Abstract
The advent of cryptographically relevant quantum computers threatens the currently used classical asymmetric cryptography. Attackers can already record network traffic today, intending to decrypt it later using cryptographically relevant quantum computers. In order to continue to guarantee the security of asymmetric cryptography, post-quantum cryptography (PQC) is being adopted. While the performance of these primitives in isolation is usually well understood, their performance within some protocols remains insufficiently investigated. QUIC is a new general-purpose transport protocol of the IETF but requires further study of PQC Key Encapsulation Mechanism (KEM) algorithms. Thorough investigation of PQC KEM algorithms in QUIC across varying network conditions is therefore highly important to accompany the migration to PQC.