OG
Olivier Gillot
— On the schedule —
Post-Quantum Cryptography on a Budget: Benchmarking ML-KEM and ML-DSA on Constrained IoT Hardware
With Q-day approaching, post-quantum cryptography is no longer optional, but is it viable on the small, constrained devices that make up much of the IoT? This talk presents real, measured benchmarks of NIST-standardised algorithms (ML-KEM, ML-DSA, SLH-DSA) against classical RSA and elliptic-curve cryptography, across nine real devices ranging from Raspberry Pi single-board computers to bare-metal microcontrollers, using OpenSSL 3.5 and wolfSSL. The results challenge a common assumption: on the most constrained hardware, post-quantum key exchange is often faster and more energy-efficient than the classical algorithms it's replacing. Attendees will see a live, on-stage demonstration of all nine devices running real TLS 1.3 handshakes side by side, watching the performance differences happen in real time.
— Compositor's note —
I'm an MSc Cybersecurity student at Edinburgh Napier University, supervised by Professor Bill Buchanan, currently completing a dissertation on the viability of post-quantum cryptography on constrained IoT hardware. My benchmarking work spans NIST-standardised algorithms (ML-KEM, ML-DSA, SLH-DSA) across devices from Raspberry Pi single-board computers to bare-metal microcontrollers, measuring both computational performance and energy consumption using OpenSSL 3.5 and wolfSSL. This research produced my first published paper, "Energy Consumption of Post-Quantum Cryptography on Constrained and General-Purpose Architectures" (Cryptography, MDPI, 2026), and a follow-up study benchmarking full TLS 1.3 PQC handshakes across a 36-combination algorithm matrix on microcontroller-class devices. Originally from Belgium, I've called Scotland home for over a decade, and I'm looking forward to meeting you all and sharing this work in Prague.