Securing the Energy Supply Chain with Quantum-Resistant Communication

Motivation & challenges

Energy infrastructure depends on trustworthy, timely communications. The future availability of quantum-capable systems could weaken widely used public-key cryptography, making early preparation important for information that must remain protected over long periods. PiQASO addresses this challenge by testing migration approaches before quantum-safe protection becomes an operational necessity.

The main challenge is to introduce post-quantum mechanisms into heterogeneous environments that include long-lived and resource-constrained components. Migration must therefore account for compatibility, manageable processing overhead, reliable authentication and a phased transition from current cryptographic methods.

The regulatory landscape adds urgency. NIS2 mandates rigorous cybersecurity risk management for energy operators, and forthcoming harmonised standards are expected to require quantum-safe cryptography for critical infrastructure. MOH and MORE need to build PQC competence now, while there is still time to test, iterate, and plan.

Current landscape

The MOH scenario represents a controlled energy-monitoring environment in which telemetry passes between a supervisory endpoint and a secure gateway. The setup is used to examine how a protected communication channel can be established and maintained without disclosing details of production systems or operational configurations.

The MORE scenario contributes the renewable-energy edge perspective, where gateways collect and exchange operational data on behalf of field equipment. CERTH contributes technical expertise and supports the monitoring and assessment layer, helping the partners evaluate the security approach across the communication chain.

Neither environment has a clear path to post-quantum migration using currently available commercial tools. There is no off-the-shelf PQC solution designed for Honeywell DCS environments or for the class of IED devices deployed in Greek substations. The gap between PQC research and practical OT deployment is exactly the space UC4 is designed to bridge.

Use Case description, goals and objectives

UC4 (Energy) brings together MOH, MORE and CERTH to validate post-quantum protection for representative energy-sector communications. The work combines an operational energy perspective with technical integration, monitoring and assessment, while keeping the published description at a high level and excluding sensitive infrastructure details.

User Story 1 – Quantum-Secure Grid Telemetry. In this story, a representative telemetry flow is protected between a simulated supervisory environment and a gateway using the PiQASO software components. The objective is to establish an authenticated, quantum-resistant communication channel and confirm that telemetry can continue to be exchanged reliably. CERTH supports the technical setup and the assessment of the security and performance evidence.

The evaluation considers the main building blocks needed for secure session establishment, authentication and protected telemetry exchange. Rather than publishing detailed configurations or measurements, the public description focuses on the overall finding: post-quantum mechanisms can be assessed in a representative setup while performance, interoperability and operational continuity remain central acceptance criteria.

CERTH works with MOH and MORE on the technical implementation and provides monitoring and assessment expertise. The collaboration supports evidence-based decisions on migration readiness and helps translate research outcomes into practical guidance for the energy sector.

The next steps are to expand the validation to additional migration and onboarding scenarios, compare alternative deployment options and refine a phased adoption roadmap. This approach allows the partners to build confidence progressively while protecting system availability and avoiding unnecessary changes to existing assets.

By the end of the project, UC4 aims to deliver a validated, replicable PQC migration roadmap for the energy sector, demonstrating that quantum-safe cryptography can be deployed in real industrial environments without compromising the performance and reliability that critical infrastructure demands.

About Motor Oil Group

Motor Oil Group is one of Greece’s leading energy groups, with activities spanning conventional and renewable group of energy. Within PiQASO, Motor Oil Hellas (MOH) and Motor Oil Renewable Energy (MORE) contribute the operational perspective of the energy sector, helping ensure that the proposed cybersecurity solutions address realistic requirements for availability, resilience and secure data exchange.

The use case focuses on communications between energy monitoring environments, gateways and supervisory systems. These environments combine established operational technology with modern digital services, creating a need for security measures that can be introduced gradually without disrupting essential functions.

MOH and MORE participate in PiQASO alongside CERTH, which supports the technical integration, monitoring and assessment activities for the Energy Use Case. Together, the partners are examining practical pathways for introducing quantum-resistant protection into representative energy communication scenarios.

The project funded under Grant Agreement No. ​101190366​ is supported by the European Cybersecurity Competence CentreFunded by the European Union.
Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Cybersecurity Competence Centre.
Neither the European Union nor the granting authority can be held responsible for them.