The migration of remote-access and industrial communication systems from classical public-key cryptography to post-quantum cryptography (PQC) requires careful evaluation at both the protocol and system levels. This paper presents PQC-E2E-CA, a system-level evaluation framework for reviewing post-quantum and hybrid cryptographic configurations in Secure Shell (SSH). The framework integrates OQS-enabled OpenSSH and OpenSSL with Linux netem network emulation, automated experiment execution, SCP integrity verification, and statistical post-processing. The evaluation separates key exchange behavior from host key authentication. Specifically, it measures ML-KEM and hybrid ML-KEM as SSH key exchange mechanisms, and ML-DSA as a host-key signature mechanism. Experiments are conducted under controlled RTT and packet-loss conditions using a gateway virtualised client-server testbed. The results show that ML-KEM and hybrid ML-KEM can be integrated into SSH without prohibitive application-level session setup overhead in the evaluated environment. Among the evaluated configurations, ML-KEM-768 demonstrates comparatively lower SSH session establishment latency at 50 ms RTT with 0% packet loss. ML-DSA-44 achieves the lowest host-key authentication latency under the same conditions and maintains relatively stable performance at 150 ms RTT with 5% packet loss. SCP throughput results for 100 MB and 200 MB transfers indicate that sustained transfer performance is mainly influenced by RTT and transport-layer dynamics using a single dominant key exchange configuration. These findings support migration toward standardized post-quantum mechanisms in SSH-based gateway and remote-access environments, provided that algorithm choice and system configuration are validated under representative workloads and network conditions.
Toward practical migration to post-quantum SSH: system-level design and evaluation
Muhammad Shahbaz Khan

