<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>" in IEEE
Internet of Things Journal</journal-title>
      </journal-title-group>
      <issn pub-type="ppub">2542-6605</issn>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.1109/JIOT.2024.3410702</article-id>
      <title-group>
        <article-title>Cryptographic defense against quantum computer attacks: A scoping review</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vullnet Gërvalla</string-name>
          <email>vullnet.gervalla@student.uni-pr.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eliot Bytyçi</string-name>
          <email>eliot.bytyci@uni-pr.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Prishtina</institution>
          ,
          <addr-line>Avenue Mother Teresa, No-5, 10000, Prishtinë</addr-line>
          ,
          <country>Republic of Kosova</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2024</year>
      </pub-date>
      <volume>25</volume>
      <issue>18</issue>
      <fpage>345</fpage>
      <lpage>358</lpage>
      <abstract>
        <p>With the advancement of quantum computing, traditional cryptography algorithms are becoming more vulnerable to attacks. As a result, researchers and industries are exploring new methods to withstand those possible attacks in the future. Thus, we conducted a scoping review on one of cybersecurity's most pressing challenges: keeping our data safe from quantum computing attacks. The survey focuses more on the studies with realistic implementation chances that are tested or proven to work, published between 2020 and 2024, identified through online databases: IEEE Xplore, Springer Link, ACM Digital Library, and ScienceDirect. From our perspective, based on the survey, there are two main paths to addressing the issue: quantum key distribution and post-quantum algorithms. Moreover, selected studies agree that implementing these new solutions isn't cheap, but complete security failure is far more expensive. Of course, the solutions have limitations, most notably, that these solutions can't be fully tested against real quantum computers yet since they're still being developed. But that doesn't mean that we need to wait for quantum computing to be the norm, before we start thinking of ways to defend against them. Furthermore, there are several tested solutions that believe that they are ready for implementation now, especially in critical areas like finance and healthcare.</p>
      </abstract>
      <kwd-group>
        <kwd>quantum cryptography</kwd>
        <kwd>quantum computer</kwd>
        <kwd>1post-quantum</kwd>
        <kwd>quantum key distribution</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The emergence of practical quantum computing threatens to undermine the foundational pillars of
cryptographic security. Classical public-key encryption schemes, such as Rivest-Shamir-Adleman
(RSA) and elliptic-curve cryptography (ECC), that rely on
mathematical problems, prime
factorization and discrete logarithms, respectively, are believed to be unbreakable for classical
computers. However, with the development of large-scale quantum computers, algorithms like
Shor’s [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] promise the efficient factorization of large integers, rendering classical keys vulnerable
and compromising a multitude of secure communication protocols. As a result, the cryptographic
community has accelerated the pursuit of quantum-resistant, or post-quantum [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], cryptographic
schemes that can withstand the capabilities of a quantum adversary.
      </p>
      <p>
        In parallel to post-quantum cryptography (PQC), quantum key distribution (QKD) systems offer
another complementary approach for secure communication in a quantum world. QKD leverages
fundamental quantum mechanical properties, such as quantum entanglement, to enable secure
distribution of symmetric keys with theoretically unbreakable security guarantees [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. However,
despite its promise, QKD faces challenges in terms of infrastructure, cost, and integration with
existing systems. Meanwhile, PQC solutions, ranging from lattice-based, hash-based, and code-based
cryptographic algorithms, are rapidly advancing toward standardization and practical deployment.
Organizations like the U.S. National Institute of Standards and Technology (NIST) are leading the
efforts to finalize post-quantum encryption and signature standards [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>This scoping review examines the development, testing and real-world implementation of both
QKD and PQC solutions. While the theoretical security properties of many proposed algorithms are
well-documented, their practical readiness - particularly in terms of cost implications and the
challenges of migrating existing infrastructures, remains underexplored. Indeed, the shift to
quantum-resistant security is not merely a matter of selecting a new algorithm, it involves
assessment of performance overhead, compatibility with legacy systems, and cost-effectiveness. For
organizations managing sensitive data that must remain secure for decades, the urgency of this
transition cannot be overstated.</p>
      <p>
        While a growing body of literature explores the theoretical foundation of post-quantum
cryptography and quantum key distribution, not all studies equally address the feasibility of
nearterm deployment. Many solutions have been conceptually validated, but their practicality in
largescale, latency-sensitive networks remains underexamined. Additionally, understanding the cost of
integrating quantum resistant measures is critical, as the financial overhead can pose significant
barriers to adoption. Recent years have seen several research prototypes, and the development of
hybrid solutions, combining classical and quantum-resistant methods [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. By examining these works
systematically, we aim to bridge the gap between theory and practice and identify which solutions
are ready for implementation, what their associated costs might be, and how prepared various
industries are to integrate them.
      </p>
      <p>Having said that, this review is structured around these primary objectives:
1. Identify and characterize recent quantum-resistant cryptographic solutions: We
focus on solutions published from 2022 onwards, including QKD implementations and
various classes of PQC algorithms. Although the range of PQC schemes is broad, particular
emphasis is placed on lattice-based cryptography, as this category is well-represented in
current research and is considered a leading candidate for standardization.
2. Assess cost and real-world readiness: Beyond pure cryptographic strength, this review
evaluates the economic and engineering challenges associated with these quantum-resilient
measures. We examine studies that address increased resource consumption, latency or
bandwidth overhead, necessary hardware modifications, and cost estimates. This includes
investigations that quantify the added expense of integrating quantum-safe solutions into
critical infrastructures.
3. Analyze current implementation challenges and potential solutions: This review
highlights the technical hurdles, design complexities, migration roadmaps, and regulatory or
policy considerations that influence the feasibility of adopting quantum-safe measures.
Special attention is given to studies that present frameworks, guidelines, or case studies
illustrating how organizations can transition their security infrastructures efficiently.</p>
      <p>In undertaking this analysis, we offer a more grounded perspective, countering overly theoretical
optimism or undue pessimism, and instead providing a balanced, evidence-based overview of where
we stand today in our preparedness for the quantum era.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Methodology</title>
      <p>For this scoping review we followed the Arksey &amp; O’Malley five‐stage scoping review process:
identifying the research questions, identifying relevant studies, study selection, charting the data,
and finally collating, summarizing and reporting results. Having laid out the research questions and
aims of this review above, the following sections outline the information sources, screening and
selection procedures, charting the data and risk of bias.</p>
      <sec id="sec-2-1">
        <title>2.1. Identifying Relevant Studies</title>
        <p>We included studies meeting the following criteria:





</p>
        <p>Population and Context: Studies focusing on cryptographic schemes designed to be secure
against quantum attacks, including both quantum key distribution (QKD) and post-quantum
cryptographic (PQC) algorithms. These studies addressed the threat posed by quantum
computers to classical cryptographic infrastructures.</p>
        <p>Intervention and Phenomenon of Interest: We targeted research presenting or
evaluating cryptographic solutions, frameworks, protocols, or proofs-of-concept related to
quantum-safe security. This encompassed:
o Post-quantum algorithms under consideration for standardization (e.g., lattice-based
cryptography).
o Quantum key distribution (QKD) systems or protocols demonstrating real-world or
testbed implementations.</p>
        <p>o Hybrid solutions combining classical and quantum-safe techniques.</p>
        <p>Outcomes of Interest: Primary outcomes included considerations of security against
quantum attacks, algorithmic complexity, and resistance to quantum-based cryptanalysis.
Secondary outcomes included implementation cost estimates, performance overhead (e.g.,
increases in latency, bandwidth consumption, or computational resources), and readiness for
large-scale deployment. We focused on indicators that reflect how close the described
solutions are to practical implementation, rather than purely theoretical security claims.
Timeframe and Language: The search was limited to studies published between 2022 and
the time of the review, end of 2024, ensuring the inclusion of the most recent advancements
and practical demonstrations. Only open-access studies in English were considered to
maintain consistency and ensure access to complete texts.</p>
        <p>Exclusion Criteria: We excluded studies that:
o Addressed quantum cryptographic topics unrelated to secure key exchange or digital
signature schemes (e.g. non-cryptographic quantum computation research).
o Focused solely on quantum hardware aspects without direct cryptographic
relevance.
o Fell outside of the thematic scope of quantum-safe cryptography defence, such as
studies focusing only on classical cryptographic methods.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Information sources and search strategy</title>
        <p>We conducted the literature search across four major scholarly databases well-regarded in the fields
of computing and cryptography: IEEE Xplore, ACM Digital Library, Springer Link, and Science
Direct. These databases were selected for their broad coverage of cryptographic research, established
peer-review standards, and wide inclusion of reputable conference proceedings and journal articles.</p>
        <p>Search Queries and Filters: We limited the search to English-language, open-access
articles published from 2022 to the end of 2024. The search terms used in all databases
included “cryptography” and “quantum” in the title field. By requiring these terms in the
title, we aimed to retrieve studies that placed quantum-safe cryptography or
quantumrelated cryptographic defenses as a primary focus. Each database’s filtering tools were
utilized to restrict by publication year (2022–2024) and open-access availability where
possible.</p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3. Study selection process</title>
        <p>The study followed a multi-stage selection process:
1. Initial Retrieval: More than one hundred papers were retrieved by combining the results
from the four selected databases.
2. Title-Based Screening: From the initial set of about one hundred papers, we examined the
titles for relevance. We included only those titles that explicitly suggested a focus on
quantum-related cryptography (e.g., mention of “post-quantum,” “quantum key
distribution,” “quantum-safe,” or “quantum cryptanalysis”) and the defense mechanisms or
migrations associated with them. Titles that were too broad, unclear, or related to quantum
computing but not cryptography were excluded. This step narrowed the pool down to
approximately 30 studies.
3. Abstract Review: Next, the abstracts of these 30 studies were thoroughly read. Abstracts
needed to demonstrate a clear emphasis on practical or semi-practical implementation
aspects of post-quantum or quantum-safe cryptographic solutions. Abstracts that mentioned
cost analysis, performance overhead, or other readiness indicators were favored. Those that
focused solely on theoretical aspects without any connection to practical deployment
scenarios were excluded. After this screening, 20 studies were deemed suitable for full
inclusion.</p>
      </sec>
      <sec id="sec-2-4">
        <title>2.4. Charting the Data</title>
        <p>Data extraction for each included paper was guided by a structured approach, where the following
were gathered:





</p>
        <p>Bibliographic Information: Title, authors, year of publication, and publication venue
(journal or conference proceedings).</p>
        <p>Type of Solution: Whether the study focused on QKD, lattice-based PQC algorithms,
codebased algorithms, hybrid approaches, or general frameworks for migrating to quantum-safe
cryptography.</p>
        <p>Implementation Context: Any mention of testbeds, pilot deployments, or real-world
networks. If implementation was purely theoretical or simulated, we noted this distinction.
Cost and Overhead: Information regarding additional computational, hardware, or
financial costs introduced by quantum-safe solutions. Studies that provided numerical or
qualitative assessments of cost, energy consumption, required infrastructure changes, and
staffing or training needs were highlighted.</p>
        <p>Performance Metrics: Details on cryptographic performance such as key generation and
exchange times, encryption/decryption speed, bandwidth consumption, memory overhead,
and latency factors.</p>
        <p>Readiness and Feasibility: Qualitative descriptors of how close these solutions are to
practical deployment. Particular attention was paid to studies that discussed timelines,
migration strategies, interoperability with existing systems, and industry or policy
guidance.</p>
      </sec>
      <sec id="sec-2-5">
        <title>2.5. Risk of bias and quality assessment</title>
        <p>Due to the relatively recent and highly technical nature of the field, we did not apply a traditional
risk of bias tool often used in other sciences scoping reviews. Instead, we considered indicators of
reliability and practical significance as a proxy for quality assessment. For example, we gave greater
weight to studies that included some form of empirical testing, performance benchmarks, or cost
analysis rather than those offering purely speculative or theoretical results. Studies that presented
reproducible experiments, open-source code, or alignment with recognized standardization bodies
(e.g., referencing the NIST Post-Quantum Cryptography process) were considered more robust.</p>
        <p>While this is not a standard bias assessment tool, it aligns with the pragmatic aims of this review.
The logic here is that a “proven to work” or “tested” claim suggests at least some level of verification
against real or simulated conditions, reducing the likelihood that conclusions are based solely on
speculation. Thus, studies presenting empirical or semi-empirical data and referencing ongoing
standardization efforts were deemed to be at lower risk of bias in terms of overstating their practical
readiness.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Results</title>
      <p>
        The search and selection process identified 20 studies, from which [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] describes one of the earliest
quantum algorithms for breaking classical cryptography and [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] contributed to defining the quantum
cryptography terminology used in this review. The remaining 18 studies each contributed to
different aspects of quantum-safe cryptography.
      </p>
      <p>
        The studies examined various approaches to creating secure systems in the face of quantum
computing threats. For example, authors in [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] combined QKD and PQC to create a hybrid
framework tested under simulated conditions. While other [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] developed a three-key hybrid system
combining classical and quantum-safe algorithms, implemented on Field-programmable Gate Array
(FPGA) platforms. In the IoT context, study [7] integrated blockchain technology with lightweight
cryptographic protocols and QKD to secure resource-constrained devices. These studies addressed
different aspects of quantum-safe cryptography, from theoretical innovations to practical
deployment challenges.
      </p>
      <p>
        The studies varied in their level of empirical testing and practical application. For instance,
authors in [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] provided real-world validation of its hybrid system for securing 5G networks, reducing
its bias risk. On the other hand, study [8] offered mostly theoretical analysis without practical
validation, making it more prone to bias. Studies that included real-world testing or detailed
implementation strategies generally provided stronger and more reliable evidence.
      </p>
      <sec id="sec-3-1">
        <title>3.1. Result analysis</title>
        <p>
          Individual studies explored a variety of themes and methodologies. For instance, authors in [9]
highlighted advancements in photon-source technologies to improve QKD scalability, while others
optimized hardware for lattice-based PQC, demonstrating improved efficiency for constrained
devices [10]. Additionally, in a case the potential role of AI in enhancing QKD systems, offering
innovative but untested proposals for dynamic optimizations, was examined [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ].
        </p>
        <p>The synthesis of the studies identified three primary application contexts:



critical infrastructures and networks,
IoT systems, and
algorithm/hardware optimization.</p>
        <p>Each application context was further grouped based on the cryptographic approach (into hybrid
systems, QKD, and PQC). Studies that did not fit into these categories are also discussed to ensure
comprehensive coverage.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.1.1. Critical infrastructures and networks</title>
        <p>
          Several studies focused on using hybrid cryptographic systems to protect critical infrastructures. For
example, [12] proposed a TLS protocol that combines QKD with lattice-based PQC algorithms like
CRYSTALS-Kyber, ensuring strong security while maintaining compatibility with existing
infrastructure. Others [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ] developed a flexible three-key system that integrates pre-quantum,
postquantum, and quantum cryptography. This study stood out for its implementation on FPGA
platforms, showing real-world feasibility while maintaining security against quantum threats.
        </p>
        <p>
          Advancements in QKD were highlighted in [9], which explored the use of quantum dot photon
sources to improve scalability and reduce vulnerabilities in large-scale networks. Similarly, [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ]
validated the use of QKD in critical infrastructure, focusing on secure key exchange in large
communication networks through hierarchical key management, enhancing security with reduced
latency.
        </p>
        <p>This study [8] explored the resilience of lattice-based cryptosystems against quantum attacks.
Although primarily theoretical, it emphasized the importance of lattice-based methods, like
CRYSTALS-Kyber, which are increasingly recognized for their potential in critical infrastructure.
Similarly, authors in [11] evaluated PQC algorithms for operational technology systems, highlighting
the need for low-latency solutions in legacy environments.</p>
      </sec>
      <sec id="sec-3-3">
        <title>3.1.2. IoT and Resource-Constrained Environments</title>
        <p>A solution proposed by [7] integrated blockchain, lightweight cryptography, and QKD to secure
multimedia data in IoT devices. This study emphasized energy efficiency and scalability for
resourceconstrained environments. Authors in [13] combined QKD with lattice-based PQC, optimizing
security for IoT systems with limited computational power.</p>
        <p>This study [14] discussed how QKD protocols, like BB84, could secure IoT applications, focusing
on vulnerabilities in sensing and networking layers. It also emphasized the challenges of adapting
QKD to short-range and low-power devices.</p>
        <p>Interestingly, the authors in [10] provided a hardware-specific approach to optimize PQC for IoT,
achieving lower energy consumption. Similarly, [15] offered practical insights into integrating
lattice-based PQC algorithms into cryptographic libraries, enhancing usability for constrained
systems.</p>
      </sec>
      <sec id="sec-3-4">
        <title>3.1.3. Algorithms and hardware optimization</title>
        <p>
          The authors in [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ] explored how TLS protocols could integrate QKD and PQC, validated under ETSI
standards. This study emphasized scalability and cost-efficiency, making it relevant for real-world
applications.
        </p>
        <p>Alternatively, [9] provided significant advancements in QKD scalability, focusing on
photonsource technology to address long-distance communication challenges.</p>
        <p>Notably, [16] applied quantum annealing to optimize PQC algorithms, showing potential for
improving efficiency in cryptographic tasks. Whereas [17] focused on planning systematic
transitions to PQC, highlighting dependency analysis and cost considerations.</p>
      </sec>
      <sec id="sec-3-5">
        <title>3.1.4. Studies outside the above-mentioned groupings</title>
        <p>
          Some studies did not fit into specific application contexts but provided broader insights, for instance
[18] explored the institutional and policy challenges of adopting quantum-safe cryptography,
focusing on organizational readiness and regulatory gaps. Whereas [19] introduced Quantum Secure
Direct Communication (QSDC) as an alternative to QKD, emphasizing its potential for direct, secure
communication. Notably, [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ] explored AI’s role in enhancing QKD performance, presenting
innovative but untested ideas.
        </p>
      </sec>
      <sec id="sec-3-6">
        <title>3.2. Reporting biases</title>
        <p>
          Some studies emphasized benefits while underreporting challenges. For instance, [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ] highlighted
potential optimizations through AI but did not address the practical hurdles of implementing such
systems. Similarly, [20] discussed hybrid cryptographic systems but offered limited details on
realworld scalability.
        </p>
      </sec>
      <sec id="sec-3-7">
        <title>3.3. Certainty of evidence</title>
        <p>
          Studies involving real-world testing, such as [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ] and [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ], provided the highest certainty of evidence.
Theoretical studies, like [8], contributed valuable insights but lacked empirical testing, limiting their
practical applicability. Overall, the evidence showed significant progress in quantum-safe
cryptography while highlighting areas that need further development.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Discussion</title>
      <p>This scoping review provides a comprehensive mapping of the current landscape of
quantumresistant cryptographic solutions, highlighting both the diversity of approaches and the varying
levels of implementation readiness. By exploring the breadth of research rather than assessing the
strength of evidence, we have identified key themes, research gaps, and future directions that can
inform both research and practice in this rapidly evolving field.</p>
      <p>
        The findings of this scoping review emphasize the critical need for both theoretical innovation
and practical implementation in quantum-safe cryptography. Hybrid cryptographic systems,
combining QKD and PQC, emerged as a leading solution for ensuring resilience against quantum
threats. For instance, [12] demonstrated the robust integration of QKD and lattice-based PQC into
TLS protocols, addressing quantum-era security challenges while maintaining compatibility with
existing infrastructures. Similarly, [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] provided a compelling example of a three-key system
achieving security flexibility and resilience against quantum attacks.
      </p>
      <p>
        While practical applications in IoT and 5G networks highlighted the feasibility of transitioning to
quantum-safe measures, challenges in scalability, latency, and cost persist. For instance, [7]
illustrated the integration of blockchain and lightweight cryptography with QKD for
resourceconstrained environments, but the study also emphasized the infrastructure demands of QKD.
Likewise, [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] showcased QKD’s potential in securing critical infrastructures but acknowledged the
difficulty of large-scale deployment.
      </p>
      <p>Post-quantum cryptography has shown promise as a scalable alternative or complement to QKD.
Studies like [10] optimized lattice-based algorithms for constrained devices, while [15] underscored
the importance of usability through open-source integrations. However, theoretical studies like [8]
underscored the field's reliance on lattice-based algorithms, which, while promising, remain subject
to scrutiny and future potential quantum attacks.</p>
      <sec id="sec-4-1">
        <title>4.1. Limitations</title>
        <p>
          This review identified several limitations in the current body of research. While empirical studies
provided valuable insights, many studies, such as [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ] and [19], relied heavily on theoretical models
without practical validation. This reliance on untested proposals limits the immediate applicability
of their findings.
        </p>
        <p>Another limitation was the lack of cost and scalability analyses in many studies. For instance, [9]
provided advancements in QKD technologies but did not address the financial and infrastructural
challenges of implementing these systems in real-world networks. Similarly, [18] discussed
organizational and policy barriers but offered limited quantitative data on cost or resource
requirements.</p>
        <p>Standardization and interoperability challenges were another recurring theme. While studies like
[17] presented structured approaches for transitioning to PQC, the absence of finalized standards
complicates large-scale adoption. This uncertainty is particularly significant in critical infrastructure
environments where backward compatibility with legacy systems is critical.</p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Future work</title>
        <p>
          Based on this review, several roads for future research and development are clear. Initially,
theoretical studies, such as [8] and [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ], need empirical testing to validate their assumptions and
proposed solutions. More experimental implementations and testbeds, like those in [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ], should be
prioritized.
        </p>
        <p>Addressing scalability challenges in QKD and PQC is critical. Studies like [9] should extend their
focus to include cost and performance benchmarks for real-world deployments. Similarly, the
infrastructure requirements highlighted in [7] need to be addressed to make quantum-safe
cryptography viable for large-scale adoption.</p>
        <p>
          Hybrid systems combining QKD and PQC showed significant promise but require further
optimization for resource efficiency and ease of integration. This study [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ] offers a valuable starting
point for exploring lightweight and flexible implementations.
        </p>
        <p>Studies like [18] emphasized the need for clear guidelines and frameworks to support the
transition to quantum-safe measures. Collaborative efforts between researchers, industry
stakeholders, and policymakers are essential for defining interoperability standards and
incentivizing adoption.</p>
        <p>Future research should focus on energy-efficient PQC implementations, particularly for IoT and
constrained environments. [10] demonstrated the potential for hardware-specific optimizations,
which should be further developed and scaled.</p>
      </sec>
      <sec id="sec-4-3">
        <title>4.3. Conclusion</title>
        <p>
          This scoping review highlights the growing importance of quantum-safe cryptography in preparing
for the challenges posed by quantum computing. Hybrid systems that combine QKD and PQC have
emerged as a powerful approach, offering both resilience and flexibility against quantum threats.
Studies such as [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ] and [12] demonstrate practical solutions that integrate quantum-safe methods
into existing infrastructures. Similarly, advancements in PQC, as shown in [10], highlight the
potential for scalable and efficient cryptographic systems.
        </p>
        <p>However, challenges remain. While QKD provides unmatched security, its cost and scalability
limit its widespread adoption. PQC, on the other hand, offers a more accessible alternative but
requires further optimization for resource-constrained environments like IoT systems. The lack of
finalized standards and the need for practical validation also pose barriers to the adoption of
quantum-safe solutions.</p>
        <p>To fully realize the potential of quantum-safe cryptography, future efforts should focus on
bridging the gap between theory and practice. This includes testing proposed systems in real-world
settings, addressing scalability and cost issues, and developing clear policies and standards to guide
implementation.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Declaration on Generative AI</title>
      <p>During the preparation of this work, the authors used GPT-4o and Grammarly to improve the
grammar and to spell check.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Peter</surname>
            <given-names>W.</given-names>
          </string-name>
          <string-name>
            <surname>Shor</surname>
          </string-name>
          .
          <year>1997</year>
          .
          <article-title>Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer</article-title>
          .
          <source>SIAM J. Comput. 26</source>
          ,
          <issue>5</issue>
          (Oct.
          <year>1997</year>
          ),
          <fpage>1484</fpage>
          -
          <lpage>1509</lpage>
          . https://doi.org/10.1137/S0097539795293172
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Gasser</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Post-quantum Cryptography</article-title>
          . In: Mulder,
          <string-name>
            <given-names>V.</given-names>
            ,
            <surname>Mermoud</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Lenders</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            ,
            <surname>Tellenbach</surname>
          </string-name>
          ,
          <string-name>
            <surname>B.</surname>
          </string-name>
          <source>(eds) Trends in Data Protection and Encryption Technologies</source>
          . Springer, Cham. https://doi.org/10.1007/978-3-
          <fpage>031</fpage>
          -33386-6_
          <fpage>10</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Radanliev</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <article-title>Artificial intelligence and quantum cryptography</article-title>
          .
          <source>J Anal Sci Technol</source>
          <volume>15</volume>
          ,
          <issue>4</issue>
          (
          <year>2024</year>
          ). https://doi.org/10.1186/s40543-024-00416-6
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Asier</given-names>
            <surname>Atutxa</surname>
          </string-name>
          , Ane Sanz, Jorge Sasiain, Jasone Astorga, Eduardo Jacob,
          <article-title>"Towards a quantum-safe 5G: Quantum Key Distribution in core networks"</article-title>
          ,
          <source>Computer Communications</source>
          , Volume
          <volume>224</volume>
          ,
          <year>2024</year>
          , Pages
          <fpage>145</fpage>
          -
          <lpage>158</lpage>
          , ISSN 0140-3664, https://doi.org/10.1016/j.comcom.
          <year>2024</year>
          .
          <volume>06</volume>
          .005
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S.</given-names>
            <surname>Ricci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Dobias</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Malina</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Hajny</surname>
          </string-name>
          and
          <string-name>
            <given-names>P.</given-names>
            <surname>Jedlicka</surname>
          </string-name>
          ,
          <article-title>"Hybrid Keys in Practice: Combining Classical, Quantum and Post-Quantum Cryptography,"</article-title>
          <source>in IEEE Access</source>
          , vol.
          <volume>12</volume>
          , pp.
          <fpage>23206</fpage>
          -
          <lpage>23219</lpage>
          ,
          <year>2024</year>
          , doi: 10.1109/ACCESS.
          <year>2024</year>
          .
          <volume>3364520</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>K. -S.</given-names>
            <surname>Shim</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Kim</surname>
          </string-name>
          and
          <string-name>
            <given-names>W.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <article-title>"Research on Quantum Key, Distribution Key and Post-Quantum Cryptography Key Applied Protocols for Data Science and Web Security,"</article-title>
          <source>in Journal of Web Engineering</source>
          , vol.
          <volume>23</volume>
          , no.
          <issue>6</issue>
          , pp.
          <fpage>813</fpage>
          -
          <lpage>830</lpage>
          ,
          <year>September 2024</year>
          , doi: 10.13052/jwe1540-
          <fpage>9589</fpage>
          .
          <fpage>2365</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>