Post-Quantum Cryptography: A Systematic Review of Algorithms, Standardization, Challenges, and Future Research Directions

Aritrik Ghosh

SSRN Electronic Journal · 2026

The prospect of cryptographically relevant quantum computers (CRQCs) capable of running Shor's algorithm threatens the RSA, Diffie-Hellman, and elliptic-curve schemes that underpin most public-key infrastructure [1]. In response, the U.S. National Institute of Standards and Technology (NIST) ran an eight-year, multi-round public competition that produced the first three post-quantum cryptography (PQC) Federal Information Processing Standards in August 2024, with a fourth key-encapsulation mechanism selected in March 2025 [2]-[6].

This paper presents a systematic literature review, conducted according to the PRISMA 2020 reporting guideline [7], of the algorithmic families, standardization outcomes, comparative performance, security assumptions, and deployment challenges associated with post-quantum cryptography. A structured search of IEEE Xplore, ACM Digital Library, SpringerLink, the IACR Cryptology ePrint Archive, arXiv (cs.CR), and the NIST Computer Security Resource Center identified 124 candidate records; after de-duplication, title/abstract screening, and full-text eligibility assessment, 47 sources were retained for synthesis (Section III, Fig. 2).

We synthesize findings across lattice-based, code-based, hash-based, multivariate, and isogeny-based constructions, examining the lattice schemes standardized by NIST-ML-KEM (from CRYSTALS-Kyber) and ML-DSA (from CRYSTALS-Dilithium)-alongside the hash-based SLH-DSA (from SPHINCS+), the still-unfinished Falcon-derived FN-DSA standard, and the code-based candidates Classic McEliece, BIKE, and HQC. Beyond a comparative taxonomy of key size, ciphertext/signature size, computational cost, and security assumption, the review foregrounds four points of unresolved tension that the primary literature does not treat as settled: why NIST selected HQC over BIKE despite BIKE's smaller keys; why the Falcon-derived signature standard (FIPS 206) remains in draft nearly two years after its lattice-based siblings were finalized; what structural limitations remain in ML-KEM even after standardization; and which of the currently standardized hardness assumptions is best positioned to survive future cryptanalytic advances. The paper concludes with a discussion of contributions, limitations, threats to validity, and a research agenda spanning key management, cryptographic agility, lightweight PQC, side-channel resistance, and migration planning.