between the user and kernel spaces, thus increas-
ing the throughput of the file transfer.
• Authentication Improvement: Authentication of
the encryptor sides is not currently quantum re-
sistant if pre-shared PQC keys are not used. This
extension would add a certification authority and
certificates with PQC elements for authentication
to mitigate the potential man-in-the-middle at-
tacks by a quantum adversary.
• Hardware Acceleration: The software may
be adapted to be compatible with hardware-
accelerated solution described in (Ricci et al.,
2024).
7 CONCLUSION
In this article, we introduced an open-source
quantum-resistant encryption system for real-time
data transfer that can be used in site-to-site settings.
The system utilizes a combination of several differ-
ent quantum-resistant key-establishment methods to
add extra layers of security. The software can be used
as a low-cost demonstrator and experimental tool for
testing PQC. This could also be used for system
demonstration to companies seeking high throughput
before purchasing high-speed solutions like FPGA-
accelerated solutions. Therefore, it serves as a tool to
raise awareness and support of post-quantum cryptog-
raphy deployment and integration to existing systems.
The implementation of the proposed system is freely
accessible at (Tuma and Havlin, 2024).
ACKNOWLEDGEMENTS
Funded by the European Union under Grant Agree-
ment No. 101087529. Views and opinions expressed
are however those of the author(s) only and do not
necessarily reflect those of the European Union or Eu-
ropean Research Executive Agency. Neither the Eu-
ropean Union nor the granting authority can be held
responsible for them.
This work is supported by the Ministry of the Inte-
rior of the Czech Republic under Grant VJ01010008.
REFERENCES
Aguilera, A. C., Clemente, X. A. i., Lawo, D., Monroy, I. T.,
and Olmos, J. V. (2023). First end-to-end pqc pro-
tected dpu-to-dpu communications. Electronics Let-
ters, 59(17):e12901.
Avanzi, R., Bos, J., Ducas, L., Kiltz, E., Lepoint, T., Lyuba-
shevsky, V., Schanck, J. M., Schwabe, P., Seiler, G.,
and Stehl
´
e, D. (2019). Crystals-kyber algorithm spec-
ifications and supporting documentation. NIST PQC
Round, 2(4):1–43.
Bae, S., Chang, Y., Park, H., Kim, M., and Shin, Y. (2022).
A performance evaluation of ipsec with post-quantum
cryptography. In International Conference on In-
formation Security and Cryptology, pages 249–266.
Springer.
Bonnetain, X., Naya-Plasencia, M., and Schrottenloher, A.
(2019). Quantum security analysis of aes. IACR
Transactions on Symmetric Cryptology, 2019(2):55–
93.
Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V.,
Schwabe, P., Seiler, G., and Stehl
´
e, D. (2018).
Crystals-dilithium: A lattice-based digital signature
scheme. IACR Transactions on Cryptographic Hard-
ware and Embedded Systems, pages 238–268.
ETSI (2019). Etsi gs qkd 014: Quantum key distribution
(qkd) protocol and data format of rest-based key de-
livery api. https://www.etsi.org/deliver/etsi gs/QKD/
001 099/014/01.01.01 60/gs qkd014v010101p.pdf.
Frankel, S. and Krishnan, S. (2011). Ip security (ipsec) and
internet key exchange (ike) document roadmap. Tech-
nical report.
Marrok, A., Boukhelef, S., and Chikouche, N. (2022). Pqh-
wireguard: Post-quantum hybrid cryptography-based
wireguard vpn protocol. In International Conference
on Information Technology and Applications, pages
283–292. Springer.
Ricci, S., Dobias, P., Malina, L., Hajny, J., and Jedlicka, P.
(2024). Hybrid keys in practice: Combining classi-
cal, quantum and post-quantum cryptography. IEEE
Access.
Rossi, M. (2023). Pqc transition in france anssi views. In
Real World Post-Quantum Crypto.
Roy, A. (2023). kyber. https://github.com/itzmeanjan/kyber.
Schatz, D., Altheide, F., Koerfgen, H., Rossberg, M., and
Schaefer, G. (2023). Virtual private networks in the
quantum era: A security in depth approach. pages
486–494.
Tuma, P. and Havlin, J. (2024). Linux network traffic
encryptor. https://github.com/gabsssq/Linux-network-
traffic-encryptor.
van Heesch, M., van Adrichem, N., Attema, T., and Veugen,
T. (2019). Towards quantum-safe vpns and internet.
Cryptology ePrint Archive.
Wei, D. (2023). Crypto++ library. http:// www.cryptopp.c
om/.
Open-Source Post-Quantum Encryptor: Design, Implementation and Deployment
831