From Harvest-Now-Decrypt-Later to Quantum-Safe 5G/IoT: Architectural Friction, Practical Mitigations, and a Cryptographic Agility Roadmap
Do Thi Bac, May Thu Duong
SSRN Electronic Journal · 2026
The imminent threat of cryptographically relevant quantum computers (CRQCs) endangers the asymmetric foundations of 5G andInternet of Things (IoT) security, enabling "Harvest Now, Decrypt Later" (HNDL) attacks on classically encrypted traffic with longconfidentiality lifetimes. While NIST’s 2024 Post-Quantum Cryptography (PQC) standards (ML-KEM, ML-DSA, SLH-DSA)provide quantum-resistant primitives, their direct integration into 5G/IoT ecosystems encounters severe architectural friction exemplifiedby the 372-byte SIB1 bottleneck, extensive fragmentation delays, and prohibitive energy overheads on resource constrainedendpoints. This survey systematically analyzes these incompatibilities through comparative performance metrics, protocol-levelchallenges, and analytical/empirical assessments, revealing that vanilla PQC adoption is theoretically infeasible for real time andultra-low-power applications.
However, practical mitigations hybrid cryptographic frameworks, hardware acceleration, signaturefreeauthentication, and secure fragmentation consistently reduce overheads to viable levels, as demonstrated in benchmarks andindustry pilots. We propose a phased cryptographic agility roadmap aligned with 3GPP Release 19–21 and NIST timelines: ahybrid transition era (2025–2030) for immediate HNDL protection, followed by full PQC sovereignty post-2030. By balancingpessimistic theoretical barriers with engineering-driven solutions, this work provides actionable guidance for standards bodies,network operators, and researchers to secure next-generation connected infrastructure against the quantum horizon.