Skip to content
Review Open access

Post-Quantum Cryptography Migration in Internet Protocols: A Review of ML-KEM Hybrid Key Exchange in TLS and SSH

Aug 2026 · Applied and Computational Engineering · Vol 247, pp. 207-214 · 0 citations

TL;DR

The review argues that readiness depends on protocol binding, implementation behavior, monitoring, and governance as much as on algorithm strength, and develops a deployment-readiness framework with four layers: security continuity, protocol integration, operational observability, and crypto-agility.

Abstract

Internet public-key cryptography faces long-term risk from quantum computers, especially when traffic can be collected now and decrypted later. After the NIST post-quantum cryptography standards, the deployment task has shifted from algorithm selection to protocol migration. This paper reviews ML-KEM hybrid key exchange in TLS and SSH through a standards-first narrative review and protocol comparison. It synthesizes NIST standards, RFCs and IETF drafts, experiments, measurements, and primary deployment reports. The paper develops a deployment-readiness framework with four layers: security continuity, protocol integration, operational observability, and crypto-agility. The analysis shows hybrid key exchange represents the most feasible short-term solution, as it introduces post-quantum confidentiality without discarding existing elliptic curve security guarantees. However, hybrid deployment does not provide full post-quantum security. The review argues that readiness depends on protocol binding, implementation behavior, monitoring, and governance as much as on algorithm strength. Handshake size, middlebox compatibility, implementation safety, telemetry, authentication migration, and organizational crypto-agility determine whether migration can progress without weakening current Internet security.

Read PDF

Similar papers

Review Open access Jul 2026

Post-Quantum Cryptography Migration for Enterprise Security

Large-scale quantum computers threaten the public-key cryptography that protects enterprise data, communications, and digital identity. Shor's algorithm solves integer factorization and discrete logarithms in polynomial time, which would break RSA, Diffie-Hellman, and elliptic-curve schemes once a cryptographically relevant quantum computer exists. The danger is not only future. Adversaries can record encrypted traffic today and decrypt it later, a tactic known as harvest-now-decrypt-later. In August 2024 the U.S. National Institute of Standards and Technology published its first post-quantum standards: FIPS 203 (ML-KEM, derived from CRYSTALS-Kyber), FIPS 204 (ML-DSA, from CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, from SPHINCS+). This paper presents a practical migration framework for enterprises. It reviews the quantum threat and Mosca's inequality for timing the transition, summarizes the new standards with their key and signature sizes, and proposes a five-phase roadmap built on crypto-agility: discovery and inventory, risk prioritization, agility engineering, hybrid deployment, and validation. Performance trade-offs are analyzed using documented parameter sizes and illustrative TLS handshake figures. ML-KEM-768 carries a 1,184-byte public key against 64 bytes for an elliptic-curve key, while SPHINCS+ signatures can exceed 17 kilobytes. The work does not report a real deployment. It consolidates published parameters and field guidance into an actionable plan, and it highlights open challenges in certificate sizing, hardware support, and long-lived embedded systems.

M. T V · 0 citations
Review Open access Aug 2026

Toward practical migration to post-quantum SSH: system-level design and evaluation

The migration of remote-access and industrial communication systems from classical public-key cryptography to post-quantum cryptography (PQC) requires careful evaluation at both the protocol and system levels. This paper presents PQC-E2E-CA, a system-level evaluation framework for reviewing post-quantum and hybrid cryptographic configurations in Secure Shell (SSH). The framework integrates OQS-enabled OpenSSH and OpenSSL with Linux netem network emulation, automated experiment execution, SCP integrity verification, and statistical post-processing. The evaluation separates key exchange behavior from host key authentication. Specifically, it measures ML-KEM and hybrid ML-KEM as SSH key exchange mechanisms, and ML-DSA as a host-key signature mechanism. Experiments are conducted under controlled RTT and packet-loss conditions using a gateway virtualised client-server testbed. The results show that ML-KEM and hybrid ML-KEM can be integrated into SSH without prohibitive application-level session setup overhead in the evaluated environment. Among the evaluated configurations, ML-KEM-768 demonstrates comparatively lower SSH session establishment latency at 50 ms RTT with 0% packet loss. ML-DSA-44 achieves the lowest host-key authentication latency under the same conditions and maintains relatively stable performance at 150 ms RTT with 5% packet loss. SCP throughput results for 100 MB and 200 MB transfers indicate that sustained transfer performance is mainly influenced by RTT and transport-layer dynamics using a single dominant key exchange configuration. These findings support migration toward standardized post-quantum mechanisms in SSH-based gateway and remote-access environments, provided that algorithm choice and system configuration are validated under representative workloads and network conditions.

Shahid Allah Bakhsh, Inam ul Haq, Tarek Helmy et al. · 0 citations
Preprint Aug 2026

A Hybrid Post-Quantum Encryption Architecture with Self-Hosted Key Management for SME Cloud Data Protection

Harvesting ciphertext from cloud storage needs no quantum computer; decrypting it later does. That gap is the harvest-now-decrypt-later exposure: anything protected by RSA or ECDH today that must stay secret for decades is already compromised. Small and medium-sized enterprises are least able to respond: they neither run the infrastructure on which their data sits on nor employ a cryptographer. Bespoke migration suits firms with security budgets; a managed key service relocates trust rather than removing it. The obstacle is architectural, not cryptographic. We present Quantum Cloud Guard (QCG), a software-only three-layer architecture. No prior SME-oriented system combines its three elements: client-side hybrid post-quantum encryption, self-hosted key custody with client-verifiable ML-DSA-87 signatures on served keys, and an integrated application-layer abuse-prevention gateway. Files never leave the client: each is sealed under AES-256-GCM, its key wrapped to an ML-KEM-1024 public key from the enterprise's key service. The enterprise alone administers it; it signs every key with ML-DSA-87, so a client that pinned it detects substitution. Separating key custody from data custody is the point: a provider holding both can read the data. On a 24 MHz STM32F407, ML-KEM-1024 key generation takes 40.8 ms and decapsulation 44.0 ms; on the server every post-quantum operation stays sub-millisecond, signing adding 0.24 ms per request. The service runs on a 4.49 EUR/month virtual server. Under sustained flooding, the in-process gateway Sentinel Gate rejected 98.8% of attack traffic while a legitimate client's median latency moved from 621 to 625 ms. Being single-source, this shows filtering effectiveness, not DDoS resilience.

Muhammad Shaheer Bin Junaid · 0 citations
Review Open access Jul 2026

Post-Quantum Security Frameworks for Internet of Things Systems: A Layered Narrative Review of Architectures, Protocols, Trust, and Emerging Challenges

The analysis indicates a significant prevalence of lattice-based schemes, hybrid strategies, and integrations with blockchain technology, zero-knowledge proofs, federated learning, homomorphic encryption, AI, and Zero Trust architectures, as well as key gaps remain in side-channel evaluation, migration pathways, deployment costs, and real-world validation.

Rodrigo Jara Espinoza, Yohamin Nafit Pimentel Alarcon, Angelo Taco-Jimenez et al. · 0 citations
Open access Aug 2026

Beyond encryption: post-quantum cryptography and the future of quantum-safe networks

The rapid advancement of quantum computing presents an existential threat to the mathematical foundations of modern internet security. Fault-tolerant quantum computers are projected to reach the logical qubit scale necessary to execute Shor's algorithm by 2030–2035, threatening currently deployed public-key cryptography infrastructures. We evaluate the performance metrics of integrating post-quantum cryptography (PQC), specifically the newly finalized NIST standards (FIPS 203, 204, and 205), with quantum key distribution (QKD) across communication networks. Our analysis demonstrates that while hybrid PQC-QKD models reduce long-term key compromise probabilities to near 0%, they introduce a 15% to 40% increase in bandwidth overhead during initial cryptographic handshakes. Given that enterprise-wide cryptographic migrations historically require 7–10 years, organizations face an immediate vulnerability window against “harvest now, decrypt later” adversaries. Ultimately, we propose a phased, cryptographically agile framework to achieve a Zero-Trust, Quantum-Safe network architecture within a 5-year implementation timeline.

R. Delhibabu · 0 citations
Open access Sep 2026

The intersection of post-quantum cryptography and QaaS: architecting quantum-safe cloud infrastructures

By 2030, an estimated 40% of current cloud infrastructures may be rendered vulnerable by cryptanalytically relevant quantum computers (CRQCs). This paper introduces a 4-tier security framework tailored for Quantumas-a-Service (QaaS) deployments, focusing on securing data-in-transit. Integrating 3 NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, and SLHDSA), our architecture mitigates interception threats based on Shor's algorithm. Emulation across an enterprise cloud topology demonstrates a maximum latency overhead of 17.7 milliseconds per TLS handshake under high-latency WAN conditions, ensuring high-availability operations without catastrophic fragmentation failure. The proposed model demonstrates the viability of modern latticebased cryptography for live environments and provides a structured 3-phase transition roadmap for cloud service providers (CSPs) to achieve quantum-resilience seamlessly.

Unknown authors · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.