Author
Listed:
- Daniel Patryk Karcz
- Marcin Niemiec
- Michail Alexandros Kourtis
- Tobias Köppl
Abstract
The transition to post-quantum cryptography (PQC) raises practical concerns regarding the feasibility of standardized algorithms on resource-constrained embedded platforms. While National Institute of Standards and Technology (NIST)-selected PQC schemes are designed for broad applicability, their real-world performance on low-power microcontrollers remains insufficiently characterized. Using a configurable on-device evaluation framework, we assess the lattice-based key encapsulation mechanism (ML-KEM), lattice-based digital signature scheme (ML-DSA), and the hash-based digital signature scheme (SLH-DSA) implementations from the liboqs library across all NIST-standardized parameter sets and security levels. Our measurements focus on execution latency, key and signature material sizes, and dynamic memory behavior under realistic embedded constraints. Experimental results show that all evaluated ML-KEM, ML-DSA, and SLH-DSA parameter sets execute successfully on the ESP32-C6 without external memory support. ML-KEM exhibits stable and predictable memory usage across parameter sets, with execution time increasing proportionally with the security level. ML-DSA key generation and signing operations incur higher computational cost, while verification remains comparatively efficient. Evaluated SLH-DSA parameter sets demonstrate substantially higher execution latency, reflecting the inherent computational cost of hash-based signature schemes on embedded hardware. Overall, our results indicate that selected NIST PQC algorithms are deployable on modern embedded microcontrollers, provided that performance and latency trade-offs are carefully considered. The presented evaluation framework and empirical results provide practical guidance for the design of post-quantum secure embedded systems.
Suggested Citation
Daniel Patryk Karcz & Marcin Niemiec & Michail Alexandros Kourtis & Tobias Köppl, 2026.
"Exploring hardware implementation feasibility of post-quantum cryptography in embedded systems: Evaluation of NIST-standardized ML-KEM, ML-DSA and SLH-DSA on ESP32-C6,"
PLOS ONE, Public Library of Science, vol. 21(8), pages 1-22, August.
Handle:
RePEc:plo:pone00:0355179
DOI: 10.1371/journal.pone.0355179
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:plo:pone00:0355179. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: plosone (email available below). General contact details of provider: https://journals.plos.org/plosone/ .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.