Post-Quantum Cryptography (PQC) and Migration Strategies for Enterprise IT Infrastructure: Standards, Protocol Benchmarks, and Crypto-Agility
Abstract—The advent of fault-tolerant Cryptanalytically Relevant Quantum Computers (CRQCs) presents an existential threat to modern information security. Shor's polynomial-time quantum algorithm renders widely deployed public-key cryptographic primitives—including RSA, Diffie-Hellman (DH), and Elliptic Curve Cryptography (ECDH/ECDSA)—completely vulnerable to private key derivation. Furthermore, 'Harvest Now, Decrypt Later' (HNDL) adversarial campaigns actively intercept and store encrypted enterprise telemetry today, anticipating future quantum decryption capabilities. In response, the National Institute of Standards and Technology (NIST) finalized its primary Post-Quantum Cryptography (PQC) standards in FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). However, transitioning complex enterprise IT ecosystems to quantum-resistant primitives introduces severe architectural and computational disruptions: public key and signature sizes increase by several orders of magnitude, cryptographic handshake latencies escalate, network packets experience Maximum Transmission Unit (MTU) fragmentation, and legacy Hardware Security Modules (HSMs) lack microarchitectural support for lattice-based polynomial arithmetic. This paper provides an exhaustive, mathematically grounded technical survey and architectural roadmap for enterprise PQC migration. We formalize the Module Learning with Errors (M-LWE) and Module Short Integer Solution (M-SIS) hardness foundations, evaluate hybrid classical/post-quantum cryptographic transition models across standard transport protocols (TLS 1.3, IKEv2/IPsec, SSH), and formulate an enterprise Crypto-Agility Maturity Model. Furthermore, we construct an empirical enterprise testbed measuring throughput, connection establishment latency, memory footprints, and packet fragmentation across legacy and quantum-resistant suites. Our results show that while ML-KEM-768 achieves microsecond-level encapsulation, its 1,088-byte ciphertext expands TLS ClientHello payloads into multiple TCP segments under constrained networks. Finally, we establish open research directions in post-quantum identity federations, stateful hash signature tracking, and hardware-accelerated polynomial arithmetic. Index Terms—Post-Quantum Cryptography (PQC), FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), Crypto-Agility, TLS 1.3, Lattice-Based Cryptography, Harvest Now Decrypt Later, Hardware Security Modules (HSM), Enterprise Migration.
Authors
- Tanishk Sharma
- Yash Prashar (ORCID: https://orcid.org/0000-0001-7857-2939)
- Ashok Kajla
- Ram Babu Buri
- Dr. Vishal Shrivastava
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-09
- DOI
- https://doi.org/10.5281/zenodo.23260338
- Primary Topic
- Cryptography and Data Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00