Implementing quantum-safe cryptography into network infrastructure

Main Article Content

Akbayan Bekarystankyzy
Amir Zhailin

Abstract

As the era of quantum computing approaches, the fundamental cryptographic primitives securing global communications face a paradigm shift. With the National Institute of Standards and Technology (NIST) finalizing new standards, the industry must urgently address the vulnerabilities of legacy systems. The imminent advent of CRQCs (Cryptographically Relevant Quantum Computers) poses an existential threat to the Public Key Infrastructure (PKI) underpinning the global digital economy. Classical algorithms such as RSA and ECC (Elliptic Curve Cryptography) are vulnerable to polynomial-time cryptanalysis via Shor’s algorithm. This study investigates the HNDL (Harvest Now, Decrypt Later) threat model and evaluates the resilience of NIST-standardized PQC (Post-Quantum Cryptography) algorithms: ML-KEM and ML-DSA. Utilizing a high-performance Fortinet networking environment, we experimentally validate that "Hybrid Mode" IPsec VPNs can achieve quantum resistance with negligible performance degradation, offering a viable migration path for enterprise infrastructure. Specifically, we benchmark the trade-offs between PQC’s larger key sizes and network latency, demonstrating that the overhead remains within acceptable operational thresholds. Implementing hybrid protocols provides a critical transition mechanism, allowing organizations to secure long-term data confidentiality against retrospective decryption while preserving interoperability with legacy systems.


Google Scholar

CrossRef

OUCI

Scilit

WorldCat

Index Copernicus

Semantic Scholar


Article Details

How to Cite
Bekarystankyzy, A., & Zhailin, A. (2025). Implementing quantum-safe cryptography into network infrastructure. Scientific Collection «InterConf+», (64(276), 210–218. https://doi.org/10.51582/interconf.19-20.12.2025.020
Author Biographies

Akbayan Bekarystankyzy, Narxoz University; Republic of Kazakhstan

PhD, Associate Professor, School of Digital Technologies

Amir Zhailin, Narxoz University; Republic of Kazakhstan

2nd course Master’s Student

References

Shor P. Algorithms for quantum computation: discrete logarithms and factoring // Proceedings 35th Annual Symposium on Foundations of Computer Science. Santa Fe, NM, USA: IEEE, 1994. P. 124–134. DOI: https://doi.org/10.1109/SFCS.1994.365700 DOI: https://doi.org/10.1109/SFCS.1994.365700

Module-Lattice-Based Key-Encapsulation Mechanism Standard: FIPS 203 / National Institute of Standards and Technology. Gaithersburg, MD, 2024. DOI: https://doi.org/10.6028/NIST.FIPS.203. DOI: https://doi.org/10.6028/NIST.FIPS.203

Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2) : RFC 9370 / D. Tjhai et al. // Internet Engineering Task Force. 2023. May. DOI: https://doi.org/10.17487/RFC9370 DOI: https://doi.org/10.17487/RFC9370

Enhancing Security with Post-Quantum Cryptography for IPsec Key Exchange // FortiOS 7.6.0 Administration Guide. Sunnyvale, CA: Fortinet, Inc., 2025. URL: https://docs.fortinet.com/document/fortigate/7.6.0/new-features/229631/enhancing-security-with-post-quantum-cryptography-for-ipsec-key-exchange-7-6-1

Mosca M. Cybersecurity in an Era with Quantum Computers: Will We Be Ready? // IEEE Security & Privacy. 2018. Vol. 16, no. 5. P. 38–41. DOI: https://doi.org/10.1109/MSP.2018.3761723 DOI: https://doi.org/10.1109/MSP.2018.3761723