Paper 2026/1274

Design and Performance Evaluation of Post-Quantum Authentication for Embedded Systems: A Case Study on PIV

Emmanuelle Dottax, IDEMIA Secure Transactions
Rina Zeitoun, IDEMIA Secure Transactions
Abstract

As the transition to post-quantum cryptography accelerates, security protocols must evolve to resist quantum threats while remaining practical, particularly on constrained devices where memory, bandwidth, and performance are limited. We consider the NIST Personal Identity Verification (PIV) system, where smart cards rely on digital signatures for authentication. Since post-quantum signatures introduce substantial computational and memory overhead, whereas post-quantum Key Encapsulation Mechanisms (KEMs) are generally lighter, we investigate KEM-based alternatives for authentication and assess the migration of secure messaging to post-quantum primitives. We propose post-quantum variants of the PIV authentication and secure messaging protocols and implement both signature-based and KEM-based approaches on a real smart card platform. We evaluate their computational and communication costs in a realistic embedded setting and present detailed performance metrics that enable assessing the impact of post-quantum migration across different hardware and communication configurations. Our results show that KEM-based authentication significantly reduces execution time and transmitted data compared to post-quantum signature-based designs, while KEM-based post-quantum secure messaging incurs moderate overhead compared to its classical counterpart. These findings highlight KEM-based authentication as a practical migration strategy for post-quantum secure embedded systems.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. Minor revision. SECRYPT 2026
Keywords
Post-Quantum CryptographyAuthenticationSecure ChannelProtocol DesignEmbedded DevicePIV
Contact author(s)
emmanuelle dottax @ idemia com
rina zeitoun @ idemia com
History
2026-06-19: approved
2026-06-17: received
See all versions
Short URL
https://ia.cr/2026/1274
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1274,
      author = {Emmanuelle Dottax and Rina Zeitoun},
      title = {Design and Performance Evaluation of Post-Quantum Authentication for Embedded Systems: A Case Study on {PIV}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1274},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1274}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.