PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 4, 2026Cybersecurity2 citationsOpen Access

Post-quantum readiness and cryptographic transition planning for enterprise cloud

AGAnkit GuptaSMShilpi Mittal

Key Points

  • The aim is to develop a framework for enterprises to transition to post-quantum cryptographic standards and assess associated risks.
  • Developed a standards-based algorithm selection framework using NIST's post-quantum standards.
  • Created a cloud threat model to identify risks including retroactive confidentiality loss.
  • Utilized a quantitative timing-risk model grounded in Mosca’s inequality.
  • Applied a Monte Carlo estimator for comparison of migration strategies.
  • Delaying migration start by four years increases expected exposed fraction of confidentiality window from 0.37 to 0.54.
  • Probabilistic estimates showed significant sensitivity to tail uncertainty compared to deterministic planning.

Abstract

Abstract Cryptographically relevant quantum computers (CRQCs) would break widely deployed public-key cryptography (RSA/ECC) via Shor’s algorithm, enabling retroactive decryption of captured ciphertext (“harvest now, decrypt later”). This paper presents an enterprise-cloud transition framework that couples (i) standards-based algorithm selection using NIST’s post-quantum standards (FIPS 203–205), (ii) a cloud threat model that distinguishes retroactive confidentiality loss from forward integrity/authentication risks, and (iii) a quantitative timing-risk model grounded in Mosca’s inequality. Using a public expert-elicitation distribution for Q-day timing and a reproducible Monte Carlo estimator, we compare migration strategies and key planning parameters (migration start year, migration duration, and confidentiality lifetime). We also contrast this probabilistic view with common deterministic single-date Q-day planning, highlighting how tail uncertainty can materially change exposure estimates and recommended start years. For a representative enterprise case (X=10 X = 10 years, Y=6 Y = 6 years), delaying the migration start from 2026 to 2030 increases the expected exposed fraction of the confidentiality window from 0. 37 to 0. 54 under a midline timeline. We also provide cloud-specific implementation guidance (crypto inventory, hybrid TLS/QUIC and service-mesh deployments, PKI readiness, and governance), and summarize performance and interoperability drivers arising from larger post-quantum key material.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Gupta et al. (2026) studied this question.

synapsesocial.com/papers/69d0b028659487ece0fa6302https://doi.org/10.1186/s42400-026-00579-2
Ask AI
Helpful
Bookmark
Share
View Full Paper