DIGITAL TWIN-DRIVEN POST-QUANTUM CRYPTOGRAPHIC MIGRATION FOR SMART GRID CRITICAL INFRASTRUCTURE: A SIMULATION-BASED PROOF-OF-CONCEPT FRAMEWORK

Authors:

Gulab Kumar Mondal,Dharampal Singh,Arijit Das,Moumita Pal,Biswarup Neogi,

DOI NO:

https://doi.org/10.26782/jmcms.2026.09.00002

Keywords:

post-quantum cryptography,digital twin,smart grid,IEC 61850,IEC 62351,crypto-agility,critical infrastructure.,

Abstract

The prospective arrival of a cryptanalytically relevant quantum computer (CRQC) threatens the asymmetric primitives that protect smart grid communications, protection signalling and identity assertions. Migration to the NIST-standardised post-quantum cryptography (PQC) suite — ML-KEM (FIPS 203) and ML-DSA (FIPS 204) — is unavoidable, but distribution substations cannot be taken offline, intelligent electronic devices (IEDs) operate under millisecond-class deadlines, and PQC key, ciphertext and signature sizes invalidate protocol assumptions embedded in IEC 61850 and DNP3 Secure Authentication. This paper proposes and evaluates TwinPQC, a digital-twin framework in which a cyber-physical replica of a distribution substation is used to simulate, validate and stage PQC adoption before any physical deployment. The environment integrates OpenDSS power simulation, ns-3 network emulation, QEMU-virtualised ARM-class IED firmware and a crypto-agility broker built on the Open Quantum Safe stack. Four cryptographic configurations are evaluated over 480 simulation runs on the IEEE 13-bus and 34-bus distribution feeders. Relative to the classical baseline, the hybrid X25519+ML-KEM-768 / ECDSA+ML-DSA-65 configuration increases MMS association latency by 52.0 ± 1.4 % and GOOSE publication latency from 0.80 ± 0.04 ms to 2.10 ± 0.12 ms, retaining 97.2 % IEC 61850 Type 1A compliance on Cortex-A53 IEDs. On the emulated 120 MHz Cortex-M4 profile, Type 1A compliance falls to 62.4%, and peak heap allocation reaches 148.2 ± 1.8 KB. A frame-level analysis shows that the dominant obstacle for GOOSE is not queueing delay, which contributes under 3 µs on a 1 Gbit/s station bus, but the fact that a 3,501-byte authentication object cannot be carried in a single IEC 61850-8-1 GOOSE frame. A comparison against published pqm4 Cortex-M4 cycle counts further shows that ML-DSA-44 signing alone requires approximately 32.9 ms at 120 MHz, so the emulated constrained-device results must be read as an optimistic bound rather than a timing measurement. The twin flags migration and adversarial faults on 88 to 98 % of injected episodes per scenario, against 0 to 45 % for isolated bench testing, using deterministic predicates that policy-conforming benign traffic cannot satisfy for three of the four scenarios. A five-stage migration playbook with explicit go/no-go criteria and a rollback path is derived from these results.

Refference:

I. Aksoy, Ahmet, et al. “A Practical Performance Benchmark of Post-Quantum Cryptography across Heterogeneous Computing Environments.” Cryptography, vol. 9, no. 2, 2025, art. 32. 10.3390/cryptography9020032.
II. Al-Shetwi, Ali Q., et al. “Digital Twin Technology for Renewable Energy, Smart Grids, Energy Storage and V2G Integration.” IET Smart Grid, vol. 8, no. 1, 2025. https://ietresearch.onlinelibrary.wiley.com/journal/25152947.
III. Bowers, James, and Mark Watson. “Constrained Device Performance Benchmarking with the Implementation of Post-Quantum Cryptography.” Cryptography, vol. 8, no. 2, 2024, art. 21. 10.3390/cryptography8020021.
IV. Bundesamt für Sicherheit in der Informationstechnik. Quantum-Safe Cryptography: Fundamentals, Current Developments and Recommendations. BSI, 2024, https://www.bsi.bund.de.
V. Coppolino, Luigi, et al. “Exploiting Digital Twin Technology for Cybersecurity Monitoring in Smart Grids.” Proceedings of the 18th International Conference on Availability, Reliability and Security, ACM, 2023. 10.1145/3600160.
VI. Cybersecurity and Infrastructure Security Agency, et al. Quantum-Readiness Factsheet. CISA, 2024. https://www.cisa.gov.
VII. Cybersecurity and Infrastructure Security Agency, et al. Quantum-Readiness: Migration to Post-Quantum Cryptography. Joint Advisory, CISA, 2023, https://www.cisa.gov.
VIII. Empl, Philip, et al. “Digital Twins in Security Operations: State of the Art and Future Perspectives.” ACM Computing Surveys, vol. 58, no. 1, 2025. https://dl.acm.org/journal/csur.
IX. European Union Agency for Cybersecurity. Post-Quantum Cryptography: Current State and Quantum Mitigation. ENISA, 2022. https://www.enisa.europa.eu.
X. Hussain, S. M. Suhail, et al. “Performance Evaluation of IEC 61850 GOOSE Messaging for Time-Critical Substation Operations.” IEEE Access, vol. 8, 2020. https://ieeexplore.ieee.org/xpl/RecentIssue.jsp?punumber=6287639.
XI. Institute of Electrical and Electronics Engineers. IEEE 1815: Standard for Electric Power Systems Communications — Distributed Network Protocol (DNP3). IEEE, 2012. https://standards.ieee.org.
XII. Institute of Electrical and Electronics Engineers Power and Energy Society. IEEE 13-Bus and 34-Bus Distribution Test Feeders. Distribution Test Feeder Working Group. https://cmte.ieee.org/pes-testfeeders/.
XIII. International Electrotechnical Commission. IEC 61850 Edition 2: Communication Networks and Systems for Power Utility Automation. IEC, 2013. https://webstore.iec.ch.
XIV. International Electrotechnical Commission. IEC 61850-5: Communication Requirements for Functions and Device Models. IEC, 2013. https://webstore.iec.ch.
XV. International Electrotechnical Commission. IEC 61850-8-1: Specific Communication Service Mapping — Mappings to MMS and to ISO/IEC 8802-3. IEC, 2020, https://webstore.iec.ch.
XVI. International Electrotechnical Commission. IEC 62351-3: Profiles Including TCP/IP. IEC, 2018. https://webstore.iec.ch.
XVII. International Electrotechnical Commission. IEC 62351-4: Profiles Including MMS and Derivatives. IEC, 2018. https://webstore.iec.ch.
XVIII. International Electrotechnical Commission. IEC 62351-6: Security for IEC 61850. IEC, 2020. https://webstore.iec.ch.
XIX. International Electrotechnical Commission. IEC 62351-9: Cyber Security Key Management for Power System Equipment. IEC, 2023. https://webstore.iec.ch.
XX. Kannwischer, Matthias J., et al. pqm4: Post-Quantum Crypto Library for the ARM Cortex-M4. GitHub. https://github.com/mupq/pqm4.
XXI. Kniphoff da Cruz, Alexandre, et al. “IEC 61850 GOOSE: A Systematic Literature Review.” Automation, vol. 7, no. 2, 2026, art. 62. 10.3390/automation7020062.
XXII. MZ Automation. libiec61850: Open-Source IEC 61850 Library. Version 1.5. https://libiec61850.com.
XXIII. National Institute of Standards and Technology. Module-Lattice-Based Key-Encapsulation Mechanism Standard. FIPS 203, NIST, 2024. 10.6028/NIST.FIPS.203.
XXIV. National Institute of Standards and Technology. Module-Lattice-Based Digital Signature Standard. FIPS 204, NIST, 2024. 10.6028/NIST.FIPS.204.
XXV. National Institute of Standards and Technology. Stateless Hash-Based Digital Signature Standard. FIPS 205, NIST, 2024. 10.6028/NIST.FIPS.205.
XXVI. National Institute of Standards and Technology. Transition to Post-Quantum Cryptography Standards. NIST IR 8547, Initial Public Draft, NIST, 2024. 10.6028/NIST.IR.8547.ipd.
XXVII. National Institute of Standards and Technology National Cybersecurity Center of Excellence. Migration to Post-Quantum Cryptography. NCCoE, 2024. https://www.nccoe.nist.gov.
XXVIII. National Security Agency. Commercial National Security Algorithm Suite 2.0. NSA, 2022. https://www.nsa.gov.
XXIX. Ofenloch, Annika, et al. “MOSAIK 3.0: Combining Time-Stepped and Discrete Event Simulation.” 2022 Open Source Modelling and Simulation of Energy Systems (OSMSES), IEEE, 2022. 10.1109/OSMSES54027.2022.9769116.
XXX. Open Quantum Safe Project. liboqs and oqs-provider for OpenSSL 3. Open Quantum Safe, https://openquantumsafe.org.
XXXI. Qureshi, Ayesha, et al. “A Survey on Security-Enhancing Digital Twins.” Computer Communications, vol. 238, 2025. https://www.sciencedirect.com/journal/computer-communications.
XXXII. Reda, Haftu Tasew, et al. “Vulnerability and Impact Analysis of the IEC 61850 GOOSE Protocol in the Smart Grid.” Sensors, vol. 21, no. 4, 2021, art. 1554. 10.3390/s21041554.
XXXIII. Sánchez, Guillermo, et al. “Masquerading the IEC 61850 GOOSE Protocol: Cyber-Physical Experiments and Detection.” Proceedings of the 16th ACM International Conference on Future Energy Systems, ACM, 2025. https://dl.acm.org/conference/e-energy.
XXXIV. Sen, Ömer, et al. “Digital Twin for Evaluating Detective Countermeasures in Smart Grid Cybersecurity.” IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids, IEEE, 2023. https://ieeexplore.ieee.org.
XXXV. Steinbrink, Cornelius, et al. “CPES Testing with Mosaik: Co-Simulation Planning, Execution and Analysis.” Applied Sciences, vol. 9, no. 5, 2019, art. 923. 10.3390/app9050923.
XXXVI. Wang, Qian, and Zhen Li. “Upgrading Operational Technology Systems to Post-Quantum Cryptography: Strategies and Resource Models.” International Journal of Critical Infrastructure Protection, vol. 42, 2023, art. 100612. 10.1016/j.ijcip.2023.100612.

View Download