by Ruben Rios and José A. Montenegro (University of Málaga)
Post-quantum cryptography is no longer a theoretical exercise. As quantum-safe algorithms move towards large-scale deployment, recent studies by NICS Lab in the context of PQSecNg project show that the main challenges extend far beyond the cryptographic primitives themselves, revealing hidden bottlenecks across protocols, software stacks and network infrastructures.
The transition to post-quantum cryptography (PQC) marks one of the most significant transformations in the recent history of cybersecurity. For decades, the security of Internet communications has relied on public-key primitives such as RSA and elliptic-curve cryptography. However, sufficiently powerful quantum computers are expected to eventually break these mechanisms, compelling governments, industries, and infrastructure operators worldwide to prepare for a quantum-safe future.
Today, the discussion is no longer centred on whether this transition will occur, but on how it can be achieved efficiently and at scale, ensuring cryptoagility — the ability of systems to rapidly adapt cryptographic mechanisms as needed.
Our research has focused on understanding the practical implications of deploying PQC in real communication systems. While considerable effort has been devoted to designing and standardising quantum-resistant algorithms, much less attention has been paid to the impact of integrating them into the layered infrastructure that supports modern Internet services.
The starting point was the development of a framework for evaluating post-quantum Transport Layer Security (TLS), the protocol that provides the security foundation for most Internet communications. Existing studies often focused on isolated cryptographic operations, providing useful but incomplete insights. In contrast, real-world deployments involve complex interactions between libraries, protocols, and services, as well as variable network conditions. To capture these effects, our evaluation framework was built to measure end-to-end performance under realistic deployments.
Using this framework, we benchmarked a wide range of TLS configurations during the handshake phase [1], covering different post-quantum primitives for key establishment (KEM) and authentication (signatures). The results demonstrated that quantum-safe communications are already technically viable. However, not all configurations exhibit the same deployment costs. While some configurations introduced only modest overhead, others required considerably larger handshake messages and created additional operational challenges that make them unsuitable even for simple deployments.
While TLS remains the cornerstone of secure web communications, newer transport protocols are rapidly gaining ground. The scope of this work was therefore extended to QUIC — a transport protocol increasingly adopted by web browsers, cloud providers, and large-scale Internet platforms — which was specifically designed to reduce latency and improve connection establishment, making it an increasingly relevant deployment target for post-quantum cryptography.
A comparative analysis of post-quantum deployments in TLS and QUIC revealed that protocol behaviour becomes considerably more complex when quantum-safe algorithms are introduced [2]. The benefits associated with modern transport protocols may be undermined by larger cryptographic payloads and modified handshake procedures. These findings highlight the importance of evaluating complete protocol ecosystems rather than studying cryptographic algorithms in isolation.
Perhaps the most important insight emerging from our research is that the bottleneck is not necessarily the PQC primitive. Our latest work [3] adopted a broader perspective and investigated the deployment of PQC across different layers of the communication stack — including both KEM and signature primitives, mutually authenticated TLS, and TLS-based VPN — and across different hardware architectures — Intel and ARM. The results revealed that protocol interactions, software architectures and network conditions often contribute as much as, or even more than, the cryptographic primitives themselves to the overall deployment cost. A summary of results is shown in Figure 1.
In other words, replacing a classical primitive with a post-quantum alternative is only one part of a much larger engineering challenge. This observation is particularly relevant in the current transition toward quantum-safe communications. Understanding where bottlenecks appear and how they propagate through different layers is therefore essential for achieving efficient quantum-safe systems.
As Europe continues to invest in quantum technologies and cybersecurity resilience, practical deployment research will become increasingly important. Building secure communication infrastructures for the quantum era requires not only strong cryptographic primitives but also a deep understanding of how these primitives interact with network protocols, software, and hardware architectures.
Taken together, our studies suggest an encouraging but nuanced message. The quantum-safe Internet is already within reach. However, the path towards successful large-scale adoption will depend on rigorous benchmarking, interoperability testing and system-level optimisation efforts that extend well beyond cryptographic design.
The future quantum-safe Internet will not be defined solely by cryptography. It will be defined by our ability to efficiently integrate post-quantum cryptography into the protocols, platforms, and network infrastructure on which our society depends.
References:
[1] J.A. Montenegro, R. Rios, J. Lopez-Cerezo, “A Performance Evaluation Framework for Post-Quantum TLS”, Future Generation Computer Systems, 2025.
[2] J.A. Montenegro, R. Rios, J. Bonilla, “Comparative Analysis of Post-Quantum Handshake Performance”, in QUIC and TLS Protocols, Computer Networks, 2025.
[3] R. Rios, J.A. Montenegro, “Post-Quantum Cryptography: A Multi-layer Bottleneck Analysis”, International Journal of Information Security, 2026.
Links:
[1] https://www.nics.uma.es
[2] https://github.com/montenegro-montes
Please contact:
Ruben Rios and Jose A. Montenegro
E.T.S.I. Informática, Spain
{ruben.rdp, jmmontes}@uma.es
No. 145
No. 144
No. 143
No. 142
No. 141
No. 140
No. 139