New Challenges in Post-Quantum Cryptography

Cover of New Challenges in Post-Quantum Cryptography. Dark blue background with the book title in large white text. A glowing blue sphere with a geometric network pattern contains a computer monitor, keyboard, and a padlock icon. The Aalborg University Open Publishing logo appears in the lower right corner.
Contributors

Abraham Cano Aguilera, Eindhoven University of Technology, The Netherlands
Raphael Frantz, Eindhoven University of Technology, The Netherlands
Dimosthenis Iliadis-Apostolidis, Aalborg University, Denmark
José Luis Imaña, Complutense University of Madrid, Spain
Sokol Kosta, Aalborg University, Denmark
Daniel Christian Lawo, Eindhoven University of Technology, The Netherlands
Joseph Meyer, Eindhoven University of Technology, The Netherlands
Michał Podleś, Eindhoven University of Technology, The Netherlands
Jerónimo Sánchez García, Aalborg University, Denmark
Idelfonso Tafur Monroy, Eindhoven University of Technology, The Netherlands
Juan José Vegas Olmos, NVIDIA, USA; Aalborg University, Denmark

Abstract

New Challenges in Post-Quantum Cryptography presents a system-level perspective on the transition to post-quantum cryptography. Developed within the MSCA DN-ID QUARC consortium, the book examines how quantum computing challenges the security assumptions underlying modern cryptographic systems and explores the implications for communication networks, computing infrastructures, and digital trust frameworks.

The book introduces the foundations of classical and post-quantum cryptography, discusses the quantum threat model, and examines migration strategies, hybrid cryptographic approaches, and crypto-agile system design. Particular attention is given to the deployment of post-quantum cryptography in networking environments, including protocols such as TLS, IPsec, and MACsec, as well as issues related to performance, scalability, hardware acceleration, virtualization, and secure communication infrastructures.

Combining theoretical foundations with practical deployment considerations, the book explores how quantum-resilient security can be integrated into modern computing and communication infrastructures.

References

A. C. Aguilera. “Accelerating Quantum-Secure Communications via DPU-Based Network Offloads”. PhD thesis. Eindhoven, The Netherlands: Eindhoven University of Technology, Feb. 2026. isbn: 978-90-386-6598-6.

D. C. Lawo. “Post-Quantum Cryptography for Resilient and Secure CommunicationSystems”. PhD thesis. Eindhoven, The Netherlands: Eindhoven University of Technology, Dec. 2025. isbn: 978-90-386-6546-7.

A. Cano Aguilera, X. Arnal i Clemente, D. C. Lawo, I. Tafur Monroy, and J. J. Vegas Olmos. “First End-to-End PQC Protected DPU-to-DPU Communications”. In: Electronics Letters 59.17 (2023), e12901. doi: 10.1049/ell2.12901.

D. Lawo, R. Frantz, A. Cano Aguilera, I. Tafur Monroy, and J. J. Vegas Olmos. “Implementation and Comparison of Dilithium/Kyber and Falcon/Kyber PQC Software Stack on Data Processing Units”. In: Proceedings of the 27th Annual

Symposium of the IEEE Photonics Benelux Chapter. 27th Annual Symposium of the IEEE Photonics Benelux Chapter, IEEE Benelux 2023. Conference date: 23–24 November 2023. Ghent, Belgium, Nov. 2023. url: https://www.aanmelder.nl/ieee-ps-benelux-2023.

A. Cano Aguilera, C. Rubio García, D. Lawo, R. Frantz, I. Tafur Monroy, J. Imaña, and J. Vegas Olmos. “Post-Quantum Secure Protocols for Communication Between Data Processing Units”. In: Proceedings of IEEE Photonics Benelux Chapter Annual Symposium 2023. 27th Annual Symposium of the IEEE Photonics Benelux Chapter, IEEE Benelux 2023. Conference date: 23–24 November 2023. Nov. 2023. url: https://www.aanmelder.nl/ieee-ps-benelux-2023.

D. Lawo, R. Frantz, A. Cano Aguilera, X. Arnal I Clemente, M. Podleś, J. L. Imaña, I. Tafur Monroy, and J. J. Vegas Olmos. “Falcon/Kyber and Dilithium/Kyber Network Stack on NVIDIA’s Data Processing Unit Platform”. In: IEEE Access 12 (Mar. 2024), pp. 38048–38056. doi: 10.1109/ACCESS.2024.3374629.

A. Cano Aguilera, R. Abu Bakar, F. Alhamed, C. Rubio Garcia, J. L. Imaña, I. Tafur Monroy, F. Cugini, and J. J. Vegas Olmos. “First Line-Rate End-to-End Post-Quantum Encrypted Optical Fiber Link Using Data Processing Units (DPUs)”. In: Optical Fiber Communication Conference (OFC) 2024. Optica Publishing Group, 2024, M1G.4. doi: 10.1364/OFC.2024.M1G.4.

C. Rubio Garcia, A. Cano, J. J. Vegas Olmos, S. Rommel, and I. Tafur Monroy. “Integrating Quantum Key Distribution into TLS 1.3: A Transport Layer Approach to Quantum-Resistant Communications in Optical Networks”. In: Optical Fiber Communication Conference (OFC) 2024. Optica Publishing Group, 2024, Th3B.3. doi: 10.1364/OFC.2024.Th3B.3.

A. Cano Aguilera, C. Rubio Garcia, D. Lawo, J. L. Imaña, I. Tafur Monroy, and J. J. Vegas Olmos. “In-line rate encrypted links using pre-shared post-quantum keys and DPUs”. In: Scientific Reports 14.1 (Sept. 2024), p. 21227. doi: 10.1038/s41598-024-71861-x.

D. C. Lawo, R. Abu Bakar, A. Cano Aguilera, F. Cugini, J. L. Imaña, I. Tafur Monroy, and J. J. Vegas Olmos. “Wireless and Fiber-Based Post-Quantum-Cryptography-Secured IPsec Tunnel”. In: Future Internet 16.8 (2024), p. 300. doi: 10.3390/fi16080300.

A. Cano, C. R. Garcia, R. Frantz, I. T. Monroy, J. L. Imaña, and J. J. Vegas. “Integrating Post-Quantum Cryptography Plugins for IPsec Offloads to Data Processing Units in the Cloud-Edge Continuum”. In: 2024 IEEE 32nd International Conference on Network Protocols (ICNP). IEEE, 2024, pp. 1–6. doi: 10.1109/ICNP61940.2024.10858568.

D. Lawo, M. Podleś, R. Frantz, A. Cano Aguilera, D. Iliadis-Apostolidis, J. Sánchez García, S. Kosta, I. Tafur Monroy, J. L. Imaña, and J. J. Vegas Olmos. “The Zero-Tax Data Center: A Use Case Through Quantum Resilient Communications”. In: 2024 24th International Conference on Transparent Optical Networks (ICTON). IEEE, 2024, pp. 1–4. doi: 10.1109/ICTON62926.2024.10647337.

C. Rubio García, A. Cano Aguilera, C. Stan, J. J. Vegas Olmos, S. Rommel, and I. Tafur Monroy. “Enhanced Network Security Protocols for the Quantum Era: Combining Classical and Post-Quantum Cryptography, and Quantum Key Distribution”. In: IEEE Journal on Selected Areas in Communications 43.8 (2025), pp. 2765–2781. doi: 10.1109/JSAC.2025.3568011.

A. Cano Aguilera, C. Rubio Garcia, D. C. Lawo, I. Tafur, J. L. Imaña, and J. J. Vegas Olmos. “First Demonstration of 200 Gbps Regime Line-Rate Quantum-Secure MACsec Optical Links Using Commodity Hardware Offloads”. In: Optical Fiber Communication Conference (OFC) 2025. Optica Publishing Group, 2025, Tu2D.2. doi: 10.1364/OFC.2025.Tu2D.2.

A. Cano Aguilera, I. Tafur Monroy, J. J. Vegas Olmos, and J. L. Imaña. “ARM Architecture Optimizations for Line-Rate PQC Communications”. In: 2025 International Conference on Optical Network Design and Modeling (ONDM). IEEE, 2025, pp. 1–4. doi: 10.23919/ONDM65745.2025.11029331.

A. Cano, J. L. Imaña, I. T. Monroy, and J. J. Vegas Olmos. “Post-Quantum Cryptography for Quantum Resilient Data Transfer”. In: 2025 25th Anniversary International Conference on Transparent Optical Networks (ICTON). Ed. by C. Cojocaru, S. Spadaro, and M. Marciniak. United States: Institute of Electrical and Electronics Engineers, Aug. 2025. doi: 10.1109/ICTON67126.2025.11125195.

D. Lawo, R. Abu Bakar, A. Cano Aguilera, F. Cugini, J. L. Imaña, I. Tafur Monroy, and J. J. Vegas Olmos. “Future Data Centers: Hardware-Offloaded Post-Quantum Secure Optical IPsec Tunnel for Confidential AI Training”. In: Proceedings of the 2025 International Conference on Optical Network Design and Modeling (ONDM). Pisa, Italy, 2025. url: https://opendl.ifip- tc6.org/db/conf/ondm2025/ondm2025/1571114929.pdf.

D. Iliadis-Apostolidis, D. C. Lawo, S. Kosta, I. Tafur Monroy, and J. J. Vegas Olmos. “QRoNS: Quantum Resilience Over IPsec Tunnels for Network Slicing”. In: Electronics 14.21 (2025), p. 4234. doi: 10.3390/electronics14214234.

D. Iliadis-Apostolidis, D. C. Lawo, S. Kosta, and J. J. Vegas Olmos. “SNSVS: Scalable Network Slicing with Virtualized Systems using Post-Quantum Cryptography”. In: GLOBECOM 2025 - 2025 IEEE Global Communications Conference. IEEE, 2025, pp. 3109–3114. doi: 10.1109/GLOBECOM59602.2025.11431714.

D. C. Lawo, I. T. Monroy, and J. J. V. Olmos. “Confidential Computing and AI in Networking Fabrics”. In: 2025 25th Anniversary International Conference on Transparent Optical Networks (ICTON). IEEE, 2025, pp. 1–4. doi: 10.1109/ICTON67126.2025.11125026.

J. Meyer, A. Cano, F. Cugini, I. Tafur Monroy, and J. J. Vegas Olmos. Design and Evaluation of a Heterogeneous DPU Architecture for Accelerating Post-Quantum Cryptography. Preprint, version 1, Research Square. Nov. 2025. doi: 10.21203/rs.3.rs-7817696/v1.

P. W. Shor. “Algorithms for Quantum Computation: Discrete Logarithms and Factoring”. In: Proceedings 35th Annual Symposium on Foundations of Computer Science. IEEE, 1994, pp. 124–134. doi: 10.1109/SFCS.1994.365700.

S. Kanev, J. P. Darago, K. Hazelwood, P. Ranganathan, T. Moseley, G.-Y. Wei, and D. Brooks. “Profiling a Warehouse-Scale Computer”. In: Proceedings of the 42nd Annual International Symposium on Computer Architecture. ISCA ’15. Association for Computing Machinery, 2015, pp. 158–169. doi: 10.1145/2749469.2750392.

S. Kanev, J. P. Darago, K. Hazelwood, P. Ranganathan, T. Moseley, G.-Y. Wei, and D. Brooks. “Retrospective: Profiling aWarehouse-Scale Computer”. In: International Symposium on Computer Architecture (ISCA). ISCA@50 25-Year Retrospective: 1996–2020. 2023. url: https://skanev.org/papers/wsc_retrospective.pdf.

IEEE Computer Society LAN/MAN Standards Committee. IEEE P802.3dj Project Authorization Request: Standard for Ethernet Amendment: Media Access Control Parameters for 1.6 Tb/s and Physical Layers and Management Parameters for 200 Gb/s, 400 Gb/s, 800 Gb/s, and 1.6 Tb/s Operation. Project Authorization Request P802.3dj. PAR approved 3 December 2022. Project status active at time of citation. IEEE, Sept. 2022. url: https://www.ieee802.org/3/dj/projdoc/P802d3dj_PAR.pdf.

C. Gidney. How to Factor 2048 Bit RSA Integers with Less Than a Million Noisy Qubits. 2025. doi: 10.48550/arXiv.2505.15917. arXiv: 2505.15917 [quant-ph].

Intro to Quantum. The Timelines: When Can We Expect Useful Quantum Computers?

Intro to Quantum. Accessed 25 August 2026. 2024. url: https://introtoquantum.org/essentials/timelines/.

C. Gidney and M. Ekerå. “How to Factor 2048 Bit RSA Integers in 8 Hours Using 20 Million Noisy Qubits”. In: Quantum 5 (Apr. 2021), p. 433. doi: 10.22331/q-2021-04-15-433.

J. Mascelli and M. Rodden. “Harvest Now Decrypt Later”: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks. Finance and Economics Discussion Series 2025-093. Board of Governors of the Federal Reserve System, Sept. 2025. doi: 10.17016/FEDS.2025.093.

General Intelligence and Security Service of the Netherlands (AIVD), Centrum Wiskunde & Informatica (CWI), and TNO. The PQC Migration Handbook: Guidelines for Migrating to Post-Quantum Cryptography. Guidance Report. Second edition. Publication date: 29 November 2024. General Intelligence and Security Service of the Netherlands (AIVD), Nov. 2024. url: https://english.aivd.nl/documents/2024/12/3/the-pqc-migration-handbook.

Cybersecurity Authorities of 18 European Union Member States. Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography. Joint Statement. Joint statement from partners from 18 European Union member states. Federal Office for Information Security (BSI), Nov. 2024. url: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Crypto/PQC-joint-statement.html.

National Security Agency. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ. Cybersecurity Information Sheet U/OO/194427-22. Version 2.1; PP-24-4014. National Security Agency, Dec. 2024. url: https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF.

Agence nationale de la sécurité des systèmes d’information (ANSSI). ANSSI Views on Crypto Agility. Technical Guidance. Published 19 January 2026. ANSSI, Jan. 2026. url: https://messervices.cyber.gouv.fr/guides/ANSSI-views-oncrypto-agility.

D. J. Bernstein. “Introduction to Post-Quantum Cryptography”. In: Post-Quantum Cryptography. Ed. by D. J. Bernstein, J. Buchmann, and E. Dahmen. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 1–14. doi: 10.1007/978-3-540-88702-7_1.

G. Alagic, D. Apon, D. Cooper, Q. Dang, T. Dang, J. Kelsey, J. Lichtinger, Y.-K. Liu, C. Miller, D. Moody, et al. Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process. NIST Internal Report 8413-upd1. National Institute of Standards and Technology, Sept. 2022. doi: 10.6028/NIST.IR.8413-upd1.

National Institute of Standards and Technology. Module-Lattice-Based Key-Encapsulation Mechanism Standard. Federal Information Processing Standards Publication NIST FIPS 203. Washington, D.C.: U.S. Department of Commerce, Aug. 2024. doi: 10.6028/NIST.FIPS.203.

National Institute of Standards and Technology. Module-Lattice-Based Digital Signature Standard. Federal Information Processing Standards Publication NIST FIPS 204. Washington, D.C.: U.S. Department of Commerce, Aug. 2024. doi: 10.6028/NIST.FIPS.204.

National Institute of Standards and Technology. Stateless Hash-Based Digital Signature Standard. Federal Information Processing Standards Publication NIST FIPS 205. Washington, D.C.: U.S. Department of Commerce, Aug. 2024. doi: 10.6028/NIST.FIPS.205.

F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan. “Secure Quantum Key Distribution With Realistic Devices”. In: Reviews of Modern Physics 92.2 (May 2020), p. 025002. doi: 10.1103/RevModPhys.92.025002.

R. Rios and J. A. Montenegro. “Post-Quantum Cryptography: A Multi-layer Bottleneck Analysis”. In: International Journal of Information Security 25.3, 89 (May 2026). doi: 10.1007/s10207-026-01242-0.

D. Boneh and V. Shoup. A Graduate Course in Applied Cryptography. Online textbook. Version 0.6; accessed 25 August 2026. 2023. url: https://toc.cryptobook.us/.

C. Paar and J. Pelzl. Understanding Cryptography: A Textbook for Students and Practitioners. Berlin, Heidelberg: Springer, 2010. doi: 10.1007/978-3-642-04101-3.

C. Matt and U. Maurer. “The One-Time Pad Revisited”. In: 2013 IEEE International Symposium on Information Theory. IEEE, 2013, pp. 2706–2710. doi: 10.1109/ISIT.2013.6620718.

National Institute of Standards and Technology. Advanced Encryption Standard (AES). Federal Information Processing Standards Publication NIST FIPS 197-upd1. Updated version of FIPS 197, originally published in 2001. Washington, D.C.: U.S. Department of Commerce, May 2023. doi: 10.6028/NIST.FIPS.197-upd1.

J. Daemen and V. Rijmen. “The Block Cipher Rijndael”. In: Smart Card Research and Applications. Ed. by J.-J. Quisquater and B. Schneier. Berlin, Heidelberg: Springer Berlin Heidelberg, 2000, pp. 277–284. doi: 10.1007/10721064_26.

M. J. Dworkin. Recommendation for Block Cipher Modes of Operation: Methods and Techniques. NIST Special Publication 800-38A. Gaithersburg, MD: National Institute of Standards and Technology, Dec. 2001. doi: 10.6028/NIST.SP.800-38A.

M. J. Dworkin. Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC. NIST Special Publication 800-38D. Gaithersburg, MD: National Institute of Standards and Technology, Nov. 2007. doi: 10.6028/NIST.SP.800-38D.

H. Krawczyk, M. Bellare, and R. Canetti. HMAC: Keyed-Hashing for Message Authentication. RFC 2104. RFC Editor, Feb. 1997. doi: 10.17487/RFC2104.

M. J. Dworkin. Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication. NIST Special Publication 800-38B. Gaithersburg, MD: National Institute of Standards and Technology, Oct. 2016. doi: 10.6028/NIST.SP.800-38B.

E. Rescorla. The Transport Layer Security (TLS) Protocol Version 1.3. RFC 8446. RFC Editor, Aug. 2018. doi: 10.17487/RFC8446.

J. Viega and D. McGrew. The Use of Galois/Counter Mode (GCM) in IPsec Encapsulating Security Payload (ESP). RFC 4106. RFC Editor, June 2005. doi:10.17487/RFC4106.

IEEE. IEEE Standard for Local and Metropolitan Area Networks–Media Access Control (MAC) Security. IEEE Std 802.1AE-2018. IEEE, Dec. 2018. doi: 10.1109/IEEESTD.2018.8585421.

H. Krawczyk and P. Eronen. HMAC-based Extract-and-Expand Key Derivation Function (HKDF). RFC 5869. RFC Editor, May 2010. doi: 10.17487/RFC5869.

National Institute of Standards and Technology. SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions. Federal Information Processing Standards Publication NIST FIPS 202. Gaithersburg, MD: U.S. Department of Commerce, Aug. 2015. doi: 10.6028/NIST.FIPS.202.

Certicom Research. SEC 1: Elliptic Curve Cryptography. Standard SEC 1, Version 2.0. Standards for Efficient Cryptography Group, May 2009. url: https://www.secg.org/sec1-v2.pdf.

W. Diffie and M. Hellman. “New Directions in Cryptography”. In: IEEE Transactions on Information Theory 22.6 (1976), pp. 644–654. doi: 10.1109/TIT.1976.1055638.

D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, and W. Polk. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. RFC 5280. RFC Editor, May 2008. doi: 10.17487/RFC5280.

International Telecommunication Union. Information technology — Open Systems Interconnection — The Directory: Public-key and attribute certificate frameworks. Recommendation X.509. Geneva, Switzerland: ITU-T, 2019. url: https://handle.itu.int/11.1002/1000/14033.

K. S. Mohamed. “Cryptography Concepts: Integrity, Authentication, Availability, Access Control, and Non-repudiation”. In: New Frontiers in Cryptography: Quantum, Blockchain, Lightweight, Chaotic and DNA. Cham: Springer Cham, 2020, pp. 41–63. doi: 10.1007/978-3-030-58996-7_3.

C. Kaufman, P. Hoffman, Y. Nir, P. Eronen, and T. Kivinen. Internet Key Exchange Protocol Version 2 (IKEv2). RFC 7296. RFC Editor, Oct. 2014. doi: 10.17487/RFC7296.

S. Kent. IP Encapsulating Security Payload (ESP). RFC 4303. RFC Editor, Dec. 2005. doi: 10.17487/RFC4303.

S. Kent and K. Seo. Security Architecture for the Internet Protocol. RFC 4301. RFC Editor, Dec. 2005, p. 101. doi: 10.17487/RFC4301.

S. Dubroca. “MACsec: Encryption for the Wired LAN”. In: Proceedings of Netdev 1.1. 2016. url: https://netdevconf.info/1.1/proceedings/papers/MACsec-Encryption-for-the-wired-LAN.pdf.

IEEE. IEEE Standard for Local and Metropolitan Area Networks–Port-Based Network Access Control. IEEE Std 802.1X-2010. Revision of IEEE Std 802.1X-2004. IEEE, 2010, pp. 1–205. doi: 10.1109/IEEESTD.2010.5409813.

F. Arute, K. Arya, R. Babbush, D. Bacon, J. C. Bardin, R. Barends, R. Biswas, S. Boixo, F. G. S. L. Brandao, D. A. Buell, et al. “Quantum Supremacy Using a Programmable Superconducting Processor”. In: Nature 574.7779 (Oct. 2019), pp. 505–510. doi: 10.1038/s41586-019-1666-5.

V. Bhatia and K. R. Ramkumar. “An Efficient Quantum Computing Technique for Cracking RSA Using Shor’s Algorithm”. In: 2020 IEEE 5th International Conference on Computing Communication and Automation (ICCCA). IEEE, 2020, pp. 89–94. doi: 10.1109/ICCCA49541.2020.9250806.

Network and Information Systems Cooperation Group. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. Implementation Roadmap. European Commission, June 2025. url: https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmaptransition-post-quantum-cryptography.

R. Horodecki, P. Horodecki, M. Horodecki, and K. Horodecki. “Quantum Entanglement”. In: Reviews of Modern Physics 81.2 (June 2009), pp. 865–942. doi: 10.1103/RevModPhys.81.865.

J. R. Friedman, V. Patel, W. Chen, S. K. Tolpygo, and J. E. Lukens. “Quantum Superposition of Distinct Macroscopic States”. In: Nature 406.6791 (July 2000), pp. 43–46. doi: 10.1038/35017505.

W. Easttom. “Quantum Computing and Cryptography”. In: Modern Cryptography: Applied Mathematics for Encryption and Information Security. Cham: Springer Cham, 2021, pp. 385–390. doi: 10.1007/978-3-030-63115-4.

L. K. Grover. “A Fast Quantum Mechanical Algorithm for Database Search”. In: Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing. STOC ’96. Association for Computing Machinery, 1996, pp. 212–219. doi: 10.1145/237814.237866.

X. Bonnetain, M. Naya-Plasencia, and A. Schrottenloher. “Quantum Security Analysis of AES”. In: IACR Transactions on Symmetric Cryptology 2019.2 (June 2019), pp. 55–93. doi: 10.13154/tosc.v2019.i2.55-93.

M. Grassl, B. Langenberg, M. Roetteler, and R. Steinwandt. “Applying Grover’s Algorithm to AES: Quantum Resource Estimates”. In: Proceedings of the 7th International Workshop on Post-Quantum Cryptography - Volume 9606. PQCrypto 2016. Springer-Verlag, 2016, pp. 29–43. doi: 10.1007/978-3-319-29360-8_3.

G. Brassard, P. Høyer, and A. Tapp. “Quantum Cryptanalysis of Hash and Claw-Free Functions”. In: LATIN’98: Theoretical Informatics. Ed. by C. L. Lucchesi and A. V. Moura. Berlin, Heidelberg: Springer Berlin Heidelberg, 1998, pp. 163–169. doi: 10.1007/BFb0054319.

D. Moody, R. Perlner, A. Regenscheid, A. Robinson, and D. Cooper. Transition to Post-Quantum Cryptography Standards. NIST Internal Report 8547 ipd. National Institute of Standards and Technology, Nov. 2024. doi: 10.6028/NIST.IR.8547.ipd.

M. Mosca and M. Piani. Quantum Threat Timeline Report 2024. Research Report. Report by Global Risk Institute and evolutionQ. Global Risk Institute, Dec. 2024. url: https://globalriskinstitute.org/publication/2024-quantum-threattimeline-report/.

J. Bos, L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, J. M. Schanck, P. Schwabe, G. Seiler, and D. Stehle. “CRYSTALS-Kyber: A CCA-Secure Module-Lattice-Based KEM”. In: 2018 IEEE European Symposium on Security and Privacy (EuroS&P). 2018, pp. 353–367. doi: 10.1109/EuroSP.2018.00032.

L. Ducas, E. Kiltz, T. Lepoint, V. Lyubashevsky, P. Schwabe, G. Seiler, and D. Stehlé. “CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme”. In: IACR Transactions on Cryptographic Hardware and Embedded Systems 2018.1 (Feb. 2018), pp. 238–268. doi: 10.13154/tches.v2018.i1.238-268.

D. J. Bernstein, A. Hülsing, S. Kölbl, R. Niederhagen, J. Rijneveld, and P. Schwabe. “The SPHINCS+ Signature Framework”. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. CCS ’19. New York, NY, USA: Association for Computing Machinery, 2019, pp. 2129–2146. doi: 10.1145/3319535.3363229.

C. Aguilar-Melchor, O. Blazy, J.-C. Deneuville, P. Gaborit, and G. Zémor. “Efficient Encryption From Random Quasi-Cyclic Codes”. In: IEEE Transactions on Information Theory 64.5 (2018), pp. 3927–3943. doi: 10.1109/TIT.2018.2804444.

A. Kipnis and A. Shamir. “Cryptanalysis of the Oil and Vinegar Signature Scheme”. In: Advances in Cryptology – CRYPTO ’98. Ed. by H. Krawczyk. Vol. 1462. Lecture Notes in Computer Science. Berlin, Heidelberg: Springer Berlin Heidelberg, 1998, pp. 257–266. doi: 10.1007/BFb0055733.

W. Beullens. “Breaking Rainbow Takes a Weekend on a Laptop”. In: Advances in Cryptology – CRYPTO 2022: 42nd Annual International Cryptology Conference, CRYPTO 2022, Santa Barbara, CA, USA, August 15–18, 2022, Proceedings, Part II. Berlin, Heidelberg: Springer-Verlag, 2022, pp. 464–479. doi: 10.1007/978-3-031-15979-4_16.

D. A. Cooper, D. C. Apon, Q. H. Dang, M. S. Davidson, M. J. Dworkin, and C. A. Miller. Recommendation for Stateful Hash-Based Signature Schemes. NIST Special Publication 800-208. Gaithersburg, MD: National Institute of Standards and Technology, Oct. 2020. doi: 10.6028/NIST.SP.800-208.

G. Alagic, M. Bros, P. Ciadoux, D. Cooper, Q. Dang, T. Dang, J. Kelsey, J. Lichtinger, Y.-K. Liu, C. Miller, et al. Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process. NIST Internal Report 8545. Gaithersburg, MD: National Institute of Standards and Technology, Mar. 2025. doi: 10.6028/NIST.IR.8545.

M. O. Alshomrany, F. Alsolami, M. Al-Hashimi, M. Saleh, O. Abulnaja, T. F. Al-Somani, and A. Altuwaijri. “QUASAR: Achieving Quantum Readiness for Post-Quantum Cryptography on RISC-V at Minimum Hardware Cost”. In: Electronics 15.10 (May 2026), p. 2154. doi: 10.3390/electronics15102154.

P.-A. Fouque, J. Hoffstein, P. Kirchner, V. Lyubashevsky, T. Pornin, T. Prest, T. Ricosset, G. Seiler, W. Whyte, and Z. Zhang. Falcon: Fast-Fourier Lattice-Based Compact Signatures over NTRU. Specification, version 1.2, submitted to the NIST Post-Quantum Cryptography Standardization Process. Jan. 2020. url: https://falcon-sign.info/falcon.pdf.

J. Howe, T. Prest, and D. Apon. “SoK: How (not) to Design and Implement Post-Quantum Cryptography”. In: Topics in Cryptology – CT-RSA 2021. Ed. by K. G. Paterson. Vol. 12704. Lecture Notes in Computer Science. Cham: Springer, 2021, pp. 444–477. doi: 10.1007/978-3-030-75539-3_19.

D. J. Bernstein, K. Bhargavan, S. Bhasin, A. Chattopadhyay, T. K. Chia, M. J. Kannwischer, F. Kiefer, T. B. Paiva, P. Ravi, and G. Tamvada. “KyberSlash: Exploiting Secret-Dependent Division Timings in Kyber Implementations”. In: IACR Transactions on Cryptographic Hardware and Embedded Systems 2025.2 (Mar. 2025), pp. 209–234. doi: 10.46586/tches.v2025.i2.209-234.

National Vulnerability Database. CVE-2024-37880 Detail. National Vulnerability Database. Accessed 25 August 2026. 2024. url: https://nvd.nist.gov/vuln/detail/CVE-2024-37880.

R. Rios, J. A. Montenegro, A. Muñoz, and D. Ferraris. “Toward the Quantum-Safe Web: Benchmarking Post-Quantum TLS”. In: IEEE Network 39.5 (Sept. 2025), pp. 247–253. doi: 10.1109/MNET.2025.3531116.

D. P. Karcz, M. Niemiec, M. A. Kourtis, and T. Köppl. “Exploring Hardware Implementation Feasibility of Post-Quantum Cryptography in Embedded Systems: Evaluation of NIST-Standardized ML-KEM, ML-DSA, and SLH-DSA on ESP32-C6”. In: PLOS ONE 21.8 (Aug. 2026), e0355179. doi: 10.1371/journal.pone.0355179.

O. Gillot, W. J. Buchanan, and M. G. Tehrani. “Energy Consumption of Post-Quantum Cryptography on Constrained and General-Purpose Architectures”. In: Cryptography 10.4 (2026), p. 55. doi: 10.3390/cryptography10040055.

European Union Agency for Cybersecurity (ENISA). Hybridization of Traditional Cryptographic Mechanisms with PQC: Standardisation Status. Standardisation Status Report. Published 30 April 2026; this report does not establish an ENISA/ECCG recommendation. European Union Agency for Cybersecurity (ENISA), Apr. 2026. url: https://certification.enisa.europa.eu/document/download/02f54596-6a99-4c9e-88c4-8c711ebff9c1_en?filename=ENISA+report+-+Hybridization+of+traditional+cryptographic+mechanisms+with+PQC+-+Standardisation+Status+-+30+April+2026+.pdf.

J. Haridas and M. Bachman. PQC in Plaintext: Google Cloud’s Post-Quantum Cryptography Roadmap. Google Cloud Blog. Accessed 25 August 2026. Aug. 2026. url: https://cloud.google.com/blog/products/identity-security/pqc-inplaintext-google-clouds-post-quantum-cryptography-roadmap.

Apple Inc. Prepare Your Network for Quantum-Secure Encryption in TLS. Apple Support. Accessed 25 August 2026. June 2026. url: https://support.apple.com/en-la/122756.

A. Weibel. ML-KEM Post-Quantum TLS Now Supported in AWS KMS, ACM, and Secrets Manager. AWS Security Blog. Accessed 25 August 2026. Apr. 2025. url: https://aws.amazon.com/blogs/security/ml-kem-post-quantum-tls-nowsupported-in-aws-kms-acm-and-secrets-manager/.

T. Daffron. Future-Proofing the Internet: Akamai Achieves End-to-End PQC. Akamai Blog. Accessed 25 August 2026. Aug. 2026. url: https://www.akamai.com/blog/security/future-proofing-internet-akamai-achieves-end-to-endpqc.

European Cybersecurity Certification Group, Sub-group on Cryptography. Agreed Cryptographic Mechanisms. Cryptographic Guidance. Version 2.0; applicable from 6 May 2025. European Cybersecurity Certification Group, Apr. 2025. url: https://certification.enisa.europa.eu/document/download/a845662b-aee0-484e-9191-890c4cfa7aaa_en?filename=ECCG+Agreed+Cryptographic+Mechanisms+version+2.pdf.

Federal Office for Information Security (BSI). Cryptographic Mechanisms: Recommendations and Key Lengths – Part 2: Use of Transport Layer Security (TLS). Technical Guideline BSI TR-02102-2. Version 2025-1. Federal Office for Information Security (BSI), 2025. url: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR02102/BSI-TR-02102-2.html.

Federal Office for Information Security (BSI). Cryptographic Mechanisms: Recommendations and Key Lengths – Part 3: Use of Internet Protocol Security (IPsec) and Internet Key Exchange (IKEv2). Technical Guideline BSI TR-02102-3. Version 2025-01. Federal Office for Information Security (BSI), 2025. url: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR02102/BSI-TR-02102-3.html.

Agence nationale de la sécurité des systèmes d’information (ANSSI). Cryptographie post-quantique (PQC). Official ANSSI guidance portal. Accessed 24 August 2026. url: https://cyber.gouv.fr/enjeux-technologiques/cryptographie-postquantique.

C. Tjhai, M. Tomlinson, G. Bartlett, S. Fluhrer, D. Van Geest, O. Garcia-Morchon, and V. Smyslov. Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2). RFC 9370. RFC Editor, May 2023. doi: 10.17487/RFC9370.

S. Fluhrer, P. Kampanakis, D. McGrew, and V. Smyslov. Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-quantum Security. RFC 8784. RFC Editor, June 2020. doi: 10.17487/RFC8784.

S. J. Park, R. Govindan, K. Shen, D. Culler, F. Özcan, G.-W. Kim, and H. Levy. “Lovelock: Towards Smart NIC-Hosted Clusters”. In: ACM SIGENERGY Energy Informatics Review 4.5 (Apr. 2025), pp. 172–179. doi: 10.1145/3727200.3727226.

A. Stephan and L. Wüstrich. “The Path of a Packet Through the Linux Kernel”. In: Seminar IITM WS 23. Technical University of Munich, Chair of Network Architectures and Services, 2024, pp. 89–93. doi: 10.2313/NET-2024-04-1_16.

M. Hossain. Trends in Data Center Security: Part 1: Traffic Trends. Cisco Security Blog. Accessed 25 August 2026. May 2014. url: https://blogs.cisco.com/security/trends-in-data-center-security-part-1-traffic-trends.

N. Kamiyama, Y. Nakano, K. Shiomoto, G. Hasegawa, M. Murata, and H. Miyahara. “Investigating Structure of Modern Web Traffic”. In: 2015 IEEE 16th International Conference on High Performance Switching and Routing (HPSR). IEEE, 2015, pp. 1–8. doi: 10.1109/HPSR.2015.7483102.

Intel Corporation. Intel Ethernet Adapters and Devices User Guide: Single Root I/O Virtualization (SR-IOV). Document ID: 705831. Version 29.3. Intel Corporation. Nov. 2024. url: https://edc.intel.com/content/www/us/en/design/products/ethernet/adapters-and-devices-user-guide/29.3/single-root-i-o-virtualization-sr-iov/.

V. Del Piccolo, A. Amamou, K. Haddadou, and G. Pujolle. “A Survey of Network Isolation Solutions for Multi-Tenant Data Centers”. In: IEEE Communications Surveys & Tutorials 18.4 (2016), pp. 2787–2821. doi: 10.1109/COMST.2016.2556979.

V. G. Cerf and E. Cain. “The DoD Internet Architecture Model”. In: Computer Networks (1976) 7.5 (1983), pp. 307–318. doi: 10.1016/0376-5075(83)90042-9.

International Organization for Standardization and International Electrotechnical Commission. Information Technology – Open Systems Interconnection – Basic Reference Model: The Basic Model. International Standard ISO/IEC 7498-1:1994. ISO/IEC, Nov. 1994. url: https://www.iso.org/standard/20269.html.

S. Goldberg and A. Paul. Post-Quantum Encryption for Cloudflare IPsec Is Generally Available. Cloudflare Blog. Accessed 25 August 2026. Apr. 2026. url: https: //blog.cloudflare.com/post-quantum-ipsec/.

Apple Inc. Quantum-Secure Cryptography in Apple Operating Systems. Apple Platform Security. Apple Inc. Jan. 2026. url: https://support.apple.com/guide/security/quantum-secure-cryptography-apple-devices-secc7c82e533/web.

Cisco Systems, Inc. Post-Quantum Cryptography on Cisco 8000 Series Secure Routers for IKEv2 Sessions. Security and VPN Configuration Guide. Cisco Systems, Inc. Apr. 2026. url: https://www.cisco.com/c/en/us/td/docs/routers/iosxe/security-vpn/security-vpn/m-pqc-ikev2.html.

M. Perera, M. Mackay, M. Hashem Eiza, A. Raschella, N. Shone, and M. K. Maheshwari. “Towards Quantum-Safe O-RAN: Experimental Evaluation of MLKEM-Based IPsec on the E2 Interface”. In: Future Internet 18.4 (Apr. 2026), p. 188. doi: 10.3390/fi18040188.

P. Kampanakis. Post-Quantum Key Exchange with ML-KEM in the Internet Key Exchange Protocol Version 2 (IKEv2). Internet-Draft draft-ietf-ipsecme-ikev2-mlkem-09. Work in Progress. Internet Engineering Task Force, July 2026. url: https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/09/.

B. Westerbaan. State of the Post-Quantum Internet in 2025. Cloudflare Blog. Accessed 25 August 2026. Oct. 2025. url: https://blog.cloudflare.com/pq-2025/.

E. C. Santos, T. A. O. D. Cordeiro, and H. de Oliveira Silva. “Performance Evaluation of Post-Quantum Cryptography in IoT: A Case Study on MQTT Over TLS Under Network Constraints”. In: 2026 14th International Symposium on Digital Forensics and Security (ISDFS). IEEE, 2026, pp. 1–6. doi: 10.1109/ISDFS69419.2026.11458974.

D. Adrian, B. Beck, D. Benjamin, and D. O’Brien. Advancing Our Amazing Bet on Asymmetric Cryptography. Chromium Blog. Accessed 25 August 2026. May 2024. url: https://blog.chromium.org/2024/05/advancing-our-amazing-bet-onasymmetric.html.

E. Ozturk, D. Zimmerman, K. Yap, M. Cornu, and T. Kantecki. Post-Quantum Cryptography: Accelerating Open Quantum Safe Library with Intel AVX-512 Keccak 1600 Implementation. Technology Guide. Last updated 4 November 2025. Intel Corporation, Nov. 2025. url: https://builders.intel.com/solutionslibrary/post-quantum-cryptography-accelerating-open-quantum-safe-librarywith-intel-avx-512-keccak-1600-implementation.

B. Han, V. Gopalakrishnan, L. Ji, and S. Lee. “Network Function Virtualization: Challenges and Opportunities for Innovations”. In: IEEE Communications Magazine 53.2 (2015), pp. 90–97. doi: 10.1109/MCOM.2015.7045396.

ETSI Industry Specification Group for Network Functions Virtualisation. Network Functions Virtualisation (NFV) Release 3; Evolution and Ecosystem; Report on Network Slicing Support with ETSI NFV Architecture Framework. ETSI Group Report ETSI GR NFV-EVE 012 V3.1.1. European Telecommunications Standards Institute, Dec. 2017. url: https://www.etsi.org/deliver/etsi_gr/NFV-EVE/001_099/012/03.01.01_60/gr_nfv-eve012v030101p.pdf.

S. Kumar. SR-IOV. NgKore Documentation. Last updated 16 February 2026; accessed 25 August 2026. May 2023. url: https://docs.ngkorefoundation.org/kernel-bypass/sriov/.

A. Banerjee, T. Reddy.K, D. Schoinianakis, T. Hollebeek, and M. Ounsworth. Post-Quantum Cryptography for Engineers. RFC 9958. RFC Editor, June 2026. doi: 10.17487/RFC9958.

J. Stenstam. Algorithm-Split DNSSEC: KSK/ZSK Algorithm Separation. Internet-Draft draft-johani-dnsop-dnssec-alg-split-02. Work in Progress. Internet Engineering Task Force, July 2026. url: https://datatracker.ietf.org/doc/draft-johanidnsop-dnssec-alg-split/02/.

OpenSSH Project. OpenSSH 10.0 Release Notes. OpenSSH Release Notes. Accessed 25 August 2026. Apr. 2025. url: https://www.openssh.org/txt/release-10.0.

J. Schaad, B. Ramsdell, and S. Turner. Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 4.0 Message Specification. RFC 8551. RFC Editor, Apr. 2019. doi: 10.17487/RFC8551.

B. Salter, A. Raine, and D. Van Geest. Use of the ML-DSA Signature Algorithm in the Cryptographic Message Syntax (CMS). RFC 9882. RFC Editor, Oct. 2025. doi: 10.17487/RFC9882.

J. Prat, M. Ounsworth, and D. Van Geest. Use of ML-KEM in the Cryptographic Message Syntax (CMS). RFC 9936. RFC Editor, Mar. 2026. doi: 10.17487/RFC9936.

Author Biographies
Abraham Cano Aguilera, Eindhoven University of Technology, The Netherlands

Abraham Cano Aguilera received his BSc in Telecommunications Technologies and Services Engineering and his MSc in Advanced Mathematics and Mathematical Engineering from Universitat Politècnica de Catalunya (UPC), Spain. He completed an industrial PhD at Eindhoven University of Technology in collaboration with NVIDIA within the QUARC project. His research focuses on applied and post-quantum cryptography, particularly lattice-based cryptography, high-speed secure communication, and the implementation and offloading of cryptographic protocols using Data Processing Units and other network accelerators.

Raphael Frantz, Eindhoven University of Technology, The Netherlands

Raphael Frantz received his BSc in Computer Science and MSc in High-Performance Visual Computing from Université de Reims Champagne-Ardenne, France. Within QUARC, his doctoral research combines academic work at Eindhoven University of Technology with research activities carried out in collaboration with NVIDIA. His research focuses on high-performance networking and programmable network accelerators, including Data Processing Units and SmartNICs, with particular interest in offloading communication and data-processing tasks from host systems.

Dimosthenis Iliadis-Apostolidis, Aalborg University, Denmark

Dimosthenis Iliadis-Apostolidis received his MEng in Electrical and Computer Engineering from Aristotle University of Thessaloniki, Greece. He conducted his doctoral research at Aalborg University within the QUARC project, including an industrial secondment with NVIDIA. His research focuses on programmable and secure data-center networking, including P4-based packet processing, Data Processing Units, network virtualization, network slicing, and the integration of post-quantum cryptography with IPsec.

José Luis Imaña, Complutense University of Madrid, Spain

José Luis Imaña received his MSc and PhD degrees in Physics from Complutense University of Madrid, Spain. He is an Associate Professor in the Department of Computer Architecture and Automation at Complutense University of Madrid. His research interests include computer arithmetic, finite-field computation, cryptographic hardware, reconfigurable architectures, and hardware implementation of post-quantum cryptography.

Sokol Kosta, Aalborg University, Denmark

Sokol Kosta received his BSc, MSc, and PhD degrees in Computer Science from Sapienza University of Rome, Italy. He is an Associate Professor in the Professor Promotion Programme at the Department of Electronic Systems, Aalborg University. He has been involved in multiple EU and national projects as PI and coordinator, having graduated 5 PhD students so far. His research has been recognized internationally with 10+ awards, including the 2024 IEEE Infocom Test of Time award. In QUARC, he is the main supervisor of two Doctoral Candidates (DCs). His research interests include edge computing,
networking, AI acceleration, mobile cloud computing, distributed systems, and cybersecurity of critical infrastructure.

Daniel Christian Lawo, Eindhoven University of Technology, The Netherlands

Daniel Christian Lawo received his BSc and MSc degrees in Electrical Engineering and Information Technology from the Technical University of Munich, Germany. His doctoral work combined research at Eindhoven University of Technology with an industrial research period at NVIDIA within the QUARC project. His research focuses on post-quantum cryptography for resilient communication systems, with particular emphasis on data-center networking, hardware offloading, and the integration of post-quantum mechanisms into protocols such as IPsec and MACsec.

Joseph Meyer, Eindhoven University of Technology, The Netherlands

Joseph Meyer received his undergraduate and graduate degrees in Electrical and Electronics Engineering from Tel Aviv University, Israel. He is an industrial doctoral researcher at Eindhoven University of Technology within the QUARC project, including an industrial secondment with NVIDIA. His research focuses on post-quantum cryptography and its acceleration on heterogeneous computing and Data Processing Unit architectures, including the offloading of post-quantum key-establishment mechanisms.

Michał Podleś, Eindhoven University of Technology, The Netherlands

Michał Podleś received his MSc in Computer Science, specializing in Artificial Intelligence and Data Analysis, from AGH University of Science and Technology in Kraków, Poland. He is a doctoral researcher at Eindhoven University of Technology within the QUARC project, including an industrial secondment with NVIDIA. His work focuses on high-performance networking and DPUs, including network acceleration, memory-system performance, and the identification of architectural bottlenecks in high-speed computing systems.

Jerónimo Sánchez García, Aalborg University, Denmark

Jerónimo Sánchez García received his BSc in Computer Science from Universidad de Almería and his MSc in High Performance Computing from Universidade da Coruña, Spain. He is a doctoral researcher at Aalborg University within the QUARC project, including an industrial secondment with NVIDIA. His research focuses on high-performance networking and communication offloading, including Data Processing Units, programmable network accelerators, and message-processing mechanisms for high-performance computing systems.

Idelfonso Tafur Monroy, Eindhoven University of Technology, The Netherlands

Idelfonso Tafur Monroy received his PhD in Electrical Engineering from Eindhoven University of Technology. He is a Full Professor in the Department of Electrical Engineering at Eindhoven University of Technology, where he leads research in quantum and terahertz systems. His research spans photonic and terahertz communication systems, integrated photonics, quantum communication, and technologies for high-capacity and secure communication infrastructures.

Juan José Vegas Olmos, NVIDIA, USA; Aalborg University, Denmark

Juan José Vegas Olmos received degrees in Telecommunications and Electronic Engineering and obtained his PhD from Eindhoven University of Technology. He is Research Program Coordinator at NVIDIA in the area of Software Architecture for networking and is also an Adjunct Professor at Aalborg University. His research and industrial activities focus on high-performance communication systems, data-center networking, network acceleration, and the architecture of emerging secure communication technologies.

How to Cite

Aguilera, A. C., Frantz, R., Iliadis-Apostolidis, D., Imaña, J. L., Kosta, S., Lawo, D. C., Meyer, J., Podleś, M., García, J. S., Monroy, I. T., & Olmos, J. J. V. (2026). New Challenges in Post-Quantum Cryptography. Aalborg University Open Publishing. https://doi.org/10.54337/aau.quarc

Share this publication

How to Cite

Aguilera, A. C., Frantz, R., Iliadis-Apostolidis, D., Imaña, J. L., Kosta, S., Lawo, D. C., Meyer, J., Podleś, M., García, J. S., Monroy, I. T., & Olmos, J. J. V. (2026). New Challenges in Post-Quantum Cryptography. Aalborg University Open Publishing. https://doi.org/10.54337/aau.quarc