Abstract
Many of today’s widely used communication protocols rely heavily on classical public-key schemes, which a sufficiently powerful quantum computer could break using Shor’s algorithm. However, encrypted communication is already at risk, since attackers can record and store it and, once such a computer exists, decrypt it. Quantum-resistant schemes have been developed to prevent this, and some of them are already standardized by NIST. They are now being integrated into existing protocols such as TLS and SSH. That mainly requires adapting the key exchange and the signature schemes. This thesis focuses on the key exchange. The cryptographic security of the new schemes has been well studied. In contrast, much less is known about their performance in SSH and their behavior under real-world network conditions. This highlights the need to test and compare classical, PQC and hybrid KEX algorithms in SSH under various network constraints.