Post‐Quantum Cryptography for Smart City Cybersecurity: An Evaluation of PQC Algorithms Across IoT–Edge–Cloud Layers
Ahmed Alrowaili, Sehmus Can Ozmen, Muhammad Kazim, Mujeeb Ur RehmanABSTRACT
Smart cities are built on a vast interconnected network of Internet of things (IoT), edge and cloud systems to optimise urban services and enhance the quality of life for the residents. However, this integration of cyber‐physical infrastructure expands the attack surface, making it vulnerable to advanced cyber threats. The most notable emerging threat is quantum computers, which can break the classical cryptographic algorithms, such as RSA and ECC, that form the foundation of cybersecurity. Integrating liboqs execution benchmarks with an analytical network fragmentation model simulated with NS‐3, evaluating NIST‐approved PQC key encapsulation mechanisms, ML‐KEM (Kyber512/768/1024), HQC (128/192/256) and classic McEliece variants, alongside signature schemes ML‐DSA (Dilithium), Falcon and SLH‐DSA (SPHINCS+) within a smart city network. We also extended the benchmarking to include NIST's SP 800‐230 draft and provide preliminary benchmarks of the six new parameter sets. To assess embedded feasibility, all algorithms are additionally executed on the ESP32 P4 microcontroller, measuring timing, energy consumption and memory under resource‐constrained conditions. This dual platform methodology enables cross‐validation of network‐level overhead and hardware‐level performance. Results show consistent behaviour across platforms. ML KEM 512 (NIST Security Level 1) provides the best KEM performance, with key generation at 7.2 µs (NS‐3) and 122.6 ms (ESP32 P4), and similarly efficient encapsulation/decapsulation. ML DSA 44 (NIST Security Level 2) achieves the fastest signatures at 64 µs on NS‐3 and 490.6 ms on ESP32 P4. These findings provide evidence‐based guidelines for deploying postquantum cryptography across smart city IoT–Edge–Cloud infrastructures, emphasising crypto‐agility and hybrid cryptography for smart city networks.