<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Analysis of Problems and Prospects of Implementation of Post-Quantum Cryptographic Algorithms</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Andriy Horpenyuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ivan Opirskyy</string-name>
          <email>ivan.r.opirskyi@lpnu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Pavlo Vorobets</string-name>
          <email>pavlo.vorobets94@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Evaluation</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Described</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of Standards</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Lviv Polytechnic National University</institution>
          ,
          <addr-line>12 Stepan Bandera str., Lviv, 79000</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>39</fpage>
      <lpage>49</lpage>
      <abstract>
        <p>The paper provides an overview and analysis of the current state, problems, and prospects of post-quantum cryptography. Considered the status of the Poststandardizing post-quantum cryptography.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The concept of a quantum computer is no
longer just a theory. The battle for supremacy in
quantum technology is on among nations since it
is the most significant technology in the world [
        <xref ref-type="bibr" rid="ref1 ref2">1,
2</xref>
        ]. Technology will shorten the amount of time it
takes to compute from years to hours or even
minutes. The scientific community will greatly
benefit from the power of quantum computing. It
does, however, highlight significant cybersecurity
risks. Theoretically, an attack might be launched
against
any
cryptographic
algorithm.
      </p>
      <sec id="sec-1-1">
        <title>When</title>
        <p>practical quantum computers with
millions of
qubits capacity become available, they will be
able to decrypt almost all current public-key
cryptography systems.</p>
        <p>Modern cryptography algorithms are built on
complex mathematical functions and principles to
provide strong security and protect sensitive
information
from
unauthorized
access
and
attacks.
potential</p>
        <p>But quantum</p>
        <p>computers
to
break
many
of
the
have</p>
        <p>the
classical
cryptographic algorithms that are currently in
widespread
use.</p>
      </sec>
      <sec id="sec-1-2">
        <title>Traditional</title>
        <p>cryptographic
systems, such as</p>
        <p>RSA
and</p>
        <p>ECC, rely
on
mathematical problems that are computationally
hard to solve using classical computers. However,
quantum computers can leverage their unique
quantum properties, such as superposition and
entanglement, to
perform
certain calculations
exponentially faster than classical computers. The
vulnerability
of
classical
cryptography
to
quantum</p>
        <p>attacks arises from the fundamental
differences in the computational capabilities of
quantum
and
classical computers.</p>
        <p>Quantum
computers can perform
certain
mathematical
operations in parallel, thanks to the superposition
of qubits, which allows them to solve problems
that would take classical computers an impractical
amount of time. As a result, the development and
standardization of post-quantum cryptographic</p>
        <p>2023 Copyright for this paper by its authors.
algorithms have become imperative.
Postquantum cryptography aims to create
cryptographic systems that remain secure even in
the presence of powerful quantum computers
(Table 1). These algorithms rely on mathematical
problems that are believed to be hard for both
classical and quantum computers to solve.</p>
        <p>Post-quantum cryptography evolves and
becomes more relevant in the face of advances in
quantum computing, several challenges and
problems have emerged in the standardization of
post-quantum cryptographic algorithms. Some of
these issues include a lack of mature algorithms,
performance considerations, key size and
bandwidth, interoperability and integration,
transition period, NIST standardization process,
quantum attack timeline uncertainty, and
algorithm agility.</p>
        <p>Despite these challenges, the research and
standardization efforts in post-quantum
cryptography continue to progress, and as more
secure and efficient algorithms are developed and
tested, the deployment and adoption of
postquantum cryptographic standards are expected to
become more feasible.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Literature Review and Problem</title>
    </sec>
    <sec id="sec-3">
      <title>Statement</title>
      <p>Cryptography is an essential aspect of modern
life, providing the necessary security and trust in
our digital interactions, financial transactions,
communication, and data privacy. Its widespread
use ensures the confidentiality, integrity, and
authenticity of information in various aspects of
our daily lives.</p>
      <p>When you visit a website with HTTPS
(Hypertext Transfer Protocol Secure) in the URL,
cryptography is at work. It encrypts the data
exchanged between your web browser and the
website's server, ensuring that sensitive
information like passwords, credit card details,
and personal data are protected from unauthorized
access. Also, websites and applications use
cryptographic hash functions to store user
passwords securely. The actual password is not
stored, only a hash (irreversible output) of the
password. This way, even if the database is
compromised, passwords remain protected.</p>
      <p>Cryptography is used to secure online banking
transactions. When you log in or transfer funds
through Internet banking, encryption ensures that
your financial information remains confidential
and cannot be intercepted by malicious actors.</p>
      <p>Messaging platforms like WhatsApp, Signal,
and Telegram use end-to-end encryption. This
means that only the sender and recipient can read
the messages, ensuring privacy and preventing
eavesdropping. Email communication can be
secured using encryption methods like Pretty
Good Privacy (PGP) or Secure/Multipurpose
Internet Mail Extensions (S/MIME). These
techniques protect email content and attachments
from unauthorized access during transmission.</p>
      <p>
        We are currently on the brink of a revolution in
the field of cryptography due to the emergence of
quantum computers, which have the potential to
disrupt long-standing principles of system
security. Traditional cryptographic algorithms,
such as RSA and ECC, rely on mathematical
problems that are hard to solve using classical
computers. However, quantum computers can
efficiently solve some of these problems, such as
integer factorization and discrete logarithms,
using algorithms like Shor’s algorithm and
Grover's algorithm [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. These quantum algorithms
could potentially break many of the cryptographic
algorithms currently in use, posing a threat to the
security of numerous systems and infrastructures
that rely on these algorithms. However, the cost
and complexity of building quantum computers
on a scale that would allow them to break modern
cryptographic algorithms remain uncertain [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        Post-quantum cryptography, also known as
quantum-resistant or quantum-safe cryptography,
is an emerging field that addresses the potential
threat posed by quantum computers to current
cryptographic systems. Quantum computers have
the potential to solve certain mathematical
problems much more efficiently than classical
computers, which could render many widely used
cryptographic algorithms, such as RSA and ECC,
vulnerable to attacks [
        <xref ref-type="bibr" rid="ref5 ref6">5, 6</xref>
        ].
      </p>
      <p>The central goal of post-quantum cryptography
is to develop cryptographic methods that remain
secure against both classical and quantum attacks.
These methods are based on mathematical
problems that are believed to be hard even for
powerful quantum computers. Unlike traditional
cryptographic algorithms, which rely on the
hardness of factoring large integers or solving the
elliptic curve discrete logarithm problems,
postquantum algorithms use alternative mathematical
structures such as lattices, error-correcting codes,
multivariate polynomials, and isogenies.</p>
      <p>One of the significant challenges in
postquantum cryptography is the transition from
current cryptographic standards to
quantumresistant ones. This process requires careful
evaluation, standardization, and integration into
existing systems and protocols. Cryptographers,
researchers, and industry experts are collaborating
to develop and test these algorithms to ensure their
security and efficiency in real-world applications.</p>
      <p>Post-quantum cryptography is an
interdisciplinary field that involves mathematics,
computer science, and quantum physics. It
represents a critical area of research and
development to ensure the long-term security and
resilience of our digital communication and data
in the face of evolving computing technologies.
By embracing post-quantum cryptographic
standards, we can fortify our cryptographic
systems and stay ahead of potential threats in the
era of quantum computing.</p>
    </sec>
    <sec id="sec-4">
      <title>3. Problems of Post-Quantum</title>
    </sec>
    <sec id="sec-5">
      <title>Cryptography</title>
      <p>In recent years, the rapid development of
quantum computing has sparked growing
concerns about the security of traditional
cryptographic systems. Quantum computers have
the potential to solve certain mathematical
problems much more efficiently than classical
computers, which could render many of today's
widely used cryptographic algorithms, such as
RSA, DSA, and ECDSA. This scenario poses a
significant threat to the confidentiality, integrity,
and authenticity of sensitive information in
various sectors of our lives.</p>
      <p>
        Post-quantum cryptography, also known as
quantum-resistant or quantum-safe cryptography,
aims to address these security challenges by
designing cryptographic algorithms that remain
secure against attacks from both classical and
quantum computers. The main objective is to
develop cryptographic methods based on
mathematical problems that are believed to be
hard even for powerful quantum computers [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>The need for post-quantum cryptographic
standards is becoming increasingly urgent. While
quantum computers capable of breaking current
cryptographic systems are still in the realm of
theoretical research and large-scale quantum
computing is not yet a reality, the potential threat
is real. It is crucial to prepare in advance for the
inevitable emergence of more powerful quantum
computers.
3.1.</p>
    </sec>
    <sec id="sec-6">
      <title>Lack of Mature Algorithms</title>
      <p>Many of the proposed post-quantum
cryptographic algorithms are relatively new and
have not undergone extensive real-world testing.
The lack of a long track record for these
algorithms raises concerns about their security
and efficiency. Established cryptographic
algorithms have undergone years of cryptanalysis
and peer review, which provides a high level of
confidence in their security. In contrast, the
newness of post-quantum algorithms means that
their security might not be as thoroughly
understood. It is essential to subject these
algorithms to rigorous analysis to ensure their
resistance to both classical and quantum attacks.</p>
      <p>The lack of a long history of real-world
deployment leaves open the possibility of
unforeseen attacks. Unlike well-studied classical
algorithms, there may be unexplored
vulnerabilities that could be exploited by
adversaries. Due to their relative novelty and the
ongoing standardization process, post-quantum
cryptographic algorithms may not be readily
available in commercial products and
applications. This hinders their practical
deployment in the current cryptographic
landscape.</p>
    </sec>
    <sec id="sec-7">
      <title>3.2. Quantum Attack Timeline</title>
    </sec>
    <sec id="sec-8">
      <title>Uncertainty</title>
      <p>The timeline for the emergence of powerful
quantum computers capable of breaking
traditional cryptographic algorithms remains
uncertain. This uncertainty complicates the
decision-making process for adopting
postquantum cryptographic solutions.</p>
      <p>Quantum computers use qubits instead of bits.
Unlike classical bits, which can represent either a
0 or a 1, qubits can exist in a superposition of
states, meaning they can simultaneously represent
both 0 and 1 at the same time. In classical
computing, bits are the fundamental building
blocks used to represent and process information.
They can be in one of two states: 0 or 1. These
binary states are used to perform logical
operations and store data in classical computers.
The first quantum computer with one qubit was
created and demonstrated in 1998. Since then, we
have seen the number of qubits represented in a
quantum computer grow over time (see Table 2).
Here is a basic qubit advance timeline by year as
of this writing, based on various vendor claims.</p>
      <p>
        It is important to recognize that number of
qubits is not the sole determinant of a quantum
computer’s performance or computational power.
Having more qubits is a good have, but not all
qubits are equal, and a quantum computer’s ability
to solve something is determined by more
variables than just the sheer number of qubits [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>The quality of qubits is critical. Quantum
computers are highly sensitive to noise and errors,
and maintaining qubit coherence is challenging.
High-fidelity qubits with long coherence times are
essential for reliable quantum computations. The
arrangement and connectivity of qubits in a
quantum processor are vital. The ability to
efficiently perform multi-qubit operations and
implement quantum error correction codes
depends on qubit connectivity. Quantum
computers must employ error correction
techniques to mitigate the impact of quantum
errors that naturally occur during computation.
Quantum error correction introduces additional
qubits and computational overhead. Developing
efficient quantum algorithms and software
tailored to the hardware is vital for maximizing
quantum computing performance.</p>
      <p>
        Quantum computing is an interdisciplinary
field that involves physics, computer science,
materials science, and more, and it requires
significant advancements in hardware, software,
and algorithms to achieve practical quantum
advantage in solving complex problems.
Significant progress has already been made, but it
remains in the field of research and
experimentation [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
    </sec>
    <sec id="sec-9">
      <title>3.3. Transition Period and Standardization Process</title>
      <p>As post-quantum cryptographic standards are
being developed, there is a transitional period
where both traditional and post-quantum
algorithms need to coexist. Managing this
transition effectively without compromising
security is a significant concern. The National
Institute of Standards and Technology is leading
the effort to standardize post-quantum
cryptography. However, the process is
timeconsuming, and there are various candidate
algorithms to consider, making the selection and
standardization process challenging.</p>
      <p>
        The NIST Post-Quantum Cryptography (PQC)
Standardization Process began in December 2016
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], when NIST issued a public call for
submissions of post-quantum public-key
cryptographic algorithms. They identified five
main categories of post-quantum cryptographic
algorithms:
      </p>
      <p>
        ● Lattice-based cryptography uses lattices and
their associated mathematical properties to
provide security. A lattice is a set of points in a
multi-dimensional space that form a regular
gridlike structure. Lattice-based cryptography
leverages the hardness of certain lattice problems
to provide security against quantum attacks.
Lattice-based cryptographic algorithms seem to
be the most promising and quantum-resistant [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
● Code-based cryptography relies on
errorcorrecting codes to provide security. The security
of these schemes is based on the hardness of
decoding certain structured codes, making them
resistant to quantum attacks. Code-based
cryptography is a strong contender for
postquantum cryptography because it is thought that
this problem is computationally taxing the
complexity of the decoding solution is still hard,
although the precise complexity is a topic of
ongoing research.
      </p>
      <p>● Hash-based cryptography built upon
cryptographic hash functions. These schemes are
based on the hardness of finding collisions in the
hash function, offering a potential post-quantum
solution. Hash-based cryptography’s fundamental
benefit is that it is a commonly used,
wellresearched technique that ensures great resistance
to quantum assaults, making it a candidate for
long-term security in the post-quantum period (as
a long enough key is utilized). However,
hashingbased cryptography can also have problems. First,
if attackers find a collision, the security of the
hash function can be compromised. Second, since
conventional algorithms have exponential
complexity but are only efficient for short keys,
Grover’s algorithm can crack hash functions in
time √ (where N is the length of the key), which
can lead to increased processing time and more
memory. Hash-based signature is a set of one-time
signature schemes that use a tree data structure to
efficiently combine multiple signatures. To sign a
message, a Hash-based signature selects one of
the one-time signatures from its collection and
uses it. You should never use the same signature
twice, as this will break security.</p>
      <p>
        ● Multivariate polynormal cryptography relies
on algebraic equations with multivariate
polynomials. Security is based on the difficulty of
solving systems of multivariate polynomial
equations. These polynomials can be defined both
over the basic and over the expansion field in
certain situations. Research has shown that
solving systems of multidimensional polynomial
equations is a task that requires a minimum
amount of work. However, algebraic, differential,
and Gröbner basis attacks also affect Multivariate
polynormal cryptography. As a result,
Multivariate polynormal cryptography is
essentially not used [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>● Isogeny-based cryptography is based on the
mathematics of elliptic curves and isogenies.
These schemes rely on constructing mappings
between elliptic curves. Security is based on
supersingular isogeny problems, or finding an
isogeny mapping between two supersingular
elliptic curves with the same number of points.
This is one of the few difficult mathematical
problems that currently resist quantum computer
attacks. Isogeny-based protocols require a very
small key compared to any other post-quantum
cryptography variant but are still much larger than
conventional elliptic curve algorithms. However,
compared to lattice-based cryptography, they are
less efficient and suitable for more complex
cryptographic primitives. This cryptosystem is
relatively new and untested, therefore there may
be unforeseen flaws or weak places that attackers
can take advantage of. Furthermore, even though
isogeny-based cryptography only needs small key
sizes, the computational cost of key creation is
still quite high, which could be a drawback for
systems with limited resources.</p>
      <p>
        These categories are considered potential
candidates for quantum-resistant cryptographic
standards. A total of 82 candidates were submitted
by the November 2017 deadline [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. In Dec.
2017, NIST announced that 69 of these candidates
met both the submission requirements and the
minimum acceptability criteria and were accepted
into the first round of the standardization process.
      </p>
      <p>After careful consideration during the third
round of the NIST PQC Standardization Process,
NIST has identified four candidate algorithms for
standardization. NIST will recommend two
primary algorithms to be implemented for most
use cases: CRYSTALS-KYBER
(keyestablishment) and CRYSTALS-Dilithium
(digital signatures). In addition, the signature
schemes FALCON and SPHINCS+ will also be
standardized. The four algorithms selected for this
fourth round are BIKE, Classic McEliece, HQC,
and SIKE.</p>
      <p>It is important to stay updated with the progress
of standardization efforts, as cryptographic
standards play a critical role in ensuring the
security and resilience of digital communications
in the post-quantum era.
3.4.</p>
    </sec>
    <sec id="sec-10">
      <title>Performance Considerations</title>
      <p>
        Some post-quantum cryptographic algorithms
are computationally intensive, which can lead to
slower encryption and decryption speeds
compared to traditional cryptographic algorithms.
This performance overhead may limit their
practical adoption, especially in
resourceconstrained environments [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        The labor required to generate and validate
keys is frequently substantially more than with
classical cryptography, even if a
quantumresistant cryptographic standard has smaller key
sizes. Because of this, the NIST competition
necessitates extensive performance testing, and
participants make every effort to speed up their
algorithms. Although switching to a
postquantum algorithm is expected to reduce overall
performance even on the greatest and fastest
computers and devices, NIST will most likely
choose a post-quantum standard that has a good
performance/security trade-off. After careful
thought, a production environment or product
must switch entirely to a quantum-resistant
algorithm [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>
        The performance analysis of the algorithms is
done using the Open Quantum Safe (OQS)
project. It is a project, developing and prototyping
quantum-resistant cryptography algorithms. OQS
project provides an open-source library that
implements several post-quantum cryptographic
algorithms. The OQS library aims to facilitate the
research, development, and integration of
quantum-resistant algorithms into various
applications and systems. The performance of
post-quantum algorithms can vary significantly
depending on the specific algorithm, its
implementation, and the hardware on which it is
executed. The OQS also offers benchmarking
information for different quantum-resistant
algorithms, which is used in this paper to compare
the runtime behavior and memory usage of the
algorithms [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. The algorithms’ runtime
behavior and memory usage data are gathered
based on the algorithms’ execution on Amazon
Web Service (AWS) with a CPU model of an Intel
Xeon Platinum 8259CL CPU running at 2.5 GHz.
      </p>
      <p>
        Performance analysis of numerous
quantumsafe algorithms reveals that these algorithms
typically demand a large number of CPU cycles
for their fundamental activities, such as key
creation, encrypt/decryption, key exchange,
signing, and verifying, among others (see
Table 3). Additionally, the algorithms demand
very large public key and private key sizes.
Compared to traditional cryptographic
techniques, these approaches consume a lot of
memory at runtime. The higher CPU cycle and
memory usage is constrained to the Information
Communication Technology systems and devices.
The resource constraints can be resolved for the
systems like a laptop, desktop, or high-end server
up to some extent [
        <xref ref-type="bibr" rid="ref17 ref18">17, 18</xref>
        ]. However, it is a
challenging issue for small devices like
smartphones, sensor networks [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ], smart-grid,
IoT [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ], smart devices [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ], smart homes [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ],
etc.
      </p>
      <p>It is important to remember that post-quantum
algorithms are still being actively researched and
optimized. The performance characteristics of
these algorithms might change over time as
researchers discover more efficient
implementations and further refine their designs.</p>
      <p>When evaluating the performance of
postquantum algorithms, it is essential to consider
factors such as key size, encryption and
decryption speeds, memory requirements, and the
targeted hardware platform. Performance
tradeoffs are often made to achieve a balance between
security and efficiency, depending on the specific
application’s requirements and constraints.
3.5.</p>
    </sec>
    <sec id="sec-11">
      <title>Key Size and Bandwidth</title>
      <p>Post-quantum cryptographic algorithms
require larger key sizes compared to classical
algorithms. This can lead to increased bandwidth
requirements for secure communication and can
be problematic for devices with limited storage
and processing capabilities.</p>
      <p>When comparing the key sizes of various
postquantum cryptographic algorithms, it is essential
to understand that different algorithms have
different security levels and performance
tradeoffs. Key size is one of the factors that can affect
the security and efficiency of the cryptographic
system. Generally, larger key sizes offer higher
security, but they may also result in increased
memory and bandwidth requirements.</p>
      <p>Table 3
Performance Assessment</p>
      <p>Algorithm Type
CRYSTALS- Lattice-based</p>
      <p>KYBER
CRYSTALS- Lattice-based
Dilithium</p>
      <p>Falcon</p>
      <p>Lattice-based
SPHINCS+</p>
      <p>BIKE</p>
      <p>Hash-based</p>
      <p>Code-based
HQC</p>
      <p>Code-based</p>
      <p>Classic
McEliece</p>
      <p>SIKE</p>
      <p>Code-based
Isogeny-based</p>
      <p>Performance
Overall performance of CRYSTALS-KYBER in software, hardware, and
hybrid settings is excellent.</p>
      <p>It uses pseudorandomness and truncated storage techniques to
improve performance. The scheme does not use floating-point
arithmetic, which is an advantage. Highly efficient and relatively
simple in implementation.</p>
      <p>The verification process is fast and requires low bandwidth. It is the
best choice for some constrained protocol scenarios.</p>
      <p>Key generation and verification are much faster than signing
The performance of BIKE would be suitable for most of the
applications as confirmed by several hardware benchmarks
The bandwidth of the HQC exceeds that of BIKE, HQC's key
generation but decapsulation only requires a fraction of the
kilocycles required by BIKE. HQC is one of the top two alternate
KEMs. The overall performance of the HQC is not optimal but still, it
is acceptable.</p>
      <p>It has the smallest ciphertext among any of the NIST PQC candidates
It has relatively low communication costs. However, performance on
embedded devices may be an issue because of the time to perform a
single key encapsulation/decapsulation.</p>
      <p>Table 4 presents a comparison of
postquantum cryptographic algorithms and their
typical key sizes.</p>
      <p>Larger key sizes result in the need for more
storage space to store keys and increased
bandwidth usage for transmitting cryptographic
data. This can be problematic for devices with
limited resources, such as IoT devices and mobile
devices, where memory and bandwidth are at a
premium. Larger key sizes can lead to increased
computational overhead during encryption,
decryption, and key generation operations. This
can slow down cryptographic processes and
impact system performance, especially on devices
with limited processing power. Existing systems
and protocols may not be designed to handle
postquantum key sizes, which could create
compatibility issues when transitioning to
postquantum cryptographic solutions. Upgrading
systems to support larger keys might require
significant changes and updates. The complexity
of handling large keys in software and hardware
implementations can be challenging. Designing
efficient and secure implementations for these
algorithms might be more difficult compared to
classical cryptographic algorithms.</p>
    </sec>
    <sec id="sec-12">
      <title>3.6. Interoperability and Integration</title>
      <p>Integrating post-quantum cryptographic
algorithms into existing systems and protocols
can be complex. Ensuring seamless
interoperability between post-quantum algorithms
and existing infrastructure is a challenging task.</p>
      <p>
        The current cryptographic infrastructure of any
company will need to be upgraded significantly to
transition to post-quantum cryptography. Some of
their current IT parts can become wholly unusable
and need to be replaced. There may be a need to
redesign and alter the protocol, software, and
algorithms currently in use. Overall, the company
will incur significant budget overhead and
unavoidable complexity as a result of the
conversion process [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ].
      </p>
      <p>The majority of the prospective post-quantum
cryptography algorithms face a difficult problem
with scalability. It is challenging to demonstrate
the algorithm's difficulty on a large scale. For
instance, one of the main methods for creating
quantum-safe algorithms, lattice-based
cryptography, scales well but only provides
NTRU Encrypt
Rainbow
SPHINCS
SPHINCS+
Falcon-512
Falcon-1024
CRYSTALS-Dilithium
CRYSTALS-KYBER
BIKE
HQC
SIKE
BLISS-II
Goppa-based McEliece
RLCE
Quasi-cyclic MDPC-based
McEliece
SIDH
SIDH (compressed keys)
Lattice-based
Multivariate-based
Hash-based
Hash Signature-based
Lattice-based
Lattice-based
Lattice-based
Lattice-based
Code-based
Code-based
Isogeny-based
Lattice-based
Code-based
Code-based
Code-based
Isogeny-based
Isogeny-based</p>
    </sec>
    <sec id="sec-13">
      <title>3.7. Future of Post-Quantum</title>
    </sec>
    <sec id="sec-14">
      <title>Algorithms</title>
      <p>Cybersecurity of post-quantum algorithms is a
key characteristic that adds significance to their
development and integration into modern
information systems. The fundamental concept of
post-quantum cryptography is to design
algorithms that remain resistant to attacks from
both classical and quantum computers.</p>
      <p>The primary requirement for post-quantum
algorithms is their resistance to attacks from
potential quantum computing systems. These
algorithms are designed to remain secure even in
the presence of powerful quantum computers.
Post-quantum algorithms must also resist attacks
average-case hardness. Scalability and toughness
can be compromised. Either can be achieved, but
not both.</p>
      <p>
        This means that in the world of post-quantum
cryptography, protocol designers need to be aware
of the possibility of different trade-offs and
choose systems matching their application
scenario, taking into account how frequently
public keys are sent relative to ciphertexts or
signed messages using them and how important
computation speed is relative to bandwidth. The
choice of a post-quantum cryptographic algorithm
should be driven by a careful analysis of the
specific requirements and constraints of the
application. Balancing security, efficiency, and
resource limitations is key to successfully
integrating post-quantum cryptography into
various systems and protocols. As the field of
post-quantum cryptography continues to evolve,
more efficient and optimized algorithms may
emerge, further enhancing the possibilities for
secure and practical cryptographic solutions in the
era of quantum computing [
        <xref ref-type="bibr" rid="ref24 ref25">24, 25</xref>
        ].
from classical computing systems. This is
important since new cryptographic algorithms can
be vulnerable to attacks in the initial years after
their introduction. Post-quantum algorithms
should be designed to avoid vulnerabilities to new
attack methods, including those that exploit
quantum technologies. They should undergo
scrutiny and security analysis to ensure their
resistance to various types of attacks and
vulnerabilities. Post-quantum algorithms should
be ready for updates and adaptation since the
cryptographic landscape is constantly evolving,
and new attacks and methods may emerge over
time.
      </p>
      <p>
        In the face of the impending quantum
computing era, it is imperative for every
organization to swiftly take action. Outdated and
weakly quantum-resistant cryptographic methods
must be promptly replaced with robust
alternatives. This proactive transition to existing
quantum-resistant cryptography, along with
appropriate key sizes, should be a top priority
wherever feasible. The urgency of this shift lies in
the potential vulnerability of current
cryptographic systems to quantum attacks.
Quantum computers possess the capability to
swiftly unravel traditional encryption, rendering
sensitive data susceptible to exposure. By
embracing quantum-resistant cryptography,
organizations can fortify their defenses and ensure
the longevity of their data security [
        <xref ref-type="bibr" rid="ref26 ref27">26, 27</xref>
        ].
      </p>
      <p>
        Most early quantum-involved systems are
anticipated to adopt a hybrid approach, utilizing a
combination of both quantum and classical
technologies. This hybrid model is designed to
harness the strengths of both quantum and
classical computing to create more robust and
efficient solutions for various applications [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ].
Quantum computers, while holding the potential
for certain types of computations, are still in their
nascent stages of development and are not yet
ready to completely replace classical computers
[
        <xref ref-type="bibr" rid="ref29">29</xref>
        ]. Thus, the practical implementation of
quantum computing is likely to involve
integrating quantum capabilities into existing
classical systems to address specific tasks where
quantum advantages are prominent, such as
cryptography, optimization, and simulations.
      </p>
      <p>
        The hybrid approach offers organizations the
opportunity to harness the emerging potential of
quantum computing while maintaining
compatibility with their established classical
infrastructure. It also offers a gradual transition as
quantum technologies continue to advance and
become more applicable for broader usage. As the
quantum computing field progresses and matures,
it is expected that the integration of quantum and
classical technologies will become more seamless
and sophisticated, leading to the realization of
more capable and efficient quantum-involved
systems [
        <xref ref-type="bibr" rid="ref30 ref31 ref32">30–32</xref>
        ].
      </p>
      <p>Fully quantum solutions refer to a future state
where quantum computing technologies are not
only fully developed but also integrated into
various aspects of computing, cryptography, and
problem-solving. Quantum-resistant
cryptography will eliminate most of the risk from
quantum cryptographic attacks, but
quantumbased cryptography and devices are the ultimate
protection.</p>
    </sec>
    <sec id="sec-15">
      <title>4. Conclusion</title>
      <p>Breaking current cryptographic algorithms
using a quantum computer does indeed require a
large-scale quantum computer with a significant
number of qubits. The number of qubits needed to
break specific algorithms depends on the
algorithm's security strength and the chosen
quantum attack method. However, the
exponential growth in quantum computer
technology’s development shows that the storm is
approaching very fast. The migration to
postquantum cryptographic algorithms is essential to
ensure the long-term security of our digital
infrastructure in the face of potential future
quantum computing advancements. The transition
to post-quantum cryptographic algorithms is a
complex process that requires careful evaluation,
standardization, and implementation.
Cryptographers, researchers, and industry experts are
working together to develop and test these
algorithms to ensure their security and efficiency
in real-world applications. While the timeline for
the widespread deployment of large-scale
quantum computers remains uncertain, the
migration to post-quantum cryptographic
algorithms is a prudent step to safeguard our
digital security in the era of quantum computing.</p>
      <p>Post-quantum cryptography brings significant
changes to the field of cryptography and security,
but it also opens up new opportunities for ensuring
the resilience of digital infrastructure in the face
of the growing threat of quantum computers.</p>
    </sec>
    <sec id="sec-16">
      <title>5. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          , et al.,
          <article-title>Implementation of Active Cybersecurity Education in Ukrainian Higher School</article-title>
          , Information Technology for Education,
          <source>Science, and Technics</source>
          , vol.
          <volume>178</volume>
          (
          <year>2023</year>
          )
          <fpage>533</fpage>
          -
          <lpage>551</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>031</fpage>
          - 35467-0_
          <fpage>32</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <article-title>Implementation of Active Learning in the Master's Program on Cybersecurity, Advances in Computer Science for Engineering and Education II, vol</article-title>
          .
          <volume>938</volume>
          (
          <year>2020</year>
          )
          <fpage>610</fpage>
          -
          <lpage>624</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -16621-2_
          <fpage>57</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>L. K.</given-names>
            <surname>Grover</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Fast</given-names>
            <surname>Quantum</surname>
          </string-name>
          <article-title>Mechanical Algorithm for Database Search</article-title>
          ,
          <source>in 28th Annual ACM Symposium on Theory of Computing</source>
          (
          <year>1996</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>S.</given-names>
            <surname>Yevseiev</surname>
          </string-name>
          , et al.,
          <source>Development of Niederreiter Hybrid Crypto-Code Structure on Flawed Codes, Eastern-European Journal of Enterprise Technologies. Information and Controlling System</source>
          <volume>1</volume>
          ,
          <issue>9</issue>
          (
          <issue>97</issue>
          ) (
          <year>2019</year>
          ) pp.
          <fpage>27</fpage>
          -
          <lpage>38</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2019</year>
          .156620
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sahun</surname>
          </string-name>
          , et al.,
          <article-title>Devising a Method for Improving Crypto Resistance of the Symmetric Block Cryptosystem RC5 using Nonlinear Shift Functions</article-title>
          ,
          <source>Eastern-European J. of Enterprise Tech</source>
          .
          <volume>5</volume>
          (
          <issue>113</issue>
          ) (
          <year>2021</year>
          )
          <fpage>17</fpage>
          -
          <lpage>29</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2021</year>
          .240344
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>I.</given-names>
            <surname>Opirskyy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Sovyn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Mykhailova</surname>
          </string-name>
          ,
          <article-title>Heuristic Method of Finding Bitsliceddescription of Derivative Cryptographic Sbox</article-title>
          ,
          <source>in IEEE 16th Int. Conf. on Advanced Trends in Radioelectronics, Telecommun. and Computer Engineering</source>
          (
          <year>2022</year>
          )
          <fpage>104</fpage>
          -
          <lpage>109</lpage>
          . doi:
          <volume>10</volume>
          .1109/TCSET55632.
          <year>2022</year>
          .9766883
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>D. J.</given-names>
            <surname>Bernstein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Buchmann</surname>
          </string-name>
          , E. Dahmen, Code-based
          <string-name>
            <surname>Cryptography</surname>
          </string-name>
          (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>R. A.</given-names>
            <surname>Grimes</surname>
          </string-name>
          , Cryptography
          <string-name>
            <surname>Apocalypse</surname>
          </string-name>
          (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>L.</given-names>
            <surname>Chen</surname>
          </string-name>
          , et al.,
          <source>Report on Post-Quantum Cryptography, NIST Publications</source>
          (
          <year>2016</year>
          ). doi:
          <volume>10</volume>
          .6028/NIST.IR.
          <volume>8105</volume>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>G.</given-names>
            <surname>Alagic</surname>
          </string-name>
          , et al.,
          <source>Status Report on the Second Round of the NIST Post-Quantum Cryptography Standardization Process, NIST Publications</source>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .6028/NIST.IR.
          <volume>8309</volume>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>D. J.</given-names>
            <surname>Bernstein</surname>
          </string-name>
          .
          <article-title>Visualizing Size-Security Tradeoffs for Lattice-based Encryption, IACR Cryptol</article-title>
          .
          <source>ePrint Arch</source>
          .
          <article-title>(</article-title>
          <year>2019</year>
          )
          <fpage>655</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>A.</given-names>
            <surname>Casanova</surname>
          </string-name>
          , et al.,
          <string-name>
            <given-names>A Great</given-names>
            <surname>Multivariate Short Signature</surname>
          </string-name>
          , Submission to NIST (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>G.</given-names>
            <surname>Alagic</surname>
          </string-name>
          , et al.,
          <source>Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process, NIST Publications</source>
          (
          <year>2022</year>
          ). doi:
          <volume>10</volume>
          .6028/NIST.IR.
          <volume>8413</volume>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>M.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <article-title>Post-Quantum Cryptography Algorithm's Standardization and Performance Analysis</article-title>
          .
          <source>Array</source>
          <volume>15</volume>
          (
          <year>2022</year>
          )
          <article-title>100242</article-title>
          . doi:
          <volume>10</volume>
          .1016/j.array.
          <year>2022</year>
          .100242
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>M.</given-names>
            <surname>Raavi</surname>
          </string-name>
          , et al.,
          <article-title>Security Comparisons and Performance Analyses of Post-Quantum Signature Algorithms</article-title>
          , in Applied Cryptography and Network
          <string-name>
            <surname>Security</surname>
          </string-name>
          (
          <year>2021</year>
          )
          <fpage>424</fpage>
          -
          <lpage>447</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -78375-4_
          <fpage>17</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>U.</given-names>
            <surname>Banerjee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Das</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. P.</given-names>
            <surname>Chandrakasan</surname>
          </string-name>
          ,
          <article-title>Accelerating Post-Quantum Cryptography using an Energy-Efficient TLS CryptoProcessor</article-title>
          , in
          <source>2020 IEEE International Symposium on Circuits and Systems</source>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .1109/iscas45731.
          <year>2020</year>
          .9180550
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>F</given-names>
            <surname>Borges</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. R.</given-names>
            <surname>Reis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Pereira</surname>
          </string-name>
          ,
          <article-title>A Comparison of Security and Its Performance for Key Agreements in post-Quantum Cryptography</article-title>
          ,
          <source>IEEE Access 8</source>
          (
          <year>2020</year>
          )
          <fpage>142413</fpage>
          -
          <lpage>142422</lpage>
          . doi:
          <volume>10</volume>
          .1109/access.
          <year>2020</year>
          .3013250
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>V.</given-names>
            <surname>Pastushenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kronberg</surname>
          </string-name>
          ,
          <article-title>Improving the Performance of Quantum Cryptography by Using the Encryption of the Error Correction Data</article-title>
          ,
          <source>Entropy</source>
          <volume>25</volume>
          (
          <year>2023</year>
          )
          <article-title>956</article-title>
          . doi:
          <volume>10</volume>
          .3390/e25060956
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>19</surname>
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Sokolov</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Skladannyi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <string-name>
            <surname>Hulak</surname>
          </string-name>
          ,
          <article-title>Stability Verification of Self-Organized Wireless Networks with Block Encryption</article-title>
          ,
          <source>in: 5th International Workshop on Computer Modeling and Intelligent Systems</source>
          , vol.
          <volume>3137</volume>
          (
          <year>2022</year>
          )
          <fpage>227</fpage>
          -
          <lpage>237</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <article-title>Decentralized Access Demarcation System Construction in Situational Center Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II</source>
          , vol.
          <volume>3188</volume>
          , no.
          <issue>2</issue>
          (
          <year>2022</year>
          )
          <fpage>197</fpage>
          -
          <lpage>206</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <source>Formation of Dependability and Cyber Protection Model in Information Systems of Situational Center, in: Workshop on Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>107</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>R.</given-names>
            <surname>Asif</surname>
          </string-name>
          ,
          <article-title>Post-Quantum Cryptosystems for Internet-of-Things: a Survey on Latticebased Algorithms</article-title>
          , IoT
          <volume>2</volume>
          (
          <issue>1</issue>
          ) (
          <year>2021</year>
          )
          <fpage>71</fpage>
          -
          <lpage>91</lpage>
          . doi:
          <volume>10</volume>
          .3390/iot2010005
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>M.</given-names>
            <surname>Baldi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Santini</surname>
          </string-name>
          , G. Cancellieri,
          <article-title>PostQuantum Cryptography based on Codes: State of the Art and Open Challenges</article-title>
          , in AEIT International Annual Conference (
          <year>2017</year>
          ). doi:
          <volume>10</volume>
          .23919/aeit.
          <year>2017</year>
          .8240549
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>P.</given-names>
            <surname>Wallden</surname>
          </string-name>
          , E. Kashefi,
          <article-title>Cyber Security in the Quantum Era (</article-title>
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>D.</given-names>
            <surname>Bellizia</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Post-Quantum</surname>
            <given-names>Cryptography</given-names>
          </string-name>
          :
          <article-title>Challenges and Opportunities for Robust and Secure HW Design</article-title>
          ,
          <source>in IEEE International Symposium on Defect and fault tolerance in VLSI and Nanotechnology Systems (DFT)</source>
          (
          <year>2021</year>
          )
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1109/DFT52944.
          <year>2021</year>
          .9568301
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>W.</given-names>
            <surname>Buchanan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Woodward</surname>
          </string-name>
          ,
          <source>Will Quantum Computers Be the End of Public Key Encryption? Journal of Cyber Security Technology</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ) (
          <year>2016</year>
          )
          <fpage>1</fpage>
          -
          <lpage>22</lpage>
          . doi:
          <volume>10</volume>
          .1080/23742917.
          <year>2016</year>
          .1226650
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>L.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <source>Cryptography Standards in Quantum Time: New Wine in an Old Wineskin? IEEE Security &amp; Privacy</source>
          <volume>15</volume>
          (
          <issue>4</issue>
          ) (
          <year>2017</year>
          )
          <fpage>51</fpage>
          -
          <lpage>57</lpage>
          . doi:
          <volume>10</volume>
          .1109/MSP.
          <year>2017</year>
          . 3151339
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>C.</given-names>
            <surname>Portmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Renner</surname>
          </string-name>
          ,
          <source>Security in Quantum Cryptography</source>
          <volume>94</volume>
          (
          <year>2022</year>
          )
          <article-title>025008</article-title>
          . doi:
          <volume>10</volume>
          .1103/RevModPhys.94.025008
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>W.</given-names>
            <surname>Barker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Polk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Souppaya</surname>
          </string-name>
          ,
          <article-title>Getting Ready for Post-Quantum Cryptography: Exploring Challenges Associated with Adopting and using Post-Quantum Cryptographic Algorithms</article-title>
          .
          <source>NIST Cybersecurity White Paper</source>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .6028/NIST.CSWP.
          <volume>04282021</volume>
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>C.</given-names>
            <surname>Bernhardt</surname>
          </string-name>
          , Quantum Computing for Everyone. Cambridge, MIT Press (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>P.</given-names>
            <surname>Hauke</surname>
          </string-name>
          , et al.,
          <source>Perspectives of Quantum Annealing: Methods and Implementations, Reports on Progress in Physics</source>
          <volume>83</volume>
          (
          <issue>5</issue>
          ) (
          <year>2020</year>
          )
          <fpage>054401</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>A.</given-names>
            <surname>Maitra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Samuel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Sinha</surname>
          </string-name>
          ,
          <source>Likelihood Theory in a Quantum World: Tests with Quantum Coins and Computers, Pramana J Phys</source>
          <volume>94</volume>
          (
          <year>2019</year>
          )
          <article-title>57</article-title>
          . doi:
          <volume>10</volume>
          .1007/s12043- 020-1926-9
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>