The advent of cryptographically relevant quantum computers threatens the currently used classical asymmetric cryptography. Attackers can already record network traffic today, intending to decrypt it later using cryptographically relevant quantum computers. In order to continue to guarantee the security of asymmetric cryptography, post-quantum cryptography (PQC) is being adopted. While the performance of these primitives in isolation is usually well understood, their performance within some protocols remains insufficiently investigated. QUIC is a new general-purpose transport protocol of the IETF but requires further study of PQC Key Encapsulation Mechanism (KEM) algorithms. Thorough investigation of PQC KEM algorithms in QUIC across varying network conditions is therefore highly important to accompany the migration to PQC.
In this work, handshakes are repeatedly performed in QUIC and comparatively in TLS1.3/TCP in an emulated network and the Time to First Byte is measured. The network conditions, algorithms, and congestion control algorithms are varied across different network scenarios and security levels and then evaluated.
While the obvious choice is always the algorithm with the shortest calculation time and transmission length, this is not the case in QUIC. Here, it is worth sending a moderate amount of packets in case of random packet loss so that not too many lost packets have to be retransmitted, but the communication is also not initially delayed by a second. ML-KEM is the best choice in every scenario except for high random packet loss. If ML-KEM is not available, the recommendation is not clear, as it varies depending on the scenario and security level between BIKE and HQC. HQC is the better choice if the network conditions are good or if there is a high-latency scenario due to the low calculation time of the KEM operations. BIKE, with its shorter transmission length, is the better choice at low transmission rates, high jitter and at security level 5 with high latency, as the initial packets of the server from HQC do not fit into the initial congestion control window. In case of random packet loss, both BIKE and HQC are good algorithms, HQC rather in lower security levels and at high packet loss, BIKE at lower packet loss and higher security level.
Future research should extend the investigation to PQC signature algorithms in QUIC, further supporting the migration to PQC.