Skip to content
Open access

Beyond encryption: post-quantum cryptography and the future of quantum-safe networks

Aug 2026 · Frontiers of Computer Science · 0 citations · 21 references

TL;DR

This analysis demonstrates that while hybrid PQC-QKD models reduce long-term key compromise probabilities to near 0%, they introduce a 15% to 40% increase in bandwidth overhead during initial cryptographic handshakes during initial cryptographic handshakes.

Abstract

The rapid advancement of quantum computing presents an existential threat to the mathematical foundations of modern internet security. Fault-tolerant quantum computers are projected to reach the logical qubit scale necessary to execute Shor's algorithm by 2030–2035, threatening currently deployed public-key cryptography infrastructures. We evaluate the performance metrics of integrating post-quantum cryptography (PQC), specifically the newly finalized NIST standards (FIPS 203, 204, and 205), with quantum key distribution (QKD) across communication networks. Our analysis demonstrates that while hybrid PQC-QKD models reduce long-term key compromise probabilities to near 0%, they introduce a 15% to 40% increase in bandwidth overhead during initial cryptographic handshakes. Given that enterprise-wide cryptographic migrations historically require 7–10 years, organizations face an immediate vulnerability window against “harvest now, decrypt later” adversaries. Ultimately, we propose a phased, cryptographically agile framework to achieve a Zero-Trust, Quantum-Safe network architecture within a 5-year implementation timeline.

Read PDF

Similar papers

Open access Jul 2026

Quantum Computing and the Future of Cybersecurity: Assessing the Threat to Classical Encryption Standards

It is argued that organizations should treat cryptographic migration as a present-tense operational requirement rather than a future contingency, regardless of unresolved disagreement among experts about when a cryptographically relevant quantum computer will exist.

Ramya, Rashmi · 0 citations
Review Open access 2023

The Role of Quantum-Safe Cryptography in Next-Generation Security

Quantum computing offers major computational advances but threatens modern public-key cryptography. Classical algorithms such as RSA, Diffie–Hellman (DH), and Elliptic Curve Cryptography (ECC) are vulnerable to quantum attacks, particularly Shor’s algorithm. As large-scale quantum capabilities emerge, post-quantum cryptography (PQC) has become essential to ensure future data confidentiality, integrity, and authentication. This paper discusses the need to replace classical cryptography, explores quantum-safe solutions, and examines challenges in large-scale migration. PQC is critical across government, critical infrastructure, finance, healthcare, telecommunications, IoT, autonomous vehicles, and 6G networks. A key concern is “harvest-now, decrypt-later” attacks, where encrypted data is stored today for future quantum decryption. The study analyzes classical cryptographic vulnerabilities and reviews major PQC families: lattice-based, hash-based, code-based, multivariate-based, and isogeny-based schemes, highlighting the ongoing NIST standardization efforts. It proposes a migration framework including quantum-readiness assessment, algorithm selection, hybrid implementation, and performance evaluation. Results show that although PQC introduces higher computational complexity, optimized implementations can support real-time applications with reasonable overhead. Among PQC approaches, lattice-based schemes appear most mature and balanced in terms of security and key size. The paper concludes that quantum-safe cryptography is a necessary evolution requiring continuous monitoring, adaptable systems, and alignment with emerging standards.

Noah Wright, Isabella Moore · 0 citations
Review Open access Sep 2026

Hybrid Post-Quantum Cryptography and Quantum Key Distribution Co-Design for Quantum-Safe 6G, O-RAN, and IoT Infrastructure

Cryptographically relevant quantum computers do not yet exist, but the transition away from classical public-key cryptography is already underway: adversaries can record encrypted traffic today and decrypt it once a sufficiently capable quantum computer becomes available, a threat known as harvest-now, decrypt-later. This paper examines the engineering case for combining post-quantum cryptography (PQC) with quantum key distribution (QKD) as a strategy for securing next-generation communication infrastructure, focusing on 6G core and radio-access networks, Open RAN (O-RAN), and constrained Internet of Things (IoT) deployments. Rather than treating the two mechanisms as symmetric, interchangeable layers, the paper examines what each one actually guarantees, surveys the empirical evidence available for deployment cost, and describes where national security authorities and standards bodies disagree on the value of QKD. The architecture is grounded in the finalized National Institute of Standards and Technology (NIST) PQC standards and its 2025 hybrid key-establishment guidance, drawing on empirical Open RAN latency and energy measurements published during 2025 and 2026, embedded-hardware benchmarks for constrained devices, and the small number of quantum key distribution deployments operating at metropolitan or national backbone scale today. The paper is explicit about which figures are measured results and which remain illustrative proposals, and it closes by naming the specific standardization and field-trial gaps that separate current practice from the architecture it describes. The purpose of the work is to give network architects and policymakers a single, evidence-graded reference for deciding where each mechanism belongs in a real deployment, rather than treating post-quantum and quantum-distributed keying as equivalent options.

Aagnik Chakraborty · 0 citations
Review Open access Jul 2026

Post-Quantum Cryptography Migration for Enterprise Security

Large-scale quantum computers threaten the public-key cryptography that protects enterprise data, communications, and digital identity. Shor's algorithm solves integer factorization and discrete logarithms in polynomial time, which would break RSA, Diffie-Hellman, and elliptic-curve schemes once a cryptographically relevant quantum computer exists. The danger is not only future. Adversaries can record encrypted traffic today and decrypt it later, a tactic known as harvest-now-decrypt-later. In August 2024 the U.S. National Institute of Standards and Technology published its first post-quantum standards: FIPS 203 (ML-KEM, derived from CRYSTALS-Kyber), FIPS 204 (ML-DSA, from CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, from SPHINCS+). This paper presents a practical migration framework for enterprises. It reviews the quantum threat and Mosca's inequality for timing the transition, summarizes the new standards with their key and signature sizes, and proposes a five-phase roadmap built on crypto-agility: discovery and inventory, risk prioritization, agility engineering, hybrid deployment, and validation. Performance trade-offs are analyzed using documented parameter sizes and illustrative TLS handshake figures. ML-KEM-768 carries a 1,184-byte public key against 64 bytes for an elliptic-curve key, while SPHINCS+ signatures can exceed 17 kilobytes. The work does not report a real deployment. It consolidates published parameters and field guidance into an actionable plan, and it highlights open challenges in certificate sizing, hardware support, and long-lived embedded systems.

Mini T. V. · 0 citations
Open access Sep 2026

The intersection of post-quantum cryptography and QaaS: architecting quantum-safe cloud infrastructures

By 2030, an estimated 40% of current cloud infrastructures may be rendered vulnerable by cryptanalytically relevant quantum computers (CRQCs). This paper introduces a 4-tier security framework tailored for Quantumas-a-Service (QaaS) deployments, focusing on securing data-in-transit. Integrating 3 NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, and SLHDSA), our architecture mitigates interception threats based on Shor's algorithm. Emulation across an enterprise cloud topology demonstrates a maximum latency overhead of 17.7 milliseconds per TLS handshake under high-latency WAN conditions, ensuring high-availability operations without catastrophic fragmentation failure. The proposed model demonstrates the viability of modern latticebased cryptography for live environments and provides a structured 3-phase transition roadmap for cloud service providers (CSPs) to achieve quantum-resilience seamlessly.

Akshay Joseph, R. Delhibabu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.