
  20. Alagic, G.; Alperin-Sheriff, J.; Apon, D.; Cooper, D.; Dang, Q.; Kelsey, J.; Liu, Y.K.; Miller, C.; Moody, D.; Peralta, R.; et al. Status Report on the Second Round of the NIST Post-Quantum Cryptography Standardization Process; US Department of Commerce, NIST: Gaithersburg, MD, USA, 2020; Volume 2, p. 69.
  21. Beullens, W. Breaking rainbow takes a weekend on a laptop. In Proceedings of the Annual International Cryptology Conference, Santa Barbara, CA, USA, 15–18 August 2022; Springer: Cham, Switzerland, 2022; pp. 464–479. [Google Scholar]
  22. Castryck, W.; Decru, T. An efficient key recovery attack on SIDH. In Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, France, 23–27 April 2023; Springer: Cham, Switzerland, 2023; pp. 423–447. [Google Scholar]
  23. NIST. Online PQC Conference. 2022. Available online: https://www.nist.gov/news-events/events/2022/11/fourth-pqc-standardization-conference (accessed on 23 November 2025).
  24. Alagic, G.; Bros, M.; Ciadoux, P.; Cooper, D.; Dang, Q.; Dang, T.; Kelsey, J.; Lichtinger, J.; Liu, Y.-K.; Miller, C.; et al. Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process. NIST Interagency/Internal Report (IR 8545). March 2025. Available online: https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf (accessed on 24 November 2025).
  25. Gama, N.; Nguyen, P.Q. Predicting Lattice Reduction. In Advances in Cryptology–EUROCRYPT 2008, Istanbul, Turkey, 13–17 April 2008; Lecture Notes in Computer Science; Smart, N.P., Ed.; Springer: Berlin/Heidelberg, Germany, 2008; Volume 4965, pp. 31–51. [Google Scholar] [CrossRef] [Scilit]
  26. Albrecht, M.R.; Player, R.; Scott, S. On the Concrete Hardness of Learning with Errors. Cryptology ePrint Archive, Report 2015/046. 2015. Available online: https://eprint.iacr.org/2015/046.pdf (accessed on 28 November 2025).
  27. Langlois, A.; Stehlé, D. Worst-case to average-case reductions for module lattices. Des. Codes Cryptogr. 2015, 75, 565–599. [Google Scholar] [CrossRef] [Scilit]
  28. D’Anvers, J.P.; Karmakar, A.; Sinha Roy, S.; Vercauteren, F. Saber: Module-LWR based key exchange, CPA-secure encryption and CCA-secure KEM. In Progress in Cryptology–AFRICACRYPT 2018, Marrakesh, Morocco, 7–9 May 2018; Lecture Notes in Computer Science; Joux, A., Nitaj, A., Rachidi, T., Eds.; Springer: Cham, Switzerland, 2018; Volume 10831, pp. 282–305. [Google Scholar] [CrossRef] [Scilit]
  29. Peikert, C. A Decade of Lattice Cryptography. Found. Trends® Theor. Comput. Sci. 2016, 10, 283–424. [Google Scholar] [CrossRef] [Scilit]
  30. Albrecht, M.R. On dual lattice attacks against small-secret LWE and parameter choices in HElib and SEAL. In Advances in Cryptology–EUROCRYPT 2017, Paris, France, 30 April– 4 May 2017; Lecture Notes in Computer Science; Coron, J.-S., Nielsen, J.B., Eds.; Springer: Cham, Switzerland, 2017; Volume 10211, pp. 103–129. [Google Scholar] [CrossRef] [Scilit]
  31. Tao, C.; Petzoldt, A.; Ding, J. Efficient key recovery for all HFE signature variants. In Advances in Cryptology–CRYPTO 2021, Virtual Event, 16–20 August 2021; Lecture Notes in Computer Science; Malkin, T., Peikert, C., Eds.; Springer: Cham, Switzerland, 2021; Volume 12825, pp. 70–93. [Google Scholar] [CrossRef] [Scilit]
  32. Banik, S.; Barooti, K.; Durak, F.B.; Vaudenay, S. Cryptanalysis of LowMC instances using single plaintext/ciphertext pair. IACR Trans. Symmetric Cryptol. 2020, 2020, 130–146. [Google Scholar] [CrossRef] [Scilit]
  33. Kocher, P.C.; Jaffe, J.M.; Jun, B. Differential power analysis. In Advances in Cryptology–CRYPTO 1999, Santa Barbara, CA, USA, 15–19 August 1999; Lecture Notes in Computer Science; Wiener, M., Ed.; Springer: Berlin/Heidelberg, Germany, 1999; Volume 1666, pp. 388–397. [Google Scholar] [CrossRef] [Scilit]
  34. Chari, S.; Rao, J.; Rohatgi, P. Template attacks. In Cryptographic Hardware and Embedded Systems–CHES 2002, San Francisco Bay, CA, USA, 13–15 August 2002; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2003; Volume 2523, pp. 13–28. [Google Scholar] [CrossRef] [Scilit]
  35. Maghrebi, H.; Portigliatti, T.; Prouff, E. Breaking Cryptographic Implementations Using Deep Learning Techniques. In Security, Privacy, and Applied Cryptography Engineering; Lecture Notes in Computer Science; Cadet, C., Hasan, M.A., Saraswat, V., Eds.; Springer: Cham, Switzerland, 2016; Volume 10076, pp. 3–26. [Google Scholar] [CrossRef] [Scilit]
  36. Karlov, A.; Linard de Guertechin, N. Power Analysis Attack on Kyber. Cryptology ePrint Archive, Report 2021/1311. 2021. Available online: https://eprint.iacr.org/2021/1311 (accessed on 14 December 2025).
  37. Mujdei, C.; Wouters, L.; Karmakar, A.; Beckers, A.; Bermudo Mera, J.M.; Verbauwhede, I. Side-channel analysis of lattice-based post-quantum cryptography: Exploiting polynomial multiplication. ACM Trans. Embed. Comput. Syst. 2024, 23, 27. [Google Scholar] [CrossRef] [Scilit]
  38. Zhao, Y.; Pan, S.; Ma, H.; Gao, Y.; Song, X.; He, J.; Jin, Y. Side channel security oriented evaluation and protection on hardware implementations of Kyber. IEEE Trans. Circuits Syst. I Regul. Pap. 2023, 70, 5025–5035. [Google Scholar] [CrossRef] [Scilit]
  39. Fujisaki, E.; Okamoto, T. Secure integration of asymmetric and symmetric encryption schemes. In Advances in Cryptology–CRYPTO ’99, Santa Barbara, CA, USA, 15–19 August 1999; Lecture Notes in Computer Science; Wiener, M., Ed.; Springer: Berlin/Heidelberg, Germany, 1999; Volume 1666, pp. 537–554. [Google Scholar] [CrossRef] [Scilit]
  40. Guo, Q.; Johansson, T.; Nilsson, A. A key-recovery timing attack on post-quantum primitives using the Fujisaki-Okamoto transformation and its application on FrodoKEM. In Advances in Cryptology–CRYPTO 2020, Online, 17–21 August 2020; Springer: Berlin/Heidelberg, Germany, 2020; Volume 12171, pp. 359–386. [Google Scholar] [CrossRef] [Scilit]
  41. Ravi, P.; Sinha Roy, S.; Chattopadhyay, A.; Bhasin, S. Generic side-channel attacks on CCA-secure lattice-based PKE and KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2020, 307–335. [Google Scholar] [CrossRef] [Scilit]
  42. Ueno, R.; Xagawa, K.; Tanaka, Y.; Ito, A.; Takahashi, J.; Homma, N. Curse of re-encryption: A generic power/EM analysis on post-quantum KEMs. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2022, 296–322. [Google Scholar] [CrossRef] [Scilit]
  43. Primas, R.; Peßl, P.; Mangard, S. Single-Trace Side-Channel Attacks on Masked Lattice-Based Encryption. In Cryptographic Hardware and Embedded Systems–CHES 2017, Taipei, Taiwan, 25–28 September 2017; Lecture Notes in Computer Science; Fischer, W., Homma, N., Eds.; Springer: Cham, Switzerland, 2017; Volume 10529, pp. 513–533. [Google Scholar] [CrossRef] [Scilit]
  44. Peßl, P.; Primas, R. More practical single-trace attacks on the Number Theoretic Transform. In Progress in Cryptology–LATINCRYPT 2019, Santiago, Chile, 2–4 October 2019; Lecture Notes in Computer Science; Schwabe, P., Thériault, N., Eds.; Springer: Cham, Switzerland, 2019; Volume 11774, pp. 130–149. [Google Scholar] [CrossRef] [Scilit]
  45. Chen, Z.; Karabulut, E.; Aysu, A.; Ma, Y.; Jing, J. An efficient non-profiled side-channel attack on the CRYSTALS-Dilithium post-quantum signature. In Proceedings of the IEEE 39th International Conference on Computer Design (ICCD), Storrs, CT, USA, 24–27 October 2021; pp. 583–590. [Google Scholar] [CrossRef] [Scilit]
  46. Kim, I.; Lee, T.; Han, J.; Sim, B.-Y.; Han, D.G. Novel Single-Trace ML Profiling Attacks on NIST 3 Round Candidate Dilithium. Cryptology ePrint Archive, Paper 2020/1383. 2020. Available online: https://eprint.iacr.org/2020/1383 (accessed on 10 December 2025).
  47. Wang, H.; Gao, Y.; Liu, Y.; Zhang, Q.; Zhou, Y. In-depth correlation power analysis attacks on a hardware implementation of CRYSTALS-Dilithium. Cybersecurity 2024, 7, 21. [Google Scholar] [CrossRef] [Scilit]
  48. Dachman-Soled, D.; Ducas, L.; Gong, H.; Rossi, M. LWE with side information: Attacks and concrete security estimation. In Advances in Cryptology–CRYPTO 2020, Online, 17–21 August 2020; Lecture Notes in Computer Science; Micciancio, D., Ristenpart, T., Eds.; Springer: Cham, Switzerland, 2020; Volume 12171, pp. 329–358. [Google Scholar] [CrossRef] [Scilit]
  49. Ravi, P.; Jhanwar, M.P.; Howe, J.; Chattopadhyay, A.; Bhasin, S. Exploiting determinism in lattice-based signatures. In Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security (ASIACCS), Auckland, New Zealand, 9–12 July 2019. [Google Scholar] [CrossRef] [Scilit]
  50. Kannwischer, M.J.; Biryukov, A.; Pieniak, L.P.Y. Differential power analysis of XMSS and SPHINCS. In Constructive Side-Channel Analysis and Secure Design–9th International Workshop, COSADE 2018, Singapore, 23–24 April 2018; Lecture Notes in Computer Science; Fan, J., Gierlichs, B., Eds.; Springer: Cham, Switzerland, 2018; Volume 11002, pp. 159–178. [Google Scholar] [CrossRef] [Scilit]
  51. Basu, K.; Soni, D.; Nabeel, M.; Karri, R. NIST Post-Quantum Cryptography—A Hardware Evaluation Study. Cryptology ePrint Archive, Paper 2019/047. 2019. Available online: https://eprint.iacr.org/2019/047 (accessed on 10 December 2025).
  52. Raavi, M.; Wuthier, S.; Chandramouli, P.; Balytskyi, Y.; Zhou, X.; Chang, S.-Y. Security comparisons and performance analyses of post-quantum signature algorithms. In Applied Cryptography and Network Security–ACNS 2021, Kamakura, Kanagawa, Japan, 21–24 June 2021; Lecture Notes in Computer Science; Sako, K., Tippenhauer, N.O., Eds.; Springer: Cham, Switzerland, 2021; Volume 12727, pp. 424–447. [Google Scholar] [CrossRef] [Scilit]
  53. Raavi, M.; Khan, Q.; Wuthier, S.; Chandramouli, P.; Balytskyi, Y.; Chang, S.-Y. Security and performance analyses of post-quantum digital signature algorithms and their TLS and PKI integrations. Cryptography 2025, 9, 38. [Google Scholar] [CrossRef] [Scilit]
  54. Hines, K.; Raavi, M.; Villeneuve, J.-M.; Wuthier, S.; Moreno-Colin, J.; Bai, Y. Post-Quantum cipher power analysis in lightweight devices. In Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WISEC ’22), San Antonio, TX, USA, 16–19 May 2022; ACM Press: New York, NY, USA, 2022; pp. 282–284. [Google Scholar] [CrossRef] [Scilit]
  55. Al-Shareeda, M.A.; Ghadban, A.A.H.; Glass, A.A.H.; Hadi, E.M.A.; Almaiah, M.A. Efficient implementation of post-quantum digital signatures on Raspberry Pi. Discov. Appl. Sci. 2025, 7, 597. [Google Scholar] [CrossRef] [Scilit]
  56. Halak, B.; Gibson, T.; Henley, M.; Botea, C.B.; Heath, B.; Khan, S. Evaluation of Performance, Energy, and Computation Costs of Quantum-Attack Resilient Encryption Algorithms for Embedded Devices. IEEE Access 2024, 12, 8791–8805. [Google Scholar] [CrossRef] [Scilit]
  57. Howe, J.; Westerbaan, B. Benchmarking and Analysing the NIST PQC Lattice-Based Signature Schemes Standards on the ARM Cortex M7. In Proceedings of the Progress in Cryptology-AFRICACRYPT 2023, Sousse, Tunisia, 19–21 July 2023; El Mrabet, N., De Feo, L., Duquesne, S., Eds.; Springer: Cham, Switzerland, 2023; pp. 442–462. [Google Scholar]
  58. Kannwischer, M.J.; Rijneveld, J.; Schwabe, P.; Stoffelen, K. pqm4: Testing and Benchmarking NIST PQC on ARM Cortex-M4. 2019. Available online: https://repository.ubn.ru.nl/bitstream/handle/2066/210214/210214.pdf (accessed on 10 December 2025).
  59. Choi, J.; Yoon, S.; Seo, S.C. Optimized Falcon Verify on Cortex-M4 for Post-Quantum secure UAV communications. ICT Express 2025, 11, 281–286. [Google Scholar] [CrossRef] [Scilit]
  60. Xing, Y.; Li, S. A Compact Hardware Implementation of CCA-Secure Key Exchange Mechanism CRYSTALS-KYBER on FPGA. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2021, 2021, 328–356. [Google Scholar] [CrossRef] [Scilit]
  61. Yaman, F.; Mert, A.C.; Öztürk, E.; Savaş, E. A Hardware Accelerator for Polynomial Multiplication Operation of CRYSTALS-KYBER PQC Scheme. In Proceedings of the 2021 Design, Automation & Test in Europe Conference & Exhibition (DATE), Grenoble, France, 1–5 February 2021; pp. 1020–1025. [Google Scholar] [CrossRef] [Scilit]
  62. Bisheh-Niasar, M.; Azarderakhsh, R.; Mozaffari-Kermani, M. A monolithic hardware implementation of Kyber: Comparing apples to apples in PQC candidates. In Proceedings of the International Conference on Cryptology and Information Security in Latin America, Bogotá, Colombia, 6–8 October 2021; Springer: Cham, Switzerland, 2021; pp. 108–126. [Google Scholar]
  63. Aikata, A.; Mert, A.C.; Imran, M.; Pagliarini, S.; Roy, S.S. KaLi: A Crystal for Post-Quantum Security Using Kyber and Dilithium. IEEE Trans. Circuits Syst. I Regul. Pap. 2023, 70, 747–758. [Google Scholar] [CrossRef] [Scilit]
  64. Beckwith, L.; Nguyen, D.T.; Gaj, K. Hardware Accelerators for Digital Signature Algorithms Dilithium and FALCON. IEEE Des. Test 2024, 41, 27–35. [Google Scholar] [CrossRef] [Scilit]
  65. Matteo, S.D.; Sarno, I.; Saponara, S. CRYPHTOR: A Memory-Unified NTT-Based Hardware Accelerator for Post-Quantum CRYSTALS Algorithms. IEEE Access 2024, 12, 25501–25511. [Google Scholar] [CrossRef] [Scilit]
  66. Beckwith, L.; Nguyen, D.T.; Gaj, K. High-Performance Hardware Implementation of CRYSTALS-Dilithium. In Proceedings of the 2021 International Conference on Field-Programmable Technology (ICFPT), Auckland, New Zealand, 6–10 December 2021; pp. 1–10. [Google Scholar] [CrossRef] [Scilit]
  67. Land, G.; Sasdrich, P.; Güneysu, T. A Hard Crystal—Implementing Dilithium on Reconfigurable Hardware. In Proceedings of the Smart Card Research and Advanced Applications, Birmingham, UK, 7–9 November 2022; Grosso, V., Pöppelmann, T., Eds.; Springer: Cham, Switzerland, 2022; pp. 210–230. [Google Scholar] [CrossRef] [Scilit]
  68. Wu, Z.; Chen, R.; Wang, Y.; Wang, Q.; Peng, W. An Efficient Hardware Implementation of Crystal-Dilithium on FPGA. In Proceedings of the Information Security and Privacy, Sydney, NSW, Australia, 15–17 July 2024; Zhu, T., Li, Y., Eds.; Springer: Singapore, 2024; pp. 64–83. [Google Scholar] [CrossRef] [Scilit]
  69. Lee, Y.; Youn, J.; Nam, K.; Jung, H.H.; Cho, M.; Na, J.; Park, J.Y.; Jeon, S.; Kang, B.G.; Oh, H.; et al. An Efficient Hardware/Software Co-Design for FALCON on Low-End Embedded Systems. IEEE Access 2024, 12, 57947–57958. [Google Scholar] [CrossRef] [Scilit]
  70. Schmid, M.; Amiet, D.; Wendler, J.; Zbinden, P.; Wei, T. Falcon Takes Off—A Hardware Implementation of the Falcon Signature Scheme. Publication Info: Preprint. 2023. Available online: https://eprint.iacr.org/2023/1885.pdf (accessed on 21 October 2025).
  71. Alsuhli, G.; Saleh, H.; Al-Qutayri, M.; Mohammad, B.; Stouraitis, T. Area and Power Efficient FFT/IFFT Processor for FALCON Post-Quantum Cryptography. IEEE Trans. Emerg. Top. Comput. 2024, 13, 423–437. [Google Scholar] [CrossRef] [Scilit]
  72. Ouyang, Y.; Zhu, Y.; Zhu, W.; Yang, B.; Zhang, Z.; Wang, H.; Tao, Q.; Zhu, M.; Wei, S.; Liu, L. FalconSign: An Efficient and High-Throughput Hardware Architecture for Falcon Signature Generation. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2025, 2025, 203–226. [Google Scholar] [CrossRef] [Scilit]
  73. Dai, Y.; Song, Y.; Tian, J.; Wang, Z. High-Throughput Hardware Implementation for Haraka in SPHINCS+. In Proceedings of the 2023 24th International Symposium on Quality Electronic Design (ISQED), San Francisco, CA, USA, 5–7 April 2023; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
  74. Karl, P.; Schupp, J.; Sigl, G. The Impact of Hash Primitives and Communication Overhead for Hardware-Accelerated SPHINCS+. In Proceedings of the Constructive Side-Channel Analysis and Secure Design, Gardanne, France, 9–10 April 2024; Wacquez, R., Homma, N., Eds.; Springer: Cham, Switzerland, 2024; pp. 221–239. [Google Scholar] [CrossRef] [Scilit]
  75. Amiet, D.; Leuenberger, L.; Curiger, A.; Zbinden, P. FPGA-based SPHINCS+ Implementations: Mind the Glitch. In Proceedings of the 2020 23rd Euromicro Conference on Digital System Design (DSD), Kranj, Slovenia, 26–28 August 2020; pp. 229–237. [Google Scholar] [CrossRef] [Scilit]
  76. Berthet, Q.; Upegui, A.; Gantel, L.; Duc, A.; Traverso, G. An Area-Efficient SPHINCS+ Post-Quantum Signature Coprocessor. In Proceedings of the 2021 IEEE International Parallel and Distributed Processing Symposium Workshops (IPDPSW), Portland, OR, USA, 17–21 June 2021; pp. 180–187. [Google Scholar] [CrossRef] [Scilit]
  77. Lopez-Valdivieso, J.; Cumplido, R. Design and Implementation of Hardware-Software Architecture Based on Hashes for SPHINCS+. ACM Trans. Reconfigurable Technol. Syst. 2024, 17, 54. [Google Scholar] [CrossRef] [Scilit]
  78. Giron, A.A.; Custódio, R.; Rodríguez-Henríquez, F. Post-quantum hybrid key exchange: A systematic mapping study. J. Cryptogr. Eng. 2023, 13, 71–88. [Google Scholar] [CrossRef] [Scilit]
  79. Crockett, E.; Paquin, C.; Stebila, D. Prototyping post-quantum and hybrid key exchange and authentication in TLS and SSH. In Proceedings of the Second NIST PQC Standardization Conference, Santa Barbara, CA, USA, 22–24 August 2019. [Google Scholar]
  80. Bindel, N.; Brendel, J.; Fischlin, M.; Goncalves, B.; Stebila, D. Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange. In Proceedings of the Post-Quantum Cryptography (PQCrypto 2019), Chongqing, China, 8–10 May 2019; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2019; Volume 11505, pp. 206–226. [Google Scholar] [CrossRef] [Scilit]
  81. Ghinea, D.; Kaczmarczyck, F.; Pullman, J.; Cretin, J.; Kölbl, S.; Misoczki, R.; Picod, J.M.; Invernizzi, L.; Bursztein, E. Hybrid Post-quantum Signatures in Hardware Security Keys. In Proceedings of the Applied Cryptography and Network Security Workshops (ACNS 2023), Kyoto, Japan, 19–22 June 2023; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2023; Volume 13907, pp. 480–499. [Google Scholar] [CrossRef] [Scilit]
  82. Devevey, J.; Guerreau, M.; Roméas, M. Compact, Efficient and Non-Separable Hybrid Signatures. Cryptology ePrint Archive, Paper 2025/2059. 2025. Available online: https://eprint.iacr.org/2025/2059.pdf (accessed on 13 November 2025).
  83. Microsoft. Post-Quantum Cryptography APIs Now Generally Available on Microsoft Platforms. Available online: https://techcommunity.microsoft.com/blog/microsoft-security-blog/post-quantum-cryptography-apis-now-generally-available-on-microsoft-platforms/4469093 (accessed on 22 January 2026).
  84. Google Cloud. Announcing Quantum-Safe Key Encapsulation Mechanisms in Cloud KMS. Available online: https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-key-encapsulation-mechanisms-in-cloud-kms (accessed on 22 January 2026).
  85. Amazon Web Services. ML-KEM Post-Quantum TLS Now Supported in AWS KMS, ACM, and Secrets Manager. Available online: https://aws.amazon.com/blogs/security/ml-kem-post-quantum-tls-now-supported-in-aws-kms-acm-and-secrets-manager/ (accessed on 22 January 2026).
  86. Chen, L. Standardisation of and Migration to Post-Quantum Cryptography. In Proceedings of the Security Standardisation Research (SSR 2024), Kunming, China, 16 December 2024; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2025; Volume 15559, pp. 3–13. [Google Scholar] [CrossRef] [Scilit]
  87. Pereira, S.A.; Fernandes, M.M.; Anita, E.A.M.; Grobova, T. Post-quantum Cryptography in Practice: A Survey of Algorithms, Applications, and Deployment Challenges. In Proceedings of the International Workshop on Advanced Information Security Management and Applications (AISMA 2025), Stavropol, Russia, 15–19 May 2025; Lecture Notes in Networks and Systems; Springer: Cham, Switzerland, 2025; Volume 1456, pp. 362–369. [Google Scholar] [CrossRef] [Scilit]
  88. Armknecht, F.; Sadeghi, A.R.; Schulz, S.; Wachsmann, C. A Security Framework for the Analysis and Design of Software Attestation. In Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communications Security, Berlin, Germany, 4–8 November 2013; Association for Computing Machinery: New York, NY, USA, 2013; pp. 1–12. [Google Scholar] [CrossRef] [Scilit]
  89. Castelluccia, C.; Francillon, A.; Perito, D.; Soriente, C. On the Difficulty of Software-Based Attestation of Embedded Devices. In Proceedings of the 16th ACM Conference on Computer and Communications Security, Chicago IL, USA, 9–13 November 2009; Association for Computing Machinery: New York, NY, USA, 2009; pp. 400–409. [Google Scholar] [CrossRef] [Scilit]
  90. Seshadri, A.; Luk, M.; Perrig, A.; van Doorn, L.; Khosla, P. SCUBA: Secure Code Update By Attestation in sensor networks. In Proceedings of the 5th ACM Workshop on Wireless Security, Los Angeles CA, 29 September 2006; Association for Computing Machinery: New York, NY, USA, 2006; pp. 85–94. [Google Scholar] [CrossRef] [Scilit]
  91. Shi, E.; Perrig, A.; Van Doorn, L. BIND: A fine-grained attestation service for secure distributed systems. In Proceedings of the 2005 IEEE Symposium on Security and Privacy (S&P’05), Oakland, CA, USA, 8–11 May 2005; pp. 154–168. [Google Scholar] [CrossRef] [Scilit]
  92. Lew, K.; Sarker, A.; Wuthier, S.; Kim, J.; Kim, J.; Chang, S.Y. Distributed Software Build Assurance for Software Supply Chain Integrity. Appl. Sci. 2024, 14, 9262. [Google Scholar] [CrossRef] [Scilit]
  93. Sarker, A.; Wuthier, S.; Kim, J.; Kim, J.; Chang, S.Y. Version++ Protocol Demonstration for Cryptocurrency Blockchain Handshaking with Software Assurance. In Proceedings of the 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA, 8–11 January 2023; IEEE: Piscataway, NJ, USA, 2023; pp. 915–916. [Google Scholar]
  94. Yu, S.; Song, W.; Hu, X.; Yin, H. On the Correctness of Metadata-Based SBOM Generation: A Differential Analysis Approach. In Proceedings of the 2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), Brisbane, Australia, 24–27 June 2024; pp. 29–36. [Google Scholar] [CrossRef] [Scilit]
  95. Mirakhorli, M.; Garcia, D.; Dillon, S.; Laporte, K.; Morrison, M.; Lu, H.; Koscinski, V.; Enoch, C. A Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM). arXiv 2024, arXiv:2402.11151. [Google Scholar] [CrossRef] [Scilit]
  96. Diffie, W.; Hellman, M.E. New Directions in Cryptography. IEEE Trans. Inf. Theory 1976, 22, 644–654. [Google Scholar] [CrossRef] [Scilit]
  97. Grassi, P.A.; Garcia, M.E.; Fenton, J.L. Digital Identity Guidelines; Technical Report 800-63-3; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2017. [CrossRef] [Scilit]
  98. ITU-T. Recommendation X.509: Information Technology—Open Systems Interconnection—The Directory: Public-Key and Attribute Certificate Frameworks. 2019. Available online: https://www.itu.int/rec/t-rec-x.509 (accessed on 30 November 2025).
  99. Cooper, D.; Santesson, S.; Farrell, S.; Boeyen, S.; Housley, R.; Polk, T. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. RFC 5280. 2008. Available online: https://doi.org/10.17487/RFC5280 (accessed on 20 December 2025).
  100. Sikeridis, D.; Kampanakis, P.; Devetsikiotis, M. Post-Quantum Authentication in TLS 1.3: A Performance Study. In Proceedings of the Network and Distributed Systems Security (NDSS) Symposium, San Diego, CA, USA, 23–26 February 2020. [Google Scholar]
  101. Kampanakis, P.; Panburana, P.; Daw, E.; Van Geest, D. The Viability of Post-Quantum X. 509 Certificates. Cryptology ePrint Archive. 2018. Available online: https://eprint.iacr.org/2018/063.pdf (accessed on 20 December 2025).
  102. Raavi, M.; Chandramouli, P.; Wuthier, S.; Zhou, X.; Chang, S.Y. Performance characterization of post-quantum digital certificates. In Proceedings of the 2021 International Conference on Computer Communications and Networks (ICCCN), Athens, Greece, 19–22 July 2021; IEEE: Piscataway, NJ, USA, 2021; pp. 1–9. [Google Scholar]
  103. Chen, A.C. Post-Quantum Cryptography X. 509 Certificate. In Proceedings of the 2024 International Conference on Smart Systems for applications in Electrical Sciences (ICSSES), Tumakuru, India, 3–4 May 2024; IEEE: Piscataway, NJ, USA, 2024; pp. 1–6. [Google Scholar]
  104. D’Onghia, G.; Berbecaru, D.G.; Lioy, A. Shaping a Quantum-Resistant Future: Strategies for Post-Quantum PKI. In Proceedings of the 2024 IEEE Symposium on Computers and Communications (ISCC), Paris, France, 26–29 June 2024; IEEE: Piscataway, NJ, USA, 2024; pp. 1–6. [Google Scholar]
  105. Bürstinghaus-Steinbach, K.; Krauß, C.; Niederhagen, R.; Schneider, M. Post-Quantum TLS on Embedded Systems: Integrating and Evaluating Kyber and SPHINCS+ with mbed TLS. In ASIA CCS ’20: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, Taipei, Taiwan, 5–9 October 2020; Association for Computing Machinery: New York, NY, USA, 2020; pp. 841–852. [Google Scholar] [CrossRef] [Scilit]
  106. Raavi, M.; Wuthier, S.; Chandramouli, P.; Zhou, X.; Chang, S.Y. QUIC Protocol with Post-quantum Authentication. In Proceedings of the Information Security, Belgrade, Serbia, 2 December 2022; Springer: Cham, Switzerland, 2022; pp. 84–91. [Google Scholar]
  107. Kempf, M.; Gauder, N.; Jaeger, B.; Zirngibl, J.; Carle, G. A Quantum of QUIC: Dissecting Cryptography with Post-Quantum Insights. In Proceedings of the 2024 IFIP Networking Conference (IFIP Networking), Thessaloniki, Greece, 3–6 June 2024; pp. 195–203. [Google Scholar] [CrossRef] [Scilit]
  108. Raavi, M.; Wuthier, S.; Zhou, X.; Chang, S.Y. Post-Quantum QUIC Protocol in Cloud Networking. In Proceedings of the 2023 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), Gothenburg, Sweden, 6–9 June 2023; IEEE: Piscataway, NJ, USA, 2023; pp. 573–578. [Google Scholar]
  109. Müller, M.; de Jong, J.; van Heesch, M.; Overeinder, B.; van Rijswijk-Deij, R. Retrofitting post-quantum cryptography in internet protocols: A case study of DNSSEC. SIGCOMM Comput. Commun. Rev. 2020, 50, 49–57. [Google Scholar] [CrossRef] [Scilit]
  110. Raavi, M.; Wuthier, S.; Chang, S. Securing Post-Quantum DNSSEC Against Fragmentation Mis-Association Threat. In Proceedings of the ICC 2024-IEEE International Conference on Communications, Denver, CO, USA, 9–13 June 2024; pp. 97–102. [Google Scholar] [CrossRef] [Scilit]
  111. Goertzen, J.; Stebila, D. Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation. In Proceedings of the Post-Quantum Cryptography, College Park, MD, USA, 16–18 August 2023; Johansson, T., Smith-Tone, D., Eds.; Springer: Cham, Switzerland, 2023; pp. 535–564. [Google Scholar]
  112. Lee, J.; Hoque, S.; Aydeger, A.; Zeydan, E. Quantum-Resistant Domain Name System: A Comprehensive System-Level Study. arXiv 2025, arXiv:2506.19943. [Google Scholar]
  113. Pazienza, A.; Lella, E.; Noviello, P.; Vitulano, F. Analysis of Network-level Key Exchange Protocols in the Post-Quantum Era. In Proceedings of the 2022 IEEE 15th Workshop on Low Temperature Electronics (WOLTE), Matera, Italy, 6–9 June 2022; pp. 1–4. [Google Scholar] [CrossRef] [Scilit]
  114. Herzinger, D.; Gazdag, S.L.; Loebenberger, D. Real-World Quantum-Resistant IPsec. In Proceedings of the 2021 14th International Conference on Security of Information and Networks (SIN), Edinburgh, UK, 15–17 December 2021; Volume 1, pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
  115. Damir, M.T.; Meskanen, T.; Ramezanian, S.; Niemi, V. A beyond-5g authentication and key agreement protocol. In Proceedings of the International Conference on Network and System Security, Denarau Island, Fiji, 9–12 December 2022; Springer: Cham, Switzerland, 2022; pp. 249–264. [Google Scholar]
  116. Ulitzsch, V.Q.; Park, S.; Marzougui, S.; Seifert, J.P. A post-quantum secure subscription concealed identifier for 6g. In Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, San Antonio, TX, USA, 16–19 May 2022; pp. 157–168. [Google Scholar]
  117. Khan, Q.; Chang, S.Y. Post-Quantum Key Exchange and ID Encryption Analyses for 5G Mobile Networking. In Proceedings of the NOMS 2025-2025 IEEE Network Operations and Management Symposium, Honolulu, HI, USA, 12–16 May 2025; IEEE: Piscataway, NJ, USA, 2025; pp. 1–9. [Google Scholar]
  118. Khan, Q.; Chang, S.Y. Post-Quantum Key Exchange and Subscriber Identity Encryption in 5G Using ML-KEM (Kyber)†. Information 2025, 16, 617. [Google Scholar] [CrossRef] [Scilit]
  119. Khan, Q.; Purification, S.; Cheruiyot, R.; Kim, J.; Kim, I.; Chang, S.Y. Post-Quantum Digital Signature and Authentication for eSIM in 5G Mobile Networking. In Proceedings of the IEEE Silicon Valley Cybersecurity Conference (SVCC), San Francisco, CA, USA, 23–25 June 2025. [Google Scholar]
  120. Bettale, L.; Dottax, E.; Grémy, L. Post-Quantum Secure Channel Protocols for eSIMs; Paper 2024/2005; Cryptology ePrint Archive. 2024. Available online: https://www.scitepress.org/Link.aspx?doi=10.5220/0013507200003979 (accessed on 20 December 2025).
  121. Micciancio, D.; Regev, O. Lattice-based Cryptography. In Post-Quantum Cryptography; Springer: Berlin/Heidelberg, Germany, 2021; pp. 147–191. [Google Scholar] [CrossRef] [Scilit]
  122. Katsumata, S.; Kwiatkowski, K.; Pintore, F.; Prest, T. Scalable Ciphertext Compression Techniques for Post-Quantum KEMs and their Applications. In Proceedings of the Advances in Cryptology–ASIACRYPT 2020, Part I; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2020; Volume 12491, pp. 289–320. [Google Scholar] [CrossRef] [Scilit]
  123. Liu, S.; Sakzad, A. Lattice Codes for CRYSTALS-Kyber. Des. Codes Cryptogr. 2025, 93, 3181–3205. [Google Scholar] [CrossRef] [Scilit]
  124. Schwabe, P.; Stebila, D.; Wiggers, T. Post-Quantum TLS Without Handshake Signatures. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Virtual, 9–13 November 2020; ACM: New York, NY, USA, 2020; pp. 1461–1477. [Google Scholar] [CrossRef] [Scilit]
  125. Schwabe, P.; Stebila, D.; Wiggers, T. More efficient post-quantum KEMTLS with pre-distributed public keys. In Proceedings of the Computer Security–ESORICS 2021, Darmstadt, Germany, 4–8 October 2021; Lecture Notes in Computer Science; Bertino, E., Shulman, H., Waidner, M., Eds.; Springer: Cham, Switzerland, 2021; pp. 3–22. [Google Scholar] [CrossRef] [Scilit]
  126. Celi, S.; Faz-Hernández, A.; Sullivan, N.; Tamvada, G.; Valenta, L.; Wiggers, T.; Westerbaan, B.; Wood, C.A. Implementing and Measuring KEMTLS. In Proceedings of the Progress in Cryptology–LATINCRYPT 2021, Bogota, Colombia, 6–8 October 2021; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2021; Volume 12912, pp. 88–107. [Google Scholar] [CrossRef] [Scilit]
  127. Gonzalez, R.; Wiggers, T. KEMTLS vs. Post-Quantum TLS: Performance on Embedded Systems. In Proceedings of the Security, Privacy, and Applied Cryptography Engineering (SPACE 2022), Jaipur, India, 9–12 December 2022; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2022; Volume 13783, pp. 99–117. [Google Scholar] [CrossRef] [Scilit]
  128. Rawat, A.S.; Jhanwar, M.P. Quantum-safe Signatureless DNSSEC. In ASIA CCS ’25: Proceedings of the 20th ACM Asia Conference on Computer and Communications Security, Hanoi, Vietnam, 25–29 August 2025; ACM: New York, NY, USA, 2025; pp. 267–282. [Google Scholar] [CrossRef] [Scilit]
  129. Gilad, Y.; Herzberg, A. Fragmentation considered vulnerable: Blindly intercepting and discarding fragments. In Proceedings of the 5th USENIX Workshop on Offensive Technologies (WOOT 11), San Francisco, CA, USA, 8–9 August 2011. [Google Scholar]
Figure 1. This review paper’s organization, surveying the research literature, with the horizontal axis representing different networking protocols and systems designed for scalable networks.
Figure 1. This review paper’s organization, surveying the research literature, with the horizontal axis representing different networking protocols and systems designed for scalable networks.
Cryptography 10 00012 g001
Figure 2. Timeline of PQC development and NIST standardization milestones. Blue-colored highlights represent successive candidate-selection phases (Rounds 1–4) including the number of PQC ciphers which advanced from the previous round, whereas black-colored highlights indicate significant milestones, announcements, and official standards publications, including FIPS. The NIST standardization focuses on the PQC cipher algorithms themselves and its scope excludes the incorporation to networking protocols and systems.
Figure 2. Timeline of PQC development and NIST standardization milestones. Blue-colored highlights represent successive candidate-selection phases (Rounds 1–4) including the number of PQC ciphers which advanced from the previous round, whereas black-colored highlights indicate significant milestones, announcements, and official standards publications, including FIPS. The NIST standardization focuses on the PQC cipher algorithms themselves and its scope excludes the incorporation to networking protocols and systems.
Cryptography 10 00012 g002
Table 1. List of acronyms used multiple times in this paper, including the section first introducing them (§).
Table 1. List of acronyms used multiple times in this paper, including the section first introducing them (§).
AcronymFull Form§
PQCPost-Quantum CryptographySection 1
HQCHamming Quasi-CyclicSection 1
NISTNational Institute of Standards and TechnologySection 1
OQSOpen Quantum SafeSection 1
KMSKey Management ServiceSection 2
KEMKey Encapsulation MechanismSection 2.2
FIPSFederal Information Processing StandardsSection 2.2
MLWEModule Learning With ErrorsSection 3
MLWRModule Learning With RoundingSection 3
CPACorrelation Power AnalysisSection 3.2
DPADifferential Power AnalysisSection 3.2
TLSTransport Layer SecuritySection 5.2
DNSSECDomain Name System SECurity ExtensionsSection 5.2
SUCISubscription Concealed IdentifierSection 5.3
Table 2. NIST PQC KEM algorithms, security levels, and parameter sizes. It includes HQC, although the HQC standardization is currently undergoing.
Table 2. NIST PQC KEM algorithms, security levels, and parameter sizes. It includes HQC, although the HQC standardization is currently undergoing.
AlgorithmSchemeParametersSecurityPrivate Key (B)Public Key (B)Ciphertext (B)
KyberLattice-basedKyber51211632800768
Kyber7683240011841088
Kyber10245316815681568
HQCCode-basedHQC-1281230522494433
HQC-1923458645228978
HQC-25657317724514,421
Table 3. NIST PQC digital signature algorithms, security level, and parameter sizes.
Table 3. NIST PQC digital signature algorithms, security level, and parameter sizes.
AlgorithmSchemeParametersSecurityPrivate Key (B)Public Key (B)Signature (B)
DilithiumLattice-basedDilithium 21252813122420
Dilithium 33400019523293
Dilithium 55486425924595
FalconLattice-basedFalcon 51211281897666
Falcon 10245230517931280
SPHINCS+Hash-basedSPHINCS+-128s/128f164328080/17,088
SPHINCS+-192s/192f3964816,064/35,664
SPHINCS+-256s/256f51286429,792/49,856
Table 4. Target protocols and applications in existing PQC feasibility research.
Table 4. Target protocols and applications in existing PQC feasibility research.
ProtocolApplicationPQC Functionality§
X.509 PKIGeneralDSSection 5.1
TLSWebKEM, DSSection 5.2
QUICWebKEM., DSSection 5.2
DNSSECWebDSSection 5.2
IKEWeb (IPSec)KEMSection 5.2
SUCICellularKEMSection 5.3
eSIMCellularDSSection 5.3
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Chang, S.-Y.; Khan, Q. Post-Quantum Cryptography in Networking Protocols: Challenges, Solutions, and Future Directions. Cryptography 2026, 10, 12. https://doi.org/10.3390/cryptography10010012

AMA Style

Chang S-Y, Khan Q. Post-Quantum Cryptography in Networking Protocols: Challenges, Solutions, and Future Directions. Cryptography. 2026; 10(1):12. https://doi.org/10.3390/cryptography10010012

Chicago/Turabian Style

Chang, Sang-Yoon, and Qaiser Khan. 2026. "Post-Quantum Cryptography in Networking Protocols: Challenges, Solutions, and Future Directions" Cryptography 10, no. 1: 12. https://doi.org/10.3390/cryptography10010012

APA Style

Chang, S.-Y., & Khan, Q. (2026). Post-Quantum Cryptography in Networking Protocols: Challenges, Solutions, and Future Directions. Cryptography, 10(1), 12. https://doi.org/10.3390/cryptography10010012

Article Metrics

Back to TopTop