Paper 2026/1938
A Post-Quantum Cryptography Recommendation System with TLS Validation for Heterogeneous Environments
Abstract
The choice of a post-quantum cryptography (PQC) algorithm for a concrete deployment is governed by device performance, network conditions, and the practical constraints of TLS stacks, factors that algorithm-centric guidance does not capture. This paper presents a recommendation system that ranks key-encapsulation and signature candidates using benchmarks measured on the target machines and a physically grounded cost model, and confirms as recommended only those candidates that pass end-to-end TLS handshake validation. In experiments on three hardware placements composed of macOS, Linux, and Raspberry Pi machines, the recommended signature algorithm at NIST security level 3 reverses with the server hardware. Handshakes whose server flight exceeds the initial congestion window incur an additional 124 ms on a 160 ms link, far more than the 44 ms attributable to the extra bytes alone. The validation gate further exposes deployment obstacles invisible to microbenchmarks: a standardized signature scheme whose certificates are issued but rejected by the TLS stack, and a wire-format incompatibility between generations of the same crypto provider.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Post-quantum cryptographyalgorithm selectionTLS handshakecost modelbenchmarkingheterogeneous computing
- Contact author(s)
-
smin0906 @ gmail com
shuraatum @ gmail com
dkajdfhd1 @ gmail com
kimhaha4420 @ gmail com
yulim4hyoung @ gmail com
hwajeong84 @ gmail com - History
- 2026-09-12: approved
- 2026-09-09: received
- See all versions
- Short URL
- https://ia.cr/2026/1938
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/1938,
author = {Min-Ho Song and Si-Woo Eum and Seung-Won Lee and Ha-Gyeong Kim and Yu-Lim Hyoung and Hwajeong Seo},
title = {A Post-Quantum Cryptography Recommendation System with {TLS} Validation for Heterogeneous Environments},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1938},
year = {2026},
url = {https://eprint.iacr.org/2026/1938}
}