{"id":"0c5ab47f-4ae3-48c4-b528-05d721c63171","arxiv_id":"2411.13023","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":3.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"A literature review plus an OMNeT++ simulation concluding that CRYSTALS-Kyber works over Ethernet but likely misses the 100 ms latency deadline for safety-critical wireless TCPS.","lead":"This paper argues that transportation cyber-physical systems must shift from RSA and ECC to post-quantum cryptography, then benchmarks CRYSTALS-Kyber in wired and wireless simulations. The review is accurate, but the wireless latency numbers are probably simulation artifacts rather than real network behavior.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The wireless latency conclusion in Table 9 rests on a likely simulator artifact: ciphertext delays are ~1,001,948 µs regardless of payload size, matching no physical 54 Mbps link; this undermines the central claim.","rationale":"For the central claim to hold, Table 9 must measure actual ad hoc LTE/C-V2X transmission delay. The reported ciphertext delays do not behave like transmission delays: they are essentially constant at ~1.002 s for ciphertext payloads that differ by more than a factor of two, and they exceed the physical serialization delay at 54 Mbps by roughly four orders of magnitude. This is not a matter of disagreeing with the broader consensus about PQC; it is an internal physical inconsistency in the only new experimental result. The Ethernet direction of the paper is plausible, and the survey and threat-modeling portions are reasonable summaries of established material, but the paper's stated contribution is the performance evaluation and its deployment implication. Removing the wireless result leaves a survey plus a threat model, which may be useful but does not establish the paper's own advertised empirical claim. The reader's reject verdict is therefore appropriate, and the reader's weakest-assumption identification captures the same load-bearing concern. The concern is about the simulation configuration and the interpretation of Table 9, not about author intent or integrity. A single targeted rerun with packet-level timing and disabled ARQ/fragmentation would settle whether the wireless column is physical or artifactual; until that check is done, the wireless infeasibility conclusion should not be treated as supported.","tokens_in":26168,"tokens_out":4255,"duration_ms":43206,"concrete_test":"Re-run Scenario 2 (static-static, Kyber-512) in the same OMNeT++/SimuLTE setup with packet-level logging enabled at the NIC and PHY, and record the one-way service time of a single 768-byte ciphertext packet on a dedicated 54 Mbps channel with fragmentation and ARQ disabled. Compare the measured delay to the analytic serialization time 768×8/54,000,000 ≈ 114 µs and to the delay of 1088- and 1568-byte ciphertext packets. If the delays remain at ~1,001,948 µs or fail to scale approximately linearly with packet size, Table 9's wireless column is a simulator artifact and the wireless infeasibility claim should not be reported as an empirical finding.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's advertised new result is the CRYSTALS-Kyber performance evaluation in Section 5, and the abstract's central claim is the Ethernet/wireless contrast. The wireless side of that contrast is supported only by Table 9. In every ad hoc LTE row, ciphertext delay is approximately 1,001,948–1,002,864 µs for Kyber-512 (768-byte ciphertext), Kyber-768 (1088-byte), and Kyber-1024 (1568-byte). At the stated 54 Mbps medium rate, serialization of a 768-byte ciphertext is about 114 µs; for a 1568-byte packet it is about 232 µs. The observed delays are roughly four orders of magnitude larger and, critically, do not scale with payload size. A bandwidth-limited link would produce delays roughly proportional to packet size; a fixed ~1 second plateau is characteristic of a simulator configuration artifact, such as a fixed queueing/scheduling delay, repeated retransmission, or a mis-set timer, rather than the advertised ad hoc LTE/C-V2X channel. Since the paper's conclusion that wireless TCPS cannot meet the 100 ms safety latency requirement depends entirely on this number, the central claim is unsupported. The Ethernet rows and liboqs execution times may be valid, but they do not rescue the wireless claim. The paper itself notes fragmentation was ignored (Section 5.2), which would only add delay, so it does not explain the plateau.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper argues that transportation cyber-physical systems (TCPS) must migrate to post-quantum cryptography (PQC) because Shor's and Grover's algorithms threaten the RSA/ECC/AES-based algorithms currently used in standards such as IEEE 1609.2. It reviews NIST PQC standardization, compares NIST fourth-round finalists, presents a Microsoft Threat Modeling Tool case study of the ARC-IT TM10 Electronic Toll Collection service package, and reports a performance evaluation of CRYSTALS-Kyber in simulated Ethernet and 'ADHOC LTE (C-V2X)' peer-to-peer scenarios. The central conclusion is that Kyber is effective over high-bandwidth Ethernet but faces challenges meeting the 100 ms latency requirements of safety-critical wireless TCPS applications.","tokens_in":26435,"tokens_out":4897,"duration_ms":48327,"significance":"If the experimental results were valid, the Ethernet/wireless contrast would provide useful deployment guidance for PQC in vehicle-to-everything communication. The survey material and the threat-modeling case study are competently assembled and correctly identify the need for quantum-resistant migration of TCPS cryptographic primitives. The paper's main new contribution, however, is the Kyber performance evaluation, and that contribution is undermined by a likely simulator artifact in the wireless latency measurements and by an unvalidated representation of C-V2X. The paper does not provide machine-checked proofs or derived parameter-free predictions; its strengths are its use of the standard liboqs implementation, NIST/IEEE/ARC-IT references, and a reproducible threat-modeling workflow.","major_comments":[{"comment":"The wireless latency numbers in Table 9 are not physically plausible for the stated 54 Mbps link and are effectively invariant to payload size, indicating a simulator artifact. For Kyber-512, Kyber-768, and Kyber-1024, the reported ciphertext transmission times are 1,001,948, 1,002,183, and 1,002,656 microseconds, respectively, despite ciphertext sizes of 768, 1088, and 1568 bytes; at 54 Mbps the expected serialization times are approximately 114, 161, and 232 microseconds. The encrypted-data column is also nearly constant (about 676 microseconds) for all three variants even though the AES-256 payload is the same 32 bytes, which is inconsistent with a bandwidth-limited channel. The Kyber-1024 public-key value also jumps to about 1,001,473 microseconds, whereas the Kyber-512 and Kyber-768 values are about 1,126 and 1,254 microseconds. A fixed ~1 second plateau for ciphertext transmission regardless of size is characteristic of a configured scheduling/retransmission delay, not of the advertised 54 Mbps wireless medium. Since the abstract's central claim that wireless TCPS 'challenges' latency requirements rests entirely on these values, the experimental conclusion is unsupported.","section":"Table 9 / §5.3"},{"comment":"The paper equates 'ad hoc LTE' with C-V2X and sets the wireless bandwidth to 54 Mbps, citing IEEE 802.11g and LTE data rates 'up to 54 Mbps' [29,31]. C-V2X (PC5) is a sidelink interface with its own frame structure, resource allocation, and data rates; an ad hoc LTE configuration in SimuLTE is not validated as a model of the PC5 interface. No calibration or validation of the SimuLTE channel parameters against any C-V2X standard is provided. Consequently, even if Table 9 were internally consistent, the paper would not establish that the results represent C-V2X communication, and the qualitative wireless conclusion in Section 5.3 and Section 7 would remain unsupported.","section":"§5.2"},{"comment":"The decryption failure probabilities are reported inconsistently. Table 6 lists delta values of 2^-139, 2^-164, and 2^-174 for Kyber-512, Kyber-768, and Kyber-1024, while Section 5.1.4 states that these variants have decryption failure probabilities of 'approximately 2^-69 (2^-82 for Kyber-768 and 2^-87 for Kyber-1024) under quantum assumptions.' The paper does not reconcile these values or cite the source of the latter numbers. As written, the security assessment contains contradictory quantitative claims.","section":"Table 6 / §5.1.4"},{"comment":"The methodology does not make clear whether the liboqs/OpenSSL cryptographic operations are executed inside the OMNeT++ simulation or separately on the host machine. Table 8 reports 'execution time' from five simulation runs, while Table 9 reports 'communication delay' for the same scenarios; without a precise statement of where each timer starts and stops, and whether queueing, protocol overhead, and fragmentation are included, the reader cannot determine whether the reported wireless delays include cryptographic processing time or are purely network-layer delays. This ambiguity is secondary to the Table 9 artifact, but it further weakens the experimental interpretation.","section":"§5.2 / §5.3"}],"minor_comments":[{"comment":"The label 'ADHOC LTE (C-V2X)' in Figure 3 and Table 9 is misleading because ad hoc LTE is not the same as the C-V2X PC5 sidelink; the text itself cites IEEE 802.11g and LTE uplink/downlink rates, neither of which is the PC5 interface.","section":"§5.2"},{"comment":"The paper contains a typographical error: 'Society of Automative Engineers' should be 'Society of Automotive Engineers'.","section":"§6.2"},{"comment":"The text says Kyber-1024 has Core-SVP estimates of '256 bits in a classical setting and 236 bits in a quantum setting,' but Table 3 lists 256 bits classical and 232 bits quantum; the value 236 appears to be a typographical error.","section":"§5.1.2"},{"comment":"'SPHINCS++' appears in the first paragraph of Section 6.1; the standardized scheme is SPHINCS+ (SLH-DSA).","section":"§6.1"},{"comment":"Table 3 would benefit from a note that BIKE, HQC, and Classic McEliece values are fourth-round submissions whose parameter sets may still evolve; the table currently mixes finalized standards with ongoing candidates without distinguishing their status in the final row.","section":"§3.4"}],"recommendation":"reject","confidential_remarks":"The manuscript reads as a survey/position paper with an appended experimental section, and the experimental section is the part that would justify a research claim. Because the central wireless conclusion depends on a likely simulator artifact and an unvalidated C-V2X model, the experimental contribution cannot be salvaged by textual revision alone; the wireless experiments would need to be redone with a properly configured and validated PC5 sidelink model. The survey and case-study portions are reasonable but do not constitute a sufficient research contribution for a journal publication in their current form."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Straight to it: the only genuinely new thing in this paper is the Kyber performance evaluation, and the wireless half of it is not credible. Table 9 reports ciphertext delays of about 1,001,948 µs for every Kyber variant in the ad hoc LTE scenarios, regardless of whether the ciphertext is 768 or 1568 bytes. At the stated 54 Mbps, those packets should take on the order of 114–232 µs to serialize. A fixed ~1 second plateau is a simulator configuration artifact, not a bandwidth limit. Even worse, the Kyber-1024 public key delay jumps to ~1,001,473 µs while Kyber-512 stays at ~1,126 µs—again, not something a physical link would do. The paper's headline conclusion that Kyber cannot meet 100 ms latencies over wireless rests entirely on this number. The stress-test note is right.\n\nWhat the paper does well is the survey part. Sections 2 and 3 give an accurate, up-to-date overview of NIST's standardization process, the main PQC families, and the known quantum threats to RSA/ECC/AES. The electronic toll collection threat model in Section 4 is a concrete, well-structured exercise using the Microsoft tool; it would be a useful teaching example for transportation audiences who are new to PQC. The Ethernet latency numbers are plausible, and the liboqs execution times are routine but fine.\n\nThe soft spots beyond Table 9: they call the wireless medium 'ad hoc LTE' but use 54 Mbps, which is 802.11g's rate, not LTE's. They also ignore fragmentation, which would add delay but cannot explain the plateau. These issues compound, so the experimental section needs a full redo with a proper C-V2X PHY/MAC model.\n\nWho is this for? Someone wanting a broad PQC primer with a worked threat-model case study will get value from Sections 2–4. They should not rely on the performance numbers. As a research contribution, the paper does not hold up: the advertised experiment is broken, and the survey is not new. I would not bring it to a reading group and would not cite it. It deserves a serious referee? Not in this form—a reviewer would just send it back for a new simulation. If the authors redo the experiment honestly, a revised version might be worth a look, but the novelty bar will still be low.\n\nBottom line: desk reject, but let the authors know the survey portion is salvageable.","headline":"A competent PQC-in-transportation survey is dragged down by a Kyber wireless-latency experiment that is clearly a simulator artifact, so the paper's central claim does not hold.","tokens_in":27032,"tokens_out":3157,"would_cite":false,"duration_ms":29216,"reading_group":"no","serious_thinker":"yes","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims CRYSTALS-Kyber is ready for wired transportation networks but not for safety-critical wireless vehicle links, and lays out migration and lightweight-scheme directions.","keywords":["post-quantum cryptography","transportation cyber-physical systems","CRYSTALS-Kyber","ML-KEM","vehicle-to-everything","latency requirements","electronic toll collection","threat modeling"],"falsifier":"Compute the expected over-the-air transmission time for a Kyber-512 ciphertext (768 bytes) at 54 Mbps: roughly 114 microseconds. A testbed or a packet-level simulator that transfers a 768-byte packet over a real 54 Mbps link and shows a delay near that value, rather than the paper's ~1,001,948 microseconds, would falsify the claim that the wireless medium itself makes Kyber too slow.","tokens_in":25946,"feed_emoji":"🚗","tokens_out":14756,"duration_ms":124832,"temperature":0.7,"pith_summary":"This paper argues that the transportation systems that handle tolls, traffic signals, and vehicle-to-vehicle messages depend on cryptographic algorithms that a sufficiently large quantum computer could break, and that the move to post-quantum cryptography is urgent. It makes the case through a threat-modeling study of electronic toll collection and a performance evaluation of the standardized lattice-based key-encapsulation scheme CRYSTALS-Kyber. The experimental claim is that Kyber adds only a few microseconds of delay on high-bandwidth wired Ethernet links, so it can be deployed on fixed transportation backbones now, but that the same scheme incurs delays of more than one second on the simulated wireless ad-hoc LTE links used to represent vehicle-to-everything communication, far beyond the roughly 100-millisecond budget for safety-critical messages. If this result holds, transportation agencies should prioritize PQC migration for wired infrastructure and hold off on wireless safety applications until lighter-weight or hybrid schemes become available.","feed_headline":"Quantum-safe crypto fits wired transport, misses wireless safety","feed_subtitle":"Kyber adds microseconds to Ethernet links but exceeds a second on simulated vehicle links, blocking safety use.","key_machinery":"The load-bearing object is CRYSTALS-Kyber, a key-encapsulation mechanism whose security rests on the Module Learning with Errors (MLWE) problem, a lattice problem believed hard for both classical and quantum computers. The paper's evaluation machinery is a set of four peer-to-peer communication scenarios—wired static-to-static, wireless static-to-static, wireless static-to-dynamic, and wireless dynamic-to-dynamic—simulated in a discrete-event network simulator with an LTE model, together with a threat-modeling pass over the electronic toll collection data flows. The Kyber variants (512, 768, 1024) are measured on key generation, encapsulation, decapsulation, and communication delay; the wired/wireless contrast is what carries the conclusion.","core_discovery":"The central discovery the paper asserts is that CRYSTALS-Kyber, standardized in 2024 as the module-lattice-based key-encapsulation mechanism, is practically deployable for transportation cyber-physical systems (TCPS) over high-bandwidth, low-latency Ethernet networks but not, in its current form, over the wireless links that carry safety-critical vehicle-to-everything messages. In the paper's simulations, key, ciphertext, and encrypted-data transfers over Ethernet average around 5–10 microseconds for all Kyber variants, while the same exchanges over the simulated 54 Mbps ad-hoc LTE link take more than one second for ciphertexts and push public-key exchange to over a second for the largest variant. The paper reads this as evidence that wired TCPS applications such as toll-collection backhaul can adopt Kyber immediately, whereas wireless safety applications, which need latencies at or below 100 milliseconds for collision warning and lane-change assistance, require lighter-weight PQC designs, hybrid classical-post-quantum schemes, or faster wireless technologies.","pith_inferences":["The paper's wired-versus-wireless contrast naturally extends to other lattice-based key-encapsulation schemes with comparable payload sizes, but not automatically to code-based or hash-based schemes whose public keys, ciphertexts, or signatures are much larger.","A direct testbed measurement, running Kyber key establishment over a real LTE or Wi-Fi link and recording per-packet latencies, would separate genuine bandwidth costs from simulator overhead and could change the deployment picture.","If the wireless bottleneck is mostly fixed overhead rather than bandwidth, protocol optimizations such as batching, pre-distributing public keys, or moving key establishment to a periodic background channel could let even current Kyber fit the 100 ms safety budget.","An extension of the threat model would be to treat the PQC transition itself—certificate chains, key rotation, and hybrid operation—as part of the system's threat surface, not just the cryptographic primitives."],"forward_implications":["Fixed transportation backbones, such as toll-collection centers and traffic-management offices, can adopt Kyber without breaching real-time budgets: the measured Ethernet overhead is about 5–10 microseconds.","Safety-critical wireless messages in current vehicle-to-everything links cannot carry Kyber key establishment within the 100-millisecond budget; the paper's simulated ciphertext delays exceed one second, so deployment should wait for lightweight or hybrid variants.","The electronic toll collection threat model shows that quantum-vulnerable authentication, collision, replay, and impersonation threats can be mapped to post-quantum countermeasures, but protocol-level protections such as freshness and time-based checks are still required.","The paper's own roadmap points to 5G, reduced payload sizes, and hybrid schemes that combine classical and post-quantum algorithms as the paths to making wireless post-quantum cryptography viable."],"supporting_citations":[{"why":"Specification whose parameter sets and security definitions determine the Kyber variants tested.","marker":"[5]"},{"why":"Original proposal establishing the module-lattice key-encapsulation mechanism and its MLWE foundation.","marker":"[13]"},{"why":"Threat modeling tool whose generated report supplies the vulnerabilities mapped to PQC countermeasures.","marker":"[48]"},{"why":"Architecture reference defining the electronic toll collection data flows used in the case study.","marker":"[74]"},{"why":"Standard that sets the 100 ms latency budget for safety-critical cooperative ITS messages.","marker":"[24]"},{"why":"Standard defining basic safety message exchange rates for vehicle-to-vehicle scenarios.","marker":"[75]"},{"why":"LTE simulation module that produced the wireless delay measurements.","marker":"[76]"},{"why":"Network simulator in which the wired and wireless scenarios were implemented.","marker":"[91]"},{"why":"Software library providing the Kyber implementation used in the experiments.","marker":"[94]"}],"fun_headline_variants":["Kyber secures wired traffic, stalls on vehicle safety links","Quantum-safe crypto: fast on Ethernet, slow for V2X","Post-quantum keys: microseconds wired, seconds wireless","Crypto shift: PQC ready for tolls, not for collision alerts","Kyber fits wired TCPS, but wireless latency fails safety"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the simulated 54 Mbps ad-hoc LTE link faithfully represents real peer-to-peer vehicle-to-everything wireless communication; if that model is wrong, the paper's conclusion that Kyber cannot meet wireless safety latency collapses.","fun_headline_variants_meta":{"raw":{"variants":["Kyber secures wired traffic, stalls on vehicle safety links","Quantum-safe crypto: fast on Ethernet, slow for V2X","Post-quantum keys: microseconds wired, seconds wireless","Crypto shift: PQC ready for tolls, not for collision alerts","Kyber fits wired TCPS, but wireless latency fails safety"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000602,"raw_usage":{"total_tokens":2867,"prompt_tokens":1057,"completion_tokens":1810,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":673,"completion_tokens_details":{"reasoning_tokens":1721}},"tokens_in":673,"tokens_out":1810,"duration_ms":11259,"temperature":1.0,"reasoning_tokens":1721,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T16:55:03.180585+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the expected over-the-air transmission time for a Kyber-512 ciphertext (768 bytes) at 54 Mbps: roughly 114 microseconds. A testbed or a packet-level simulator that transfers a 768-byte packet over a real 54 Mbps link and shows a delay near that value, rather than the paper's ~1,001,948 microseconds, would falsify the claim that the wireless medium itself makes Kyber too slow.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Architecture reference defining the electronic toll collection data flows used in the case study."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"LTE simulation module that produced the wireless delay measurements."},{"cited_title":"Retrieved November 1, 2024 from https://omnetpp.org/","cited_arxiv_id":null,"evidence_quote":"Network simulator in which the wired and wireless scenarios were implemented."},{"cited_title":"Retrieved November 1, 2024 from https://openquantumsafe.org/liboqs/","cited_arxiv_id":null,"evidence_quote":"Software library providing the Kyber implementation used in the experiments."}],"review_version":1}