Simulation reveals network conditions outweigh cryptographic algorithm choice in MQTT-over-TLS 1.3 performance, indicating ML-KEM-768 viability for IoT-to-cloud security.
The expected arrival of cryptographically relevant quantum computers requires Internet of Things (IoT) communication infrastructure to migrate to Post-Quantum Cryptography (PQC). However, it remains unclear how this migration affects protocol-level performance of IoT communication under controlled network degradation rather than algorithm cost alone. We used the PQC-IoTNet SITL framework to benchmark ML-KEM-768, the NIST-standardized post-quantum Key Encapsulation Mechanism, against RSA-2048 and ECC-P256 in MQTT-over-TLS 1.3 IoT-to-cloud communication across 20 network scenarios (five latency levels × four packet loss levels) and three algorithms (60 algorithm network configurations, 3000 trials). The principal finding is that network conditions, rather than cryptographic algorithm choice, dominate protocol-level performance. Under normal network conditions, ML-KEM-768 showed handshake performance comparable to the classical algorithms, while under degraded conditions, algorithm-level differences remained small relative to network-driven variance. Also, ML-KEM-768 showed an approximately 2.5 ms CPU-time advantage under congestion and an absolute peak Python-process RSS within 0.1 MB of the classical configurations, at the cost of 6.7% more bytes transmitted than RSA-2048 (1.3% fewer than ECC-P256). Connection reliability was 99.8% for ML-KEM-768 compared with 100% for RSA-2048 and ECC-P256. The only two unsuccessful connection attempts observed in the entire study occurred with ML-KEM-768 under high-impairment conditions. However, Fisher’s exact test indicated that this difference was not statistically significant at the present sample size (p = 0.50). These findings, within the evaluated SITL environment, indicate that ML-KEM-768 delivers protocol-level performance comparable to RSA-2048 and ECC-P256 under the tested network conditions while providing a standardized post-quantum key establishment mechanism for MQTT-based IoT communication. Further validation on resource-constrained hardware is required before generalizing these results to production IoT deployments.
No takes yet. Share an insight, caveat, or question.
Almutairi et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: