{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:23:24Z","timestamp":1776781404523,"version":"3.51.2"},"reference-count":58,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The efficiency of Shor\u2019s and Grover\u2019s algorithms and the advancement of quantum computers implies that the cryptography used until now to protect one\u2019s privacy is potentially vulnerable to retrospective decryption, also known as the harvest now, decrypt later attack in the near future. This dissertation proposes an overview of the cryptographic schemes used by Tor, highlighting the non-quantum-resistant ones and introducing theoretical performance assessment methods of a local Tor network. The measurement is divided into three phases. We start with benchmarking a local Tor network simulation on constrained devices to isolate the time taken by classical cryptography processes. Secondly, the analysis incorporates existing benchmarks of quantum-secure algorithms and compares these performances on the devices. Lastly, the estimation of overhead is calculated by replacing the measured times of traditional cryptography with the times recorded for Post-Quantum Cryptography (PQC) execution within the specified Tor environment. By focusing on the replaceable cryptographic components, using theoretical estimations, and leveraging existing benchmarks, valuable insights into the potential impact of PQC can be obtained without needing to implement it fully.<\/jats:p>","DOI":"10.3390\/jcp5020013","type":"journal-article","created":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T11:17:57Z","timestamp":1743506277000},"page":"13","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Post-Quantum Migration of the Tor Application"],"prefix":"10.3390","volume":"5","author":[{"given":"Denis","family":"Berger","sequence":"first","affiliation":[{"name":"Blockpass ID Lab, Edinburgh Napier University, Edinburgh EH10 5DT, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0114-1054","authenticated-orcid":false,"given":"Mouad","family":"Lemoudden","sequence":"additional","affiliation":[{"name":"Blockpass ID Lab, Edinburgh Napier University, Edinburgh EH10 5DT, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0809-3523","authenticated-orcid":false,"given":"William J.","family":"Buchanan","sequence":"additional","affiliation":[{"name":"Blockpass ID Lab, Edinburgh Napier University, Edinburgh EH10 5DT, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,4,1]]},"reference":[{"key":"ref_1","unstructured":"Shor, P. (1994, January 20\u201322). Algorithms for quantum computation: Discrete logarithms and factoring. Proceedings of the 35th Annual Symposium on Foundations of Computer Science, Santa Fe, NM, USA."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Grover, L.K. (1996, January 22\u201324). A fast quantum mechanical algorithm for database search. Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing, Philadelphia, PA, USA.","DOI":"10.1145\/237814.237866"},{"key":"ref_3","unstructured":"(2024, September 20). TOR Metrics. Available online: https:\/\/metrics.torproject.org\/."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Dingledine, R., and Syverson, P. (2004, January 9\u201313). Tor: The Second-Generation Onion Router. Proceedings of the USENIX Security Symposium, San Diego, CA, USA.","DOI":"10.21236\/ADA465464"},{"key":"ref_5","unstructured":"(2024, September 18). Tor Proposals. Available online: https:\/\/spec.torproject.org\/proposals\/."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"433","DOI":"10.22331\/q-2021-04-15-433","article-title":"How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits","volume":"5","author":"Gidney","year":"2021","journal-title":"Quantum"},{"key":"ref_7","unstructured":"Raimondo, G.M., and Locascio, L.E. (2024). FIPS 204 Federal Information Processing Standards Publication Module-Lattice-Based Digital Signature Standard. Nist Natl. Inst. Stand. Technol., 55."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Moody, D., Perlner, R., Regenscheid, A., Robinson, A., and Cooper, D. (2024). Transition to Post-Quantum Cryptography Standards, National Institute of Standards and Technology. NIST Internal Report 8547.","DOI":"10.6028\/NIST.IR.8547.ipd"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Goldberg, I., and Cheriton, D.R. (2006). On the Security of the Tor Authentication Protocol. International Workshop on Privacy Enhancing Technologies, Springer.","DOI":"10.1007\/11957454_18"},{"key":"ref_10","unstructured":"(2024, September 21). Tor Specifications. Available online: https:\/\/spec.torproject.org\/tor-spec\/index.html."},{"key":"ref_11","first-page":"219","article-title":"Circuit-extension handshakes for Tor achieving forward secrecy in a quantum world","volume":"2016","author":"Schanck","year":"2015","journal-title":"Cryptol. Eprint Arch."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1007\/s10623-011-9604-z","article-title":"Anonymity and one-way authentication in key exchange protocols","volume":"67","author":"Goldberg","year":"2013","journal-title":"Des. Codes Cryptogr."},{"key":"ref_13","first-page":"263","article-title":"Post-Quantum Forward-Secure Onion Routing (Future Anonymity in Today\u2019s Budget)","volume":"9092","author":"Ghosh","year":"2015","journal-title":"Cryptol. Eprint Arch."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"336","DOI":"10.2478\/popets-2020-0030","article-title":"T0RTT: Non-Interactive Immediate Forward-Secret Single-Pass Circuit Construction","volume":"2020","author":"Lauer","year":"2020","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref_15","first-page":"259","article-title":"Untagging tor: A formal treatment of onion encryption","volume":"Volume 10822","author":"Degabriele","year":"2018","journal-title":"Proceedings of the Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Rogaway, P., and Zhang, Y. (2018). Onion-AE: Foundations of Nested Encryption. Proc. Priv. Enhancing Technol., 85\u2013104.","DOI":"10.1515\/popets-2018-0014"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Jaques, S., Naehrig, M., Roetteler, M., and Virdia, F. (2020, January 11\u201315). Implementing Grover Oracles for Quantum Key Search on AES and LowMC. Proceedings of the EUROCRYPT 2020, Virtual Conference.","DOI":"10.1007\/978-3-030-45724-2_10"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1007\/s00145-021-09384-1","article-title":"A Cryptographic Analysis of the TLS 1.3 Handshake Protocol","volume":"34","author":"Dowling","year":"2021","journal-title":"J. Cryptol."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Schwabe, P., Stebila, D., and Wiggers, T. (2020, January 9). Post-Quantum TLS Without Handshake Signatures. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA. Technical Report 2020\/534, IACR Cryptology ePrint Archive.","DOI":"10.1145\/3372297.3423350"},{"key":"ref_20","unstructured":"Perrin, T. (2024, October 08). The Noise Protocol Framework, 2018. Revision 34, Status: Official. Available online: https:\/\/noiseprotocol.org\/."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Schwabe, P., Stebila, D., and Wiggers, T. (2021). More efficient post-quantum KEMTLS with pre-distributed public keys. Computer Security\u2014ESORICS 2021, Proceedings of the European Symposium on Research in Computer Security, Darmstadt, Germany, 4\u20138 October 2021, Springer. Cryptology ePrint Archive, Paper 2021\/779.","DOI":"10.1007\/978-3-030-88418-5_1"},{"key":"ref_22","unstructured":"Stebila, D., Fluhrer, S., and Gueron, S. (2024, November 11). Hybrid Key Exchange in TLS 1.3. Internet-Draft Draft-Ietf-Tls-Hybrid-Design-11, Internet Engineering Task Force. Available online: https:\/\/datatracker.ietf.org\/doc\/draft-ietf-tls-hybrid-design\/."},{"key":"ref_23","unstructured":"Langley, A. (2024, September 14). CECPQ2: Post-Quantum Confidentiality in TLS. Available online: https:\/\/www.imperialviolet.org\/2018\/12\/12\/cecpq2.html."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"104272","DOI":"10.1016\/j.cose.2024.104272","article-title":"Evaluation Framework for Quantum Security Risk Assessment: A Comprehensive Study for Quantum-Safe Migration","volume":"150","author":"Baseri","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_25","unstructured":"Barker, E., Dang, Q., and Hanon, N. (2020). NIST Special Publication 800-57 Part 1, Revision 5: Recommendation for Key Management, Part 1: General, National Institute of Standards and Technology. Technical Report 800-57pt1r5."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"551","DOI":"10.5220\/0010903000003120","article-title":"Post Quantum Cryptography Analysis of TLS Tunneling on a Constrained Device","volume":"1","author":"Barton","year":"2022","journal-title":"Proceedings of the 8th International Conference on Information Systems Security and Privacy\u2014ICISSP"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Alagic, G., Apon, D., Cooper, D., Dang, Q., Dang, T., Kelsey, J., Lichtinger, J., Liu, Y.K., Miller, C., and Moody, D. (2022). Status Report on the Third Round of NIST Post-Quantum Cryptography Standardization Process, National Institute of Standards and Technology.","DOI":"10.6028\/NIST.IR.8413"},{"key":"ref_28","unstructured":"Kret, E., and Schmidt, R. (2024, January 23). The PQXDH Key Agreement Protocol. Revision 3. Available online: https:\/\/signal.org\/docs\/specifications\/pqxdh\/pqxdh.pdf."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Cheng, H., Gro\u00dfsch\u00e4dl, J., R\u00f8nne, P.B., and Ryan, P.Y.A. (2021, January 1\u20135). AVRNTRU: Lightweight NTRU-based Post-Quantum Cryptography for 8-bit AVR Microcontrollers. Proceedings of the DATE 2021: Design, Automation and Test in Europe, Virtual Conference.","DOI":"10.23919\/DATE51398.2021.9474033"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Chuengsatiansup, C., Lange, T., and van Vredendaal, C. (2017, January 16\u201318). NTRU Prime: Reducing attack surface at low cost. Proceedings of the Selected Areas in Cryptography\u2013SAC 2017: 24th International Conference, Ottawa, ON, Canada.","DOI":"10.1007\/978-3-319-72565-9_12"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Bos, J.W., Bronchain, O., Custers, F., Renes, J., Verbakel, D., and van Vredendaal, C. (2023). Enabling FrodoKEM on Embedded Devices. Cryptol. Eprint Arch., Available online: https:\/\/eprint.iacr.org\/2023\/158.","DOI":"10.46586\/tches.v2023.i3.74-96"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Bos, J.W., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J.M., Schwabe, P., Seiler, G., and Stehl\u00e9, D. (2018, January 24\u201326). CRYSTALS\u2014Kyber: A CCA-Secure Module-Lattice-Based KEM. Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), London, UK.","DOI":"10.1109\/EuroSP.2018.00032"},{"key":"ref_33","unstructured":"Raimondo, G.M., and Locascio, L.E. (2024). FIPS 203 Federal Information Processing Standards Publication Module-Lattice-Based Key-Encapsulation Mechanism Standard. Nist Natl. Inst. Stand. Technol., 47."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1007\/s43926-024-00069-2","article-title":"Comparative analysis of lattice-based cryptographic schemes for secure IoT communications","volume":"4","author":"Kwala","year":"2024","journal-title":"Discov. Internet Things"},{"key":"ref_35","unstructured":"(2024, October 08). Open Quantum Safe, Liboqs. Available online: https:\/\/openquantumsafe.org."},{"key":"ref_36","unstructured":"Melchor, C.A., Aragon, N., Bettaieb, S., Bidoux, L., Blazy, O., Bos, J., Deneuville, J.C., Arnaud Dion, P.G., Lacan, J., and Persichetti, E. (2024, November 04). Hamming Quasi-Cyclic (HQC) Fourth Round Specification. Technical report, SandboxAQ, Univ. of Limoges, TII, Ecole Polytechnique, Worldline, ENAC, ISAE Supaero, Florida Atlantic Univ., Univ. of Toulon, Univ. of Bordeaux. Available online: https:\/\/pqc-hqc.org\/."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Rescorla, E. (2024, November 04). The Transport Layer Security (TLS) Protocol Version 1.3. Request for Comments 8446, 2018. Standards Track. Available online: https:\/\/datatracker.ietf.org\/doc\/rfc8446\/.","DOI":"10.17487\/RFC8446"},{"key":"ref_38","unstructured":"F\u00e6r\u00f8y, A.H. (2024, November 11). BoringSSL Tor Fork. Branch: Ahf\/boringssl. Available online: https:\/\/gitlab.torpaper.org\/ahf\/tor\/-\/commits\/ahf%2Fboringssl."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Ding, J., and Tillich, J.P. (2020). Benchmarking Post-quantum Cryptography in TLS. Post-Quantum Cryptography, Springer International Publishing.","DOI":"10.1007\/978-3-030-44223-1"},{"key":"ref_40","first-page":"hal-04845617","article-title":"A Comprehensive Survey on Post-Quantum TLS","volume":"1","author":"Alnahawi","year":"2024","journal-title":"Iacr Commun. Cryptol."},{"key":"ref_41","first-page":"59","article-title":"Key Exchange with Tight (Full) Forward Secrecy via Key Confirmation","volume":"14657","author":"Pan","year":"2024","journal-title":"Cryptol. Eprint Arch."},{"key":"ref_42","first-page":"401","article-title":"Tighter Security for Generic Authenticated Key Exchange in the QROM","volume":"14441","author":"Pan","year":"2023","journal-title":"Cryptol. Eprint Arch."},{"key":"ref_43","unstructured":"Eaton, E., Stebila, D., and Stracovsky, R. (2024, November 16). Post-Quantum Key-Blinding for Authentication in Anonymity Networks. A Compressed Version Appears in the Proceedings of Latincrypt 2021. Available online: https:\/\/eprint.iacr.org\/2021\/963.pdf."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Kampanakis, P., and Childs-Klein, W. (2024). The impact of data-heavy, post-quantum TLS 1.3 on the Time-To-Last-Byte of real-world connections. Cryptol. Eprint Arch., Paper 2024\/176.","DOI":"10.14722\/madweb.2024.23010"},{"key":"ref_45","unstructured":"Group, L.W. (2024, November 13). Stateless Hash-Based Digital Signature Algorithms (SLH-DSA) in X.509 Public Key Infrastructure (PKI). Internet-Draft Draft-Ietf-Lamps-x509-slhdsa-02, Internet Engineering Task Force. Available online: https:\/\/datatracker.ietf.org\/doc\/draft-ietf-lamps-x509-slhdsa\/."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Sikeridis, D., Kampanakis, P., and Devetsikiotis, M. (2020). Post-Quantum Authentication in TLS 1.3: A Performance Study. Cryptol. Eprint Arch., Paper 2020\/071.","DOI":"10.14722\/ndss.2020.24203"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Dolev, S., Katz, J., and Meisels, A. (2022). Faster Post-Quantum TLS Handshakes Without Intermediate CA Certificates. Cyber Security, Cryptology, and Machine Learning, Springer International Publishing.","DOI":"10.1007\/978-3-031-07689-3"},{"key":"ref_48","unstructured":"Misell, Q. (2024, November 12). Automated Certificate Management Environment (ACME) Extensions for \u201c.onion\u201d Special-Use Domain Names. Internet-Draft Draft-Ietf-Acme-Onion-04, Internet Engineering Task Force (IETF). Available online: https:\/\/acmeforonions.org\/."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TQE.2022.3233526","article-title":"Applying Grover\u2019s Algorithm to Hash Functions: A Software Perspective","volume":"3","author":"Preston","year":"2023","journal-title":"IEEE Trans. Quantum Eng."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Alagic, G., Bros, M., Ciadoux, P., Cooper, D., Dang, Q., Dang, T., Kelsey, J., Lichtinger, J., Liu, Y.K., and Miller, C. (2024). Status Report on the First Round of the Additional Digital Signature Schemes for NIST Post-Quantum Cryptography Standardization Process, National Institute of Standards and Technology. NIST Internal Report 8528.","DOI":"10.6028\/NIST.IR.8528"},{"key":"ref_51","first-page":"581","article-title":"Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures From VOLE-in-the-Head","volume":"14085","author":"Baum","year":"2023","journal-title":"Cryptol. Eprint Arch."},{"key":"ref_52","first-page":"423","article-title":"An efficient key recovery attack on SIDH","volume":"14008","author":"Castryck","year":"2022","journal-title":"Cryptol. Eprint Arch."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Rahman, M.S., DiAdamo, S., Mehic, M., and Fleming, C. (2024, January 1\u20133). Quantum Secure Anonymous Communication Networks. Proceedings of the 2024 International Conference on Quantum Communications, Networking, and Computing (QCNC), Kanazawa, Japan.","DOI":"10.1109\/QCNC62729.2024.00060"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Zhang, Y., Portokalidis, G., and Xu, J. (2022, January 10\u201314). Towards Understanding the Runtime Performance of Rust. Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201922), New York, NY, USA.","DOI":"10.1145\/3551349.3559494"},{"key":"ref_55","unstructured":"DAST, and Team, E.D. (2024, November 19). iPerf: The Network Bandwidth Measurement Tool. NLANR and ESnet. Available online: https:\/\/github.com\/esnet\/iperf."},{"key":"ref_56","unstructured":"(2024, November 21). QSOR: Quantum-Safe Onion Routing. Available online: https:\/\/arxiv.org\/pdf\/2001.03418."},{"key":"ref_57","unstructured":"Evgnosia-Alexandra, K. (2021). A note on Post Quantum Onion Routing. Cryptol. Eprint Arch., Available online: https:\/\/eprint.iacr.org\/2021\/111."},{"key":"ref_58","unstructured":"(2024, November 13). PlanetLab Europe. Available online: https:\/\/www.planet-lab.eu\/."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/2\/13\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:07:55Z","timestamp":1760029675000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/2\/13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,1]]},"references-count":58,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,6]]}},"alternative-id":["jcp5020013"],"URL":"https:\/\/doi.org\/10.3390\/jcp5020013","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,1]]}}}