Pith. sign in

REVIEW 4 major objections 5 minor 97 references

Enhancing Transportation Cyber-Physical Systems Security: A Shift to Post-Quantum Cryptography

T0 review · 4 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read The paper claims CRYSTALS-Kyber is ready for wired transportation networks but not for safety-critical wireless vehicle links, and lays out migration and lightweight-scheme directions.

desk verdict A competent PQC-in-transportation survey is dragged down by a Kyber wireless-latency experiment that is clearly a simulator artifact, so the paper's central claim does not hold. read the letter →

arxiv 2411.13023 v1 pith:5Y4SPJGI submitted 2024-11-20 cs.CR

classification cs.CR
keywords post-quantumcryptographytransportationcyber-physicalsystemsCRYSTALS-KyberML-KEMvehicle-to-everythinglatencyrequirementselectronictollcollectionthreatmodeling
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper argues that the transportation systems that handle tolls, traffic signals, and vehicle-to-vehicle messages depend on cryptographic algorithms that a sufficiently large quantum computer could break, and that the move to post-quantum cryptography is urgent. It makes the case through a threat-modeling study of electronic toll collection and a performance evaluation of the standardized lattice-based key-encapsulation scheme CRYSTALS-Kyber. The experimental claim is that Kyber adds only a few microseconds of delay on high-bandwidth wired Ethernet links, so it can be deployed on fixed transportation backbones now, but that the same scheme incurs delays of more than one second on the simulated wireless ad-hoc LTE links used to represent vehicle-to-everything communication, far beyond the roughly 100-millisecond budget for safety-critical messages. If this result holds, transportation agencies should prioritize PQC migration for wired infrastructure and hold off on wireless safety applications until lighter-weight or hybrid schemes become available.

What carries the argument

The load-bearing object is CRYSTALS-Kyber, a key-encapsulation mechanism whose security rests on the Module Learning with Errors (MLWE) problem, a lattice problem believed hard for both classical and quantum computers. The paper's evaluation machinery is a set of four peer-to-peer communication scenarios—wired static-to-static, wireless static-to-static, wireless static-to-dynamic, and wireless dynamic-to-dynamic—simulated in a discrete-event network simulator with an LTE model, together with a threat-modeling pass over the electronic toll collection data flows. The Kyber variants (512, 768, 1024) are measured on key generation, encapsulation, decapsulation, and communication delay; the wired/wireless contrast is what carries the conclusion.

What would settle it

Compute the expected over-the-air transmission time for a Kyber-512 ciphertext (768 bytes) at 54 Mbps: roughly 114 microseconds. A testbed or a packet-level simulator that transfers a 768-byte packet over a real 54 Mbps link and shows a delay near that value, rather than the paper's ~1,001,948 microseconds, would falsify the claim that the wireless medium itself makes Kyber too slow.

Watch

Extended reading notes

Core claim

The central discovery the paper asserts is that CRYSTALS-Kyber, standardized in 2024 as the module-lattice-based key-encapsulation mechanism, is practically deployable for transportation cyber-physical systems (TCPS) over high-bandwidth, low-latency Ethernet networks but not, in its current form, over the wireless links that carry safety-critical vehicle-to-everything messages. In the paper's simulations, key, ciphertext, and encrypted-data transfers over Ethernet average around 5–10 microseconds for all Kyber variants, while the same exchanges over the simulated 54 Mbps ad-hoc LTE link take more than one second for ciphertexts and push public-key exchange to over a second for the largest variant. The paper reads this as evidence that wired TCPS applications such as toll-collection backhaul can adopt Kyber immediately, whereas wireless safety applications, which need latencies at or below 100 milliseconds for collision warning and lane-change assistance, require lighter-weight PQC designs, hybrid classical-post-quantum schemes, or faster wireless technologies.

Load-bearing premise

The load-bearing premise is that the simulated 54 Mbps ad-hoc LTE link faithfully represents real peer-to-peer vehicle-to-everything wireless communication; if that model is wrong, the paper's conclusion that Kyber cannot meet wireless safety latency collapses.

Editorial extensions

If this is right

  • Fixed transportation backbones, such as toll-collection centers and traffic-management offices, can adopt Kyber without breaching real-time budgets: the measured Ethernet overhead is about 5–10 microseconds.
  • Safety-critical wireless messages in current vehicle-to-everything links cannot carry Kyber key establishment within the 100-millisecond budget; the paper's simulated ciphertext delays exceed one second, so deployment should wait for lightweight or hybrid variants.
  • The electronic toll collection threat model shows that quantum-vulnerable authentication, collision, replay, and impersonation threats can be mapped to post-quantum countermeasures, but protocol-level protections such as freshness and time-based checks are still required.
  • The paper's own roadmap points to 5G, reduced payload sizes, and hybrid schemes that combine classical and post-quantum algorithms as the paths to making wireless post-quantum cryptography viable.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper's wired-versus-wireless contrast naturally extends to other lattice-based key-encapsulation schemes with comparable payload sizes, but not automatically to code-based or hash-based schemes whose public keys, ciphertexts, or signatures are much larger.
  • A direct testbed measurement, running Kyber key establishment over a real LTE or Wi-Fi link and recording per-packet latencies, would separate genuine bandwidth costs from simulator overhead and could change the deployment picture.
  • If the wireless bottleneck is mostly fixed overhead rather than bandwidth, protocol optimizations such as batching, pre-distributing public keys, or moving key establishment to a periodic background channel could let even current Kyber fit the 100 ms safety budget.
  • An extension of the threat model would be to treat the PQC transition itself—certificate chains, key rotation, and hybrid operation—as part of the system's threat surface, not just the cryptographic primitives.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. The paper argues that transportation cyber-physical systems (TCPS) must migrate to post-quantum cryptography (PQC) because Shor's and Grover's algorithms threaten the RSA/ECC/AES-based algorithms currently used in standards such as IEEE 1609.2. It reviews NIST PQC standardization, compares NIST fourth-round finalists, presents a Microsoft Threat Modeling Tool case study of the ARC-IT TM10 Electronic Toll Collection service package, and reports a performance evaluation of CRYSTALS-Kyber in simulated Ethernet and 'ADHOC LTE (C-V2X)' peer-to-peer scenarios. The central conclusion is that Kyber is effective over high-bandwidth Ethernet but faces challenges meeting the 100 ms latency requirements of safety-critical wireless TCPS applications.

Significance. If the experimental results were valid, the Ethernet/wireless contrast would provide useful deployment guidance for PQC in vehicle-to-everything communication. The survey material and the threat-modeling case study are competently assembled and correctly identify the need for quantum-resistant migration of TCPS cryptographic primitives. The paper's main new contribution, however, is the Kyber performance evaluation, and that contribution is undermined by a likely simulator artifact in the wireless latency measurements and by an unvalidated representation of C-V2X. The paper does not provide machine-checked proofs or derived parameter-free predictions; its strengths are its use of the standard liboqs implementation, NIST/IEEE/ARC-IT references, and a reproducible threat-modeling workflow.

major comments (4)
  1. [Table 9 / §5.3] The wireless latency numbers in Table 9 are not physically plausible for the stated 54 Mbps link and are effectively invariant to payload size, indicating a simulator artifact. For Kyber-512, Kyber-768, and Kyber-1024, the reported ciphertext transmission times are 1,001,948, 1,002,183, and 1,002,656 microseconds, respectively, despite ciphertext sizes of 768, 1088, and 1568 bytes; at 54 Mbps the expected serialization times are approximately 114, 161, and 232 microseconds. The encrypted-data column is also nearly constant (about 676 microseconds) for all three variants even though the AES-256 payload is the same 32 bytes, which is inconsistent with a bandwidth-limited channel. The Kyber-1024 public-key value also jumps to about 1,001,473 microseconds, whereas the Kyber-512 and Kyber-768 values are about 1,126 and 1,254 microseconds. A fixed ~1 second plateau for ciphertext transmission regardless of size is characteristic of a configured scheduling/retransmission delay, not of the advertised 54 Mbps wireless medium. Since the abstract's central claim that wireless TCPS 'challenges' latency requirements rests entirely on these values, the experimental conclusion is unsupported.
  2. [§5.2] The paper equates 'ad hoc LTE' with C-V2X and sets the wireless bandwidth to 54 Mbps, citing IEEE 802.11g and LTE data rates 'up to 54 Mbps' [29,31]. C-V2X (PC5) is a sidelink interface with its own frame structure, resource allocation, and data rates; an ad hoc LTE configuration in SimuLTE is not validated as a model of the PC5 interface. No calibration or validation of the SimuLTE channel parameters against any C-V2X standard is provided. Consequently, even if Table 9 were internally consistent, the paper would not establish that the results represent C-V2X communication, and the qualitative wireless conclusion in Section 5.3 and Section 7 would remain unsupported.
  3. [Table 6 / §5.1.4] The decryption failure probabilities are reported inconsistently. Table 6 lists delta values of 2^-139, 2^-164, and 2^-174 for Kyber-512, Kyber-768, and Kyber-1024, while Section 5.1.4 states that these variants have decryption failure probabilities of 'approximately 2^-69 (2^-82 for Kyber-768 and 2^-87 for Kyber-1024) under quantum assumptions.' The paper does not reconcile these values or cite the source of the latter numbers. As written, the security assessment contains contradictory quantitative claims.
  4. [§5.2 / §5.3] The methodology does not make clear whether the liboqs/OpenSSL cryptographic operations are executed inside the OMNeT++ simulation or separately on the host machine. Table 8 reports 'execution time' from five simulation runs, while Table 9 reports 'communication delay' for the same scenarios; without a precise statement of where each timer starts and stops, and whether queueing, protocol overhead, and fragmentation are included, the reader cannot determine whether the reported wireless delays include cryptographic processing time or are purely network-layer delays. This ambiguity is secondary to the Table 9 artifact, but it further weakens the experimental interpretation.
minor comments (5)
  1. [§5.2] The label 'ADHOC LTE (C-V2X)' in Figure 3 and Table 9 is misleading because ad hoc LTE is not the same as the C-V2X PC5 sidelink; the text itself cites IEEE 802.11g and LTE uplink/downlink rates, neither of which is the PC5 interface.
  2. [§6.2] The paper contains a typographical error: 'Society of Automative Engineers' should be 'Society of Automotive Engineers'.
  3. [§5.1.2] The text says Kyber-1024 has Core-SVP estimates of '256 bits in a classical setting and 236 bits in a quantum setting,' but Table 3 lists 256 bits classical and 232 bits quantum; the value 236 appears to be a typographical error.
  4. [§6.1] 'SPHINCS++' appears in the first paragraph of Section 6.1; the standardized scheme is SPHINCS+ (SLH-DSA).
  5. [§3.4] Table 3 would benefit from a note that BIKE, HQC, and Classic McEliece values are fourth-round submissions whose parameter sets may still evolve; the table currently mixes finalized standards with ongoing candidates without distinguishing their status in the final row.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper's central conclusions rest on external standards, a generic threat-modeling tool, and independent simulator outputs, with no self-citation or fitting loop forcing the result.

full rationale

The claimed derivation chain in this paper is not circular. Sections 2 and 3 present vulnerabilities and PQC descriptions based on external sources: Shor's and Grover's algorithms [28, 68], NIST reports and standardization documents [1, 2, 16, 56], and published cryptanalysis and design papers [5, 8, 13, 23]. None of these sources are the authors' own results, and none are fitted to the paper's conclusions. Section 4 uses the Microsoft Threat Modeling Tool on the ARC-IT TM10 service package; the threat categories and mitigations are generated by that external tool and mapped to standardized PQC schemes, not defined in terms of the paper's own conclusions. Section 5 evaluates CRYSTALS-Kyber performance using external implementations (liboqs, OpenSSL) and a standard network simulator (OMNeT++, INET, SimuLTE). The execution times and communication delays are measured outputs, not quantities derived from the paper's own assumptions by construction. The wireless latency conclusion is an empirical observation from the simulation, and a concern that the ad hoc LTE model may be artifact-laden is a correctness or validity issue, not circularity. The only self-citations are [20], used to define TCPS, and [65], used to support the well-known point that Shor's algorithm can break RSA-based signatures in a VANET; neither is load-bearing for the central claim, which is independently supported by standard references on quantum threats and NIST standardization. No fitted parameter is renamed as a prediction, no uniqueness theorem is imported from the authors' prior work, and no ansatz is smuggled in via self-citation. Therefore, score 0.

Assumptions & free parameters 2 free parameters · 4 assumptions · 0 invented entities

No mathematical constants are fitted to data; the only user-chosen inputs are simulation scenario settings such as bandwidth, distance, and mobility, which directly condition the experimental result. No new entities are postulated. The paper relies on standard quantum algorithms, NIST evaluation criteria, and published PQC specifications as background.

free parameters (2)
  • Wireless link bandwidth = 54 Mbps
    Chosen in Section 5.2 as the data rate for 'ad hoc LTE'. The wireless latency result, the paper's main experimental claim, depends directly on this value.
  • Inter-node distance = 1350 meters
    Chosen in Section 5.2 to emulate the C-V2X communication range. It affects link quality in the LTE simulation and is used to define the bounding boxes for dynamic nodes.
assumptions (4)
  • standard math Shor's algorithm efficiently solves integer factorization and discrete logarithms on a sufficiently large quantum computer.
    Invoked in Section 2.1 and Table 1 to establish RSA, ECC, DSA, and DH vulnerabilities. These are accepted results in quantum information science.
  • domain assumption NIST PQC security strength categories and Core-SVP estimates correctly quantify the quantum and classical security of lattice-based schemes.
    Adopted from NIST documents [2, 56] in Sections 3.3 and 3.4. The paper's security-level comparisons depend on these external estimates, which are not derived here.
  • domain assumption The OMNeT++/SimuLTE 'ad hoc LTE' model with 54 Mbps faithfully represents peer-to-peer C-V2X communication in TCPS.
    Stated in Section 5.2. This is the load-bearing experimental premise. Without it, the wireless delay numbers cannot be interpreted as real-world behavior.
  • domain assumption Safety-critical V2X applications require message latencies under 100 ms.
    Used in Sections 5.3 and 6.2 to judge Kyber infeasible over wireless. This threshold applies to periodic safety messages such as BSMs, not necessarily to a one-time key establishment handshake.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Enhancing Transportation Cyber-Physical Systems Security: A Shift to Post-Quantum Cryptography." pith.science (2026). https://pith.science/paper/5Y4SPJGI

@misc{pith2026241113023,
  author       = {Pith},
  title        = {Pith review of: Enhancing Transportation Cyber-Physical Systems Security: A Shift to Post-Quantum Cryptography},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/5Y4SPJGI}},
  note         = {Machine review of arXiv:2411.13023}
}
read the original abstract

The rise of quantum computing threatens traditional cryptographic algorithms that secure Transportation Cyber-Physical Systems (TCPS). Shor's algorithm poses a significant threat to RSA and ECC, while Grover's algorithm reduces the security of symmetric encryption schemes, such as AES. The objective of this paper is to underscore the urgency of transitioning to post-quantum cryptography (PQC) to mitigate these risks in TCPS by analyzing the vulnerabilities of traditional cryptographic schemes and the applicability of standardized PQC schemes in TCPS. We analyzed vulnerabilities in traditional cryptography against quantum attacks and reviewed the applicability of NIST-standardized PQC schemes, including CRYSTALS-Kyber, CRYSTALS-Dilithium, and SPHINCS+, in TCPS. We conducted a case study to analyze the vulnerabilities of a TCPS application from the Architecture Reference for Cooperative and Intelligent Transportation (ARC-IT) service package, i.e., Electronic Toll Collection, leveraging the Microsoft Threat Modeling tool. This case study highlights the cryptographic vulnerabilities of a TCPS application and presents how PQC can effectively counter these threats. Additionally, we evaluated CRYSTALS-Kyber's performance across wired and wireless TCPS data communication scenarios. While CRYSTALS-Kyber proves effective in securing TCPS applications over high-bandwidth, low-latency Ethernet networks, our analysis highlights challenges in meeting the stringent latency requirements of safety-critical wireless applications within TCPS. Future research should focus on developing lightweight PQC solutions and hybrid schemes that integrate traditional and PQC algorithms, to enhance compatibility, scalability, and real-time performance, ensuring robust protection against emerging quantum threats in TCPS.

Figures

Figures reproduced from arXiv: 2411.13023 by the authors.

Figure 3
Figure 3. Simulation Scenarios for Evaluating Kyber in Wired and Wireless Communication Networks in TCPS The distances and mobility configurations for each scenario were designed to align with real-world TCPS communication requirements. For scenarios 1 and 2, involving two static nodes, the distance between the nodes was set to 1350 meters, reflecting the typical communication range of Cellular Vehicle-to-Everything (C-V2X) t… view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

97 extracted references · 46 canonical work pages

  1. [1]

    Gorjan Alagic, Jacob Alperin-Sheriff, Daniel Apon, David Cooper, Quynh Dang, Yi-Kai Liu, Carl Miller, Dustin Moody, Rene Peralta, Ray Perlner, Angela Robinson, and Daniel Smith -Tone. 2019. Status report on the first round of the NIST post -quantum cryptography standardization process . National Institute of Standards and Technology, Gaithersburg, MD. htt...

  2. [2]

    Gorjan Alagic, Daniel Apon, David Cooper, Quynh Dang, Thinh Dang, John Kelsey, Jacob Lichtinger, Yi-Kai Liu, Carl Miller, Dustin Moody, Rene Peralta, Ray Perlner, Angela Robinson, and Daniel Smith -Tone. 2022. Status report on the third round of the NIST Post -Quantum Cryptography Standardization process. National Institute of Standards and Technology (U....

  3. [3]

    Albrecht

    Martin R. Albrecht. 2017. On Dual Lattice Attacks Against Small-Secret LWE and Parameter Choices in HElib and SEAL. In Advances in Cryptology – EUROCRYPT 2017 , Jean -Sébastien Coron and Jesper Buus Nielsen (eds.). Springer International Publishing, Cham, 103 –129. https://doi.org/10.1007/978-3-319-56614-6_4

  4. [4]

    Albrecht, Rachel Player, and Sam Scott

    Martin R. Albrecht, Rachel Player, and Sam Scott. 2015. On the concrete hardness of Learning with Errors. Journal of Mathematical Cryptology 9, 3 (October 2015), 169–203. https://doi.org/10.1515/jmc-2015-0016

  5. [5]

    Schanck, Peter Schwabe, Grego r Seiler, and Damien Stehlé

    Roberto Avanzi, Joppe Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Grego r Seiler, and Damien Stehlé. 2021. CRYSTALS -Kyber (version 3.02) – Submission to round 3 of the NIST post -quantum project. Retrieve d from https://pq - crystals.org/kyber/data/kyber-specification-round3-20210804.pdf

  6. [6]

    Liantao Bai, Yuegong Zhang, and Guoqiang Yang. 2012. SM2 cryptographic algorithm based on discrete logarithm problem and pros pect. In 2012 2nd International Conference on Consumer Electronics, Communications and Networks (CECNet) , April 2012. IEEE, Yichang, China, 1294 –1297. https://doi.org/10.1109/CECNet.2012.6201878

  7. [7]

    Berlekamp, R

    E. Berlekamp, R. McEliece, and H. Van Tilborg. 1978. On the inherent intractability of certain coding problems (Corresp.). IEEE Trans. Inform. Theory 24, 3 (May 1978), 384–386. https://doi.org/10.1109/TIT.1978.1055873

  8. [8]

    Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen, Joost Rijneveld, and Peter Schwabe

    Daniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen, Joost Rijneveld, and Peter Schwabe. 2019. The SPHINCS + Signature Framework. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , November 06, 2019. ACM, London United Kingdom, 2129–2146. https://doi.org/10.1145/3319535.3363229

Show all 97 references
  1. [9]

    Bernstein, Tanja Lange, and Christiane Peters

    Daniel J. Bernstein, Tanja Lange, and Christiane Peters. 2008. Attacking and Defending the McEliece Cryptosystem. In Post-Quantum Cryptography, Johannes Buchmann and Jintai Ding (eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 31–46. https://doi.org/10.1007/978-3-540-88403-3_3

  2. [10]

    Guido Bertoni, Joan Daemen, Michaël Peeters, and Gilles Van Assche. 2013. Keccak. In Advances in Cryptology – EUROCRYPT 2013, Thomas Johansson and Phong Q. Nguyen (eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 313–314. https://doi.org/10.1007/978-3-642-38348-9_19

  3. [11]

    Jean-François Biasse and Fang Song. 2016. Efficient quantum algorithms for computing class groups and solving the principal ideal problem in arbitrary degree number fields. In Proceedings of the Twenty-Seventh Annual ACM-SIAM Symposium on Discrete Algorithms (SODA ’16), 2016. ...

  4. [12]

    Bone and M

    S. Bone and M. Castro. 1997. A Brief History of Quantum Computing. Surveys and Presentations in Information Systems Engineering (SURPRISE) 4, 3 (1997), 20–45

  5. [13]

    Schanck, Peter Schwabe, Gregor Seiler, and Damien St ehle

    Joppe Bos, Leo Ducas, Eike Kiltz, T Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, and Damien St ehle. 2018. CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM. In 2018 IEEE European Symposium on Security and Privacy (EuroS&P) , April

  6. [14]

    Gilles Brassard, Peter Høyer, and Alain Tapp. 1997. Quantum cryptanalysis of hash and claw-free functions. SIGACT News 28, 2 (June 1997), 14–19. https://doi.org/10.1145/261342.261346

  7. [15]

    Wouter Castryck and Thomas Decru. 2022. An efficient key recovery attack on SIDH. Retrieved from https://eprint.iacr.org/2022/975

  8. [16]

    Lily Chen, Stephen Jordan, Yi -Kai Liu, Dustin Moody, Rene Peralta, Ray Perlner, and Daniel Smith -Tone. 2016. Report on Post -Quantum Cryptography. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8105

  9. [17]

    Lily Chen, Dustin Moody, Andrew Regenscheid, and Angela Robinson. 2023. Digital Signature Standard (DSS). National Institute of Standards and Technology (U.S.), Gaithersburg, MD. https://doi.org/10.6028/NIST.FIPS.186-5

  10. [18]

    Zhao Chunhuan, Zheng Zhongxiang, Wang Xiaoyun, and Xu Guangwu. 2019. Distinguishing LWE Instances Using Fourier Transform: A Refined Framework and its Applications. Retrieved from https://eprint.iacr.org/2019/1231

  11. [19]

    Ronald Cramer, Léo Ducas, and Benjamin Wesolowski. 2016. Short Stickelberger Class Relations and application to Ideal -SVP. Retrieved from https://eprint.iacr.org/2016/885 26

  12. [20]

    Khan, Mashrur Chowdhury, and Nick Ayres

    Lipika Deka, Sakib M. Khan, Mashrur Chowdhury, and Nick Ayres. 2018. Transportation Cyber -Physical System and its importance for future mobility. In Transportation Cyber-Physical Systems. Elsevier, 1–20. https://doi.org/10.1016/B978-0-12-814295-0.00001-0

  13. [21]

    Diffie and M

    W. Diffie and M. Hellman. 1976. New directions in cryptography. IEEE Trans. Inform. Theory 22, 6 (November 1976), 644 –654. https://doi.org/10.1109/TIT.1976.1055638

  14. [22]

    Léo Ducas. 2017. Shortest Vector from Lattice Sieving: a Few Dimensions for Free. Retrieved from https://eprint.iacr.org/2017/999

  15. [23]

    Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, Peter Schwabe, Gregor Seiler, and Damien Stehlé. 2018. CRYSTALS-Dilithium: A Lattice-Based Digital Signature Scheme. TCHES (February 2018), 238–268. https://doi.org/10.46586/tches.v2018.i1.238-268

  16. [24]

    ETSI Technical Committee Intelligent Transport System (ITS). 2009. Intelligent Transport Systems (ITS); Vehicular Communications; Basic Set of Applications; Definitions. Retrieved from https://www.etsi.org/deliver/etsi_tr/102600_102699/102638/01.01.01_60/tr_102638v010101p.pdf

  17. [25]

    Galbraith and Frederik Vercauteren

    Steven D. Galbraith and Frederik Vercauteren. 2018. Computational problems in supersingular elliptic curve isogenies. Quantum Inf Process 17, 10 (October 2018), 265. https://doi.org/10.1007/s11128-018-2023-6

  18. [26]

    Gayoso Martinez, F

    V. Gayoso Martinez, F. Hernandez Alvarez, L. Hernandez Encinas, and C. Sanchez Avila. 2010. A comparison of the standardized versions of ECIES. In 2010 Sixth International Conference on Information Assurance and Security , August 2010. IEEE, Atlanta, GA, 1 –4. https://doi.org/...

  19. [27]

    Vlad Gheorghiu and Michele Mosca. 2025. Quantum resource estimation for large scale quantum algorithms. Future Generation Computer Systems 162, (January 2025), 107480. https://doi.org/10.1016/j.future.2024.107480

  20. [28]

    Lov K. Grover. 1996. A fast quantum mechanical algorithm for database search. https://doi.org/10.48550/ARXIV.QUANT-PH/9605043

  21. [29]

    Zeeshan Hameed Mir and Fethi Filali. 2014. LTE and IEEE 802.11p for vehicular networking: a performance evaluation. J Wireless Com Network 2014, 1 (December 2014), 89. https://doi.org/10.1186/1687-1499-2014-89

  22. [30]

    Helena Handschuh. 2005. SHA Family (Secure Hash Algorithm). In Encyclopedia of Cryptography and Security, Henk C. A. Tilborg (ed.). Springer US, 565–567. https://doi.org/10.1007/0-387-23483-7_388

  23. [31]

    Quang-Dung Ho, Daniel Tweed, and Tho Le -Ngoc. 2017. IEEE 802.11/Wi -Fi Medium Access Control: An Overview. In Long Term Evolution in Unlicensed Bands. Springer International Publishing, Cham, 31–41. https://doi.org/10.1007/978-3-319-47346-8_4

  24. [32]

    Anh Tuan Hoang, Mark Kennaway, Dung Tuan Pham, Thai Son Mai, Ayesha Khalid, Ciara Rafferty, and Maire O’Neill. 2024. Deep Lea rning Enhanced Side Channel Analysis on CRYSTALS -Kyber. In 2024 25th International Symposium on Quality Electronic Design (ISQED) , April 03,

  25. [33]

    Don Johnson, Alfred Menezes, and Scott Vanstone. 2001. The Elliptic Curve Digital Signature Algorithm (ECDSA). IJIS 1, 1 (August 2001), 36–63. https://doi.org/10.1007/s102070100002

  26. [34]

    Tendayi Kamucheka, Michael Fahr, Tristen Teague, Alexander Nelson, David Andrews, and Miaoqing Huang. 2021. Power-based Side Channel Attack Analysis on PQC Algorithms. Retrieved from https://eprint.iacr.org/2021/1021

  27. [35]

    Emre Karabulut and Aydin Aysu. 2021. FALCON Down: Breaking FALCON Post -Quantum Signature Scheme through Side -Channel Attacks. In 2021 58th ACM/IEEE Design Automation Conference (DAC) , December 05, 2021. IEEE, San Francisco, CA, USA, 691 –696. https://doi.org/10.1109/DAC1807...

  28. [36]

    Georgios Karagiannis, Onur Altintas, Eylem Ekici, Geert Heijenk, Boangoat Jarupan, Kenneth Lin, and Timothy Weil. 2011. Vehic ular Networking: A Survey and Tutorial on Requirements, Architectures, Challenges, Standards and Solutions. IEEE Commun. Surv. Tutorials 13, 4 (2011), ...

  29. [37]

    Jonathan Katz and Yehuda Lindell. 2015. Introduction to modern cryptography (Second edition ed.). CRC Press/Taylor & Francis, Boca Raton

  30. [38]

    Zack Kirsch. 2015. Quantum Computing: The Risk to Existing Encryption Methods. Ph.D. Dissertation. Tufts University, Massachu setts, USA. Retrieved from https://www.cs.tufts.edu/comp/116/archive/fall2015/zkirsch.pdf

  31. [39]

    Yen-Ting Kuo and Atsushi Takayasu. 2023. A Lattice Attack on CRYSTALS -Kyber with Correlation Power Analysis. Retrieved from https://eprint.iacr.org/2023/1781

  32. [40]

    Thijs Laarhoven and Michael Walter. 2021. Dual Lattice Attacks for Closest Vector Problems (with Preprocessing). In Topics in Cryptology – CT-RSA 2021, Kenneth G. Paterson (ed.). Springer International Publishing, Cham, 478–502. https://doi.org/10.1007/978-3-030-75539-3_20

  33. [41]

    Gaëtan Leurent, Mridul Nandi, and Ferdinand Sibleyras. 2018. Generic Attacks Against Beyond -Birthday-Bound MACs. In Advances in Cryptology – CRYPTO 2018, Hovav Shacham and Alexandra Boldyreva (eds.). Springer International Publishing, Cham, 306–336. https://doi.org/10.1007/97...

  34. [42]

    Brigitte Lonc, Alexandre Aubry, Hafeda Bakhti, Maria Christofi, and Hassane Aissaoui Mehrez. 2023. Feasibility and Benchmarking of Post-Quantum Cryptography in the Cooperative ITS Ecosystem. In 2023 IEEE Vehicular Networking Conference (VNC) , April 26, 2023. IEEE, Istanbul, T...

  35. [43]

    Artur Mariano, Thijs Laarhoven, Fabio Correia, Manuel Rodrigues, and Gabriel Falcao. 2017. A Practical View of the State -of-the-Art of Lattice - Based Cryptanalysis. IEEE Access 5, (2017), 24184–24202. https://doi.org/10.1109/ACCESS.2017.2748179

  36. [44]

    Zych, and Audun Jøsang

    Vasileios Mavroeidis, Kamer Vishi, Mateusz D. Zych, and Audun Jøsang. 2018. The Impact of Quantum Computing on Present Cryptography. (2018). https://doi.org/10.48550/ARXIV.1804.00200

  37. [45]

    R. J. McEliece. 1978. A Public -Key Cryptosystem Based On Algebraic Coding Theory. Deep Space Network Progress Report 44, (January 1978), 114–116

  38. [46]

    A. J. Menezes, Paul C. Van Oorschot, and Scott A. Vanstone. 1997. Handbook of applied cryptography. CRC Press, Boca Raton

  39. [47]

    Daniele Micciancio and Shafi Goldwasser. 2002. Shortest Vector Problem. In Complexity of Lattice Problems . Springer US, Boston, MA, 69 –90. 27 https://doi.org/10.1007/978-1-4615-0897-7_4

  40. [48]

    Microsoft. 2024. Microsoft Threat Modeling Tool. Retrieved July 25, 2024 from https://learn.microsoft.com/en -us/azure/security/develop/threat- modeling-tool

  41. [49]

    Shaun Miller. 2020. Algorithms in Lattice -Based Cryptanalysis. PhD Thesis. Retrieved from http://libproxy.clemson.edu/login?url=https://www.proquest.com/dissertations-theses/algorithms-lattice-based- cryptanalysis/docview/2443928396/se-2

  42. [50]

    Moller and Hamid Vakilzadian

    Dietmar P.F. Moller and Hamid Vakilzadian. 2016. Cyber-physical systems in smart transportation. In 2016 IEEE International Conference on Electro Information Technology (EIT), May 2016. IEEE, Grand Forks, ND, USA, 0776–0781. https://doi.org/10.1109/EIT.2016.7535338

  43. [51]

    Dustin Moody, Gorjan Alagic, Daniel C Apon, David A Cooper, Quynh H Dang, John M Kelsey, Yi -Kai Liu, Carl A Miller, Rene C Peralta, Ray A Perlner, Angela Y Robinson, Daniel C Smith -Tone, and Jacob Alperin -Sheriff. 2020. Status report on the second round of the NIST post -qu...

  44. [52]

    National Institute of Standards and Technology. 2001. Advanced encryption standard (AES) . National Institute of Standards and Technology, Gaithersburg, MD. https://doi.org/10.6028/NIST.FIPS.197

  45. [53]

    National Institute of Standards and Technology. 2024. Module-Lattice-Based Key-Encapsulation Mechanism Standard. National Institute of Standards and Technology, Gaithersburg, MD. https://doi.org/10.6028/NIST.FIPS.203

  46. [54]

    National Institute of Standards and Technology. 2024. Module-Lattice-Based Digital Signature Standard . National Institute of Standards and Technology, Gaithersburg, MD. https://doi.org/10.6028/NIST.FIPS.204

  47. [55]

    National Institute of Standards and Technology. 2024. Stateless Hash -Based Digital Signature Standard . National Institute of Standards and Technology, Gaithersburg, MD. https://doi.org/10.6028/NIST.FIPS.205

  48. [56]

    National Institute of Standards and Technology (NIST). 2016. Submission Requirements and Evaluation Criteria for the Post-Quantum Cryptography Standardization Process. Retrieved from https://csrc.nist.gov/CSRC/media/Projects/Post -Quantum-Cryptography/documents/call-for-propos...

  49. [57]

    Panos Papadimitratos. 2024. Secure Vehicular Communication Systems. In Encyclopedia of Cryptography, Security and Privacy , Sushil Jajodia, Pierangela Samarati and Moti Yung (eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 1–6. https://doi.org/10.1007/978-3-642-27739-9_643-2

  50. [58]

    Chris Peikert. 2016. A Decade of Lattice Cryptography. FNT in Theoretical Computer Science 10, 4 (2016), 283 –424. https://doi.org/10.1561/0400000074

  51. [59]

    John Proos and Christof Zalka. 2003. Shor’s discrete logarithm quantum algorithm for elliptic curves. (2003). https://doi.org/10.48550/ARXIV.QUANT-PH/0301141

  52. [60]

    C -V2X Technical Performance

    Qualcomm Technologies, Inc. C -V2X Technical Performance. Retrieved January 1, 2024 from https://www.qualcomm.com/content/dam/qcomm - martech/dm-assets/documents/c-v2x_technical_performance_faq.pdf

  53. [61]

    Prasanna Ravi, Anupam Chattopadhyay, Jan Pieter D’Anvers, and Anubhab Baksi. 2024. Side-channel and Fault-injection attacks over Lattice-based Post-quantum Schemes (Kyber, Dilithium): Survey and New Results. ACM Trans. Embed. Comput. Syst. 23, 2 (March 2024), 1 –54. https://do...

  54. [62]

    Prasanna Ravi, Dirmanto Jap, Shivam Bhasin, and Anupam Chattopadhyay. 2023. Invited Paper: Machine Learning Based Blind Side-Channel Attacks on PQC-Based KEMs - A Case Study of Kyber KEM. In 2023 IEEE/ACM International Conference on Computer Aided Design (ICCAD) , October 28, ...

  55. [63]

    R. L. Rivest, A. Shamir, and L. M. Adleman. 1978. A Method for Obtaining Digital Signature and Public-key Cryptosystems. Communications of the ACM 21, (1978). https://doi.org/10.1145/359340.359342

  56. [64]

    Sabani, Ilias K

    Maria E. Sabani, Ilias K. Savvas, and Georgia Garani. 2024. Learning with Errors: A Lattice-Based Keystone of Post-Quantum Cryptography. Signals 5, 2 (April 2024), 216–243. https://doi.org/10.3390/signals5020012

  57. [65]

    Kazi Hassan Shakib, Mizanur Rahman, and Mhafuzul Islam. 2023. Quantum Cyber -Attack on Blockchain -based VANET. https://doi.org/10.48550/ARXIV.2304.04411

  58. [66]

    Ari Shaller, Linir Zamir, and Mehrdad Nojoumian. 2023. Roadmap of post -quantum cryptography standardization: Side -channel attacks and countermeasures. Information and Computation 295, (December 2023), 105112. https://doi.org/10.1016/j.ic.2023.105112

  59. [67]

    Kyung-Ah Shim. 2022. A Survey on Post -Quantum Public -Key Signature Schemes for Secure Vehicular Communications. IEEE Trans. Intell. Transport. Syst. 23, 9 (September 2022), 14025–14042. https://doi.org/10.1109/TITS.2021.3131668

  60. [68]

    Peter W. Shor. 1995. Polynomial -Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. (1995). https://doi.org/10.48550/ARXIV.QUANT-PH/9508027

  61. [69]

    Siliang Suo, Chao Cui, Ganyang Jian, Xiaoyun Kuang, Yiwei Yang, Yun Zhao, and Kaitian Huang. 2020. Implementation of The High -Speed SM4 Cryptographic Algorithm Based On Random Pseudo Rounds. In 2020 IEEE International Conference on Information Technology,Big Data and Artifici...

  62. [70]

    Chengdong Tao, Albrecht Petzoldt, and Jintai Ding. 2020. Improved Key Recovery of the HFEv - Signature Scheme. Retrieved from https://eprint.iacr.org/2020/1424

  63. [71]

    Chengdong Tao, Albrecht Petzoldt, and Jintai Ding. 2021. Efficient Key Recovery for All HFE Signature Variants. In Advances in Cryptology – CRYPTO 2021, Tal Malkin and Chris Peikert (eds.). Springer International Publishing, Cham, 70–93. https://doi.org/10.1007/978-3-030-84242-0_4

  64. [72]

    Nariaki Tateiwa, Yuji Shinano, Masaya Yasuda, Shizuo Kaji, Keiichiro Yamamura, and Katsuki Fujisawa. 2024. Development and analysis of massive parallelization of a lattice basis reduction algorithm. Japan J. Indust. Appl. Math. 41, 1 (January 2024), 13 –56. https://doi.org/10....

  65. [73]

    Geoff Twardokus, Nina Bindel, Hanif Rahbari, and Sarah McCarthy. 2024. When Cryptography Needs a Hand: Practical Post-Quantum Authentication for V2V Communications. In Proceedings 2024 Network and Distributed System Security Symposium, 2024. Internet Society, San Diego, CA, US...

  66. [74]

    United States Department of Transportation (USDOT). 2024. ARC -IT v9.2: Architecture Reference for Cooperative and Intelligent Transportation. ARC-IT. Retrieved July 25, 2024 from https://www.arc-it.net/

  67. [75]

    V2X Communications Message Set Dictionary

    V2X Core Technical Committee. V2X Communications Message Set Dictionary. https://doi.org/10.4271/J2735_202409

  68. [76]

    Antonio Virdis, Giovanni Stea, and Giovanni Nardini. 2014. SimuLTE – A Modular System -level Simulator for LTE/LTE -A Networks based on OMNeT++: In Proceedings of the 4th International Conference on Simulation and Modeling Methodologies, Technologies and Applications , 2014. S...

  69. [77]

    Gang Xiong, Fenghua Zhu, Xiwei Liu, Xisong Dong, Wuling Huang, Songhang Chen, and Kai Zhao. 2015. Cyber-physical-social system in intelligent transportation. IEEE/CAA J. Autom. Sinica 2, 3 (July 2015), 320–333. https://doi.org/10.1109/JAS.2015.7152667

  70. [78]

    Yingpeng Xu, Lin Han, Zhe Yu, and Fang Che. 2022. Optimized Design Implementation and Research of SM3 Hash Algorithm Based on FPGA. In 2022 2nd International Conference on Computer Science and Blockchain (CCSB) , October 2022. IEEE, Wuhan, China, 111 –117. https://doi.org/10.1...

  71. [79]

    Xue Zhang, Zhongxiang Zheng, and Xiaoyun Wang. 2022. A detailed analysis of primal attack and its variants. Sci. China Inf. Sci. 65, 3 (March 2022), 132301. https://doi.org/10.1007/s11432-020-2958-9

  72. [80]

    Falcon - Fast-Fourier Lattice-based Compact Signatures over NTRU. Falcon. Retrieved July 25, 2024 from https://falcon-sign.info/

  73. [81]

    BIKE - Bit Flipping Key Encapsulation. BIKE. Retrieved July 25, 2024 from https://bikesuite.org/

  74. [82]

    Classic McEliece

    Classic McEliece. Classic McEliece. Retrieved July 25, 2024 from https://classic.mceliece.org/

  75. [83]

    HQC - Hamming Quasi-Cyclic. HQC. Retrieved July 25, 2024 from https://pqc-hqc.org/

  76. [84]

    SIKE – Supersingular Isogeny Key Encapsulation. SIKE. Retrieved July 25, 2024 from https://sike.org/

  77. [85]

    GeMSS: A Great Multivariate Short Signature. GeMSS. Retrieved July 25, 2024 from https://www-polsys.lip6.fr/Links/NIST/GeMSS.html

  78. [86]

    Rainbow Signature. Rainbow. Retrieved July 25, 2024 from https://www.pqcrainbow.org/

  79. [87]

    https://doi.org/10.1109/IEEESTD.2022.9810154

    IEEE Standard for Wireless Access in Vehicular Environments (WAVE) - Certificate Management Interfaces for End Entities. https://doi.org/10.1109/IEEESTD.2022.9810154

  80. [88]

    Retrieved November 14, 2024 from https://www.ibm.com/roadmaps/quantum/

    IBM Quantum Roadmap. Retrieved November 14, 2024 from https://www.ibm.com/roadmaps/quantum/

  81. [89]

    Retrieved November 14, 2024 from https://quantumai.google/roadmap

    Google Quantum Computing Roadmap. Retrieved November 14, 2024 from https://quantumai.google/roadmap

  82. [90]

    Retrieved November 14, 2024 from https://www.quantinuum.com/press -releases/quantinuum-unveils- accelerated-roadmap-to-achieve-universal-fault-tolerant-quantum-computing-by-2030

    Quantinuum Quantum Computing Roadmap. Retrieved November 14, 2024 from https://www.quantinuum.com/press -releases/quantinuum-unveils- accelerated-roadmap-to-achieve-universal-fault-tolerant-quantum-computing-by-2030

  83. [91]

    Retrieved November 1, 2024 from https://omnetpp.org/

    OMNeT++. Retrieved November 1, 2024 from https://omnetpp.org/

  84. [92]

    Retrieved November 1, 2024 from https://inet.omnetpp.org/

    INET Framework. Retrieved November 1, 2024 from https://inet.omnetpp.org/

  85. [93]

    INET Framework

    INET Mobility Models. INET Framework. Retrieved November 1, 2024 from https://inet.omnetpp.org/docs/showcases/mobility/basic/doc/

  86. [94]

    Retrieved November 1, 2024 from https://openquantumsafe.org/liboqs/

    liboqs. Retrieved November 1, 2024 from https://openquantumsafe.org/liboqs/

  87. [95]

    Retrieved from https://openssl-library.org/

    OpenSSL. Retrieved from https://openssl-library.org/

  88. [2018]

    https://doi.org/10.1109/EuroSP.2018.00032

    IEEE, London, 353–367. https://doi.org/10.1109/EuroSP.2018.00032

  89. [2024]

    https://doi.org/10.1109/ISQED60706.2024.10528674

    IEEE, San Francisco, CA, USA, 1–8. https://doi.org/10.1109/ISQED60706.2024.10528674

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.