A measurement study of PQC primitives on embedded-class ARM hardware under three execution environments with a shared software stack: native execution, a Docker container, and a Unikraft unikernel running under QEMU finds that container overhead is negligible for primitive computation, whereas unikernel overhead depends on the algorithm.
Abstract
Post-Quantum Cryptography (PQC) is being deployed while embedded systems increasingly adopt lightweight virtualization for workload isolation and security. Both trends change performance characteristics, yet their interaction is not well understood. To address this, we present a measurement study of PQC primitives on embedded-class ARM hardware under three execution environments with a shared software stack: native execution, a Docker container, and a Unikraft unikernel running under QEMU. We benchmark five signature and five key encapsulation mechanism families, and, for comparison, two classical algorithms each. We evaluate them using different parameter sets for a total of around 70 configurations, measuring execution time, memory, and energy per operation. To better gauge the impact on applications, we evaluated TLS 1.3 cipher combinations. We find that container overhead is negligible for primitive computation, whereas unikernel overhead depends on the algorithm. For most PQC families the overhead is negligible. A moderate overhead (1.28-1.53) arises in BIKE, HQC, and MAYO, and, above all, in Falcon signing (17.8-19.2). Per-operation energy closely tracks execution time in all environments. For TLS handshakes, container and unikernel clients need more time and energy per handshake, while all three environments converge once expensive post-quantum algorithms dominate the handshake. In these cases algorithm choice affects per-handshake energy by up to three orders of magnitude, far outweighing the environment. Overall, virtualization cost is inversely related to cryptographic cost: environment choice matters most for computationally cheap, standardized algorithms, while for expensive schemes, algorithm choice alone dominates performance.
These days, keeping digital conversations safe matters more than ever. The problem is, most cryptographic tools out there lean on third-party services. That opens the door to privacy risks, and things can get pretty demanding on your hardware. That’s why this research introduces the Boolean-multi-based Hyena Crypto Ell...
Chandan Kumar, Raushan Kumar, Akhilesh Kumar et al.· 2026 International Conferenc...· 0 citations
Cloud-native infrastructures now form the backbone of modern digital systems, offeringscalability and flexible deployment, But they introduce new security challenges beyondtraditional cryptographic methods. The rise of quantum computing further threatens widelyused algorithms like RSA and ECC, which remain vulnerable t...
K. Princey, T. Beena· THE SCIENTIFIC TEMPER· 0 citations
This study benchmarks seven Key Encapsulation Mechanisms and lattice-based schemes, particularly ML-KEM and Kyber, emerged as the most practical PQC solutions for resource-constrained IoT environments and demonstrates the usefulness of virtualized benchmarking for deployment planning.
Yahaya Salisu, Sandeep Kumar, Surajo Nuhu Umar et al.· International Journal of Inn...· 0 citations
The distributed function accelerator (DFA), a hardware accelerator that targets the dominant primitive in FSS: distributed point function (DPF) generation and evaluation, combines a high-throughput fixed-function engine for AES-based pseudorandom number generation with a lightweight programmable unit for protocol-speci...
The transition to post-quantum cryptography (PQC) presents significant challenges for modern computing environments due to increased computational overhead, communication latency, and implementation complexity. Existing evaluation methods typically focus on isolated cryptographic performance metrics and do not provide...
Jonatan Rassekhnia, Karl Andersson, Ahmed Afif Monrat· Journal of Cybersecurity and...· 0 citations
Post-quantum cryptography (PQC) architectures are becoming essential for secure boot mechanisms in embedded RISC-V systems due to emerging quantum threats against RSA and ECDSA in the coming years. The paper presents a hardware-accelerated CRYSTALS-Dilithium implementation on India's indigenous Shakti C-Class processor...
Darshana N. Sankhe, Soham Lotlikar, Suman Swain et al.· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.