Post-quantum TLS acceleration

An interactive core-time model of one TLS 1.3 handshake on the server. Pick a configuration, watch which engine performs each step, and edit the per-operation costs to match your own measurements.

The default costs are placeholders. They are order-of-magnitude figures for a modern server core, not measurements from your platform. Replace every value in the cost model before quoting any number from this page.

Configuration
Playback
Speed

Handshake sequence

Idle. Press Play or Step to begin.

Modelled result

Connections per second is per core, and assumes the core is saturated with handshakes and nothing else.

Per-step core time for this configuration

Core time is the time the CPU core is occupied. Device time runs on the accelerator and does not consume the core.
StepEngine Core time, µsDevice time, µs

Cost model

Edit any value. Every metric on this page recomputes immediately.

All configurations compared

Modelled connections per second per core, and the change against the classical baseline.
ArmCPS/corevs A1

Intel QAT accelerates the classical leg of a hybrid handshake. It has no lattice datapath, so ML-KEM and ML-DSA always run on the core or on the GPU. Switch between B1 and B2 to see the offload contribution, and between B2 and D1 to see the GPU contribution.