Skip navigation

PQ-OTSec: a post-quantum secure key exchange framework for Operational Technology protocols

PQ-OTSec: a post-quantum secure key exchange framework for Operational Technology protocols

Muhammad, Nasir, Sani, Abubakar Sadiq, Yuan, Dong, Sakellari, Georgia ORCID logoORCID: https://orcid.org/0000-0001-7238-8700 and Loukas, George ORCID logoORCID: https://orcid.org/0000-0003-3559-5182 (2026) PQ-OTSec: a post-quantum secure key exchange framework for Operational Technology protocols. In: 2026 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm) College Station, Texas, USA, 26th - 29th October 2026. IEEE Xplore . Institute of Electrical and Electronics Engineers (IEEE), Piscataway, New Jersey. (In Press)

[thumbnail of Author's Accepted Manuscript]
Preview
PDF (Author's Accepted Manuscript)
54387 SANI_PQ-OTSec_A_Post-Quantum_Secure_Key_Exchange_(IEEE AAM)_2026.pdf - Accepted Version
Available under License Creative Commons Attribution.

Download (1MB) | Preview

Abstract

Security mechanisms for Operational Technology (OT) protocols like Modbus/TCP Security, DNP3-SAv6 and Profinet Security protect the underlying protocols that govern how industrial automation systems communicate. However, these solutions are dependent on classical cryptography and lack the agility to withstand the emerging threat posed by quantum computing, which breaks or weakens classical cryptography. Furthermore, the increasing sophistication of classical cyberattacks on industrial control systems, as evidenced by the recent Polish power grid incident of December 2025, shows the growing capabilities of adversaries. When considered alongside the anticipated capabilities of quantum computing, this necessitates the development of robust and future-resilient security mechanisms for OT nvironments. In this paper, we present PQOTSec, a protocol-agnostic, post-quantum (PQ) secure overlay that enables mutual authentication and secure key exchange without modifying the existing protocol structure. Our framework employs NIST-standardised ML-DSA for authentication and ML-KEM for key establishment and achieves confidentiality, integrity, availability, and authenticity in PQ settings. We assess the security of our framework using the AVISPA tool and demonstrate its applicability by overlaying it onto Modbus/TCP. In our experiment, the framework shows better performance than Modbus/TCP Security, making it suitable for deployment in OT environments. We finally use PQ-OTSec to mitigate the vulnerabilities exploited in the Polish power grid attack, as well as protect against future quantum threats

Item Type: Conference Proceedings
Title of Proceedings: 2026 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm) College Station, Texas, USA, 26th - 29th October 2026
Uncontrolled Keywords: operational technology protocols, post-quantum cryptography, communication security, quantum computing
Subjects: Q Science > Q Science (General)
Q Science > QA Mathematics
Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Faculty / School / Research Centre / Research Group: Faculty of Engineering & Science
Faculty of Engineering & Science > School of Computing & Mathematical Sciences (CMS)
Last Modified: 10 Sep 2026 10:16
URI: https://gala.gre.ac.uk/id/eprint/54387

Actions (login required)

View Item View Item

Downloads

Downloads per month over past year

View more statistics