Source-linked AI summary
A Scenario-Based Evaluation of CRQC+AI Vulnerability Spectrum for TLS 1.3 Cryptographic Dependencies
Noel Grover, Mussie Haile, Brad Pedersen, Eric Uner, Bradley J Erickson
TL;DR
TLS 1.3 faces mechanism-backed quantum threats to RSA and ECC alongside conditional, less-established risks to post-quantum cryptography. This paper uses a reproducible, parameterized scenario model to estimate vulnerability timelines, finding RSA exposure could begin around 2030 while PQC risk remains conditional after 2032.
Problem
The paper addresses limited evidence on how quantum and AI advances could affect TLS 1.3 cryptographic dependencies and PQC migration timelines.
Method
The paper builds a reproducible four-scenario capability model combining hardware and AI-assisted software drivers with explicit parameters, sensitivity analysis, and falsification rules.
Results
RSA risk could begin as early as 2030, whereas PQC risk could begin as early as 2032 only under a conditional, undemonstrated structural advance against lattices.
Takeaways & Limitations
PQC migration should proceed now alongside crypto-agile hybrid approaches rather than assuming PQC will be the final encryption migration.
Takeaways & Limitations
The crossover years are scenario outputs based on chosen, unmeasured hardware and software sensitivities, not empirical forecasts.
Abstract
from arXiv · showhide
This paper evaluates quantum and AI-accelerated risks to TLS 1.3 cryptographic dependencies under an evidence-tiered model, distinguishing mechanism-backed threats (Shor algorithm against RSA and ECC) from contingency-backed risks to lattice-based post-quantum cryptography (PQC) and hypothesis-only risks to hash-based and symmetric primitives. We do not identify any known breaks of ML-KEM, ML-DSA, SLH-DSA, or AES-256. Instead, we use explicit scenario assumptions, organized as a four-scenario capability model with parameters and pseudocode for reproducibility, to stress-test migration timelines accompanied by parameter sensitivity analysis and explicit falsification analysis. The primary methodological contribution is a reproducible scenario-estimation instrument together with its explicit update mechanics: every parameter is a named, anchored quantity that can be varied and the model rerun; a stated protocol maps observed conformance to, or deviation from, the modeled curves onto revisions of specific parameters, so progressive refinements can be tested against accumulating historical data. The paper is a methodological companion to quantum resource-estimation studies and to expert-elicitation timeline surveys such as the Global Risk Institute quantum threat reports, with its revision rules stated explicitly. As of mid-2026, the model does not show any NIST-approved algorithms as broken. Instead, the vulnerability spectrum under different scenarios shows RSA risk crossing the 50% threshold between 2030-2032 and the PQC risk becoming a non-zero risk after 2032-2035 under contingency scenarios conditional on the unproven dimension-collapse. We urge PQC migration as mandatory per the 2030 and 2031 federal deadlines and by Mosca HNDL reasoning, and that crypto-agility and hybrid cryptographic deployment be considered necessary complements to any PQC migration efforts.
1. Introduction
The paper frames CRQC+AI threats to TLS 1.3 as an evidence-graded vulnerability spectrum and develops a scenario-based stress test rather than claiming breaks of standardized PQC. It advocates hybrid, crypto-agile deployment while emphasizing that TLS 1.3 primitive-erosion results are a best-case migration view.
- Implications: The paper recommends replaceable PQC deployment in hybrid, crypto-agile frameworks to address HNDL and enable migration away from compromised ciphers.It presents crypto-agility and resilient cryptography as necessary complements to PQC migration rather than asserting that PQC alone resolves all CRQC+AI risks.
- Threat landscape: It investigates CRQC+AI attack vectors beyond Grover’s and Shor’s algorithms, including HHL, geometric simplification, quantum optimization, and side-channel approaches.[10][11][12]The paper notes that HHL limitations involving matrix density and conditioning in LWE may be intrinsic rather than temporary engineering barriers.
- Contribution: The paper separates mechanism-backed threats, contingent lattice-scheme threats, and hypothesis-only hash-based and symmetric threats in an evidence-graded evaluation of TLS 1.3.[11]It explicitly states that current standardized PQC algorithms are not known to be broken and models earlier compromise through scenario assumptions involving quantum progress, AI-assisted engineering, and hypothetical cryptanalytic structure.
- Scope and approach: The instrument estimates feasible attackability for RSA-2048, ML-KEM768/1024, ML-DSA-44, SLH-DSA, and AES-256 as deployed in TLS 1.3, measuring primitive erosion.Its approach combines a hardware-budget channel model, a capability model driven by hardware and AGI-gated software growth, and a cost model for lattice and hash contingencies.
- Scope and limitations: TLS 1.3 is treated as a tractable migration surface because its keys are ephemeral and rotatable, algorithms are negotiated, and certificates are short-lived.The conclusions do not transfer directly to SSH, IPsec, DNSSEC, code signing, firmware signing, or estate-level recommendations, which may involve long-lived or unrotatable keys.
2. Background
This section surveys CRQC+AI techniques relevant to later attack pathways while distinguishing background methods from demonstrated cryptanalytic breaks. It emphasizes that HHL, quantum annealing, VQE, and geometric-algebra proposals face structural or evidentiary limitations against standardized cryptography.
- Scope of the background review: The section includes these techniques to identify both potentially relevant mechanisms and approaches that do not independently break standardized cryptography.Quantum annealing and variational methods are surveyed as adjacent quantum-optimization techniques, while non-contribution to near-term breaks is itself part of the argument.
- HHL and lattice-based cryptanalysis: HHL’s apparent exponential speedup requires sparse, well-conditioned systems and yields a quantum-state output, while LWE lattice instances do not satisfy the needed structure.Its runtime is polylogarithmic in N but polynomial in sparsity s and condition number κ; extracting individual solution coordinates removes the exponential advantage.
- Geometric-algebra direction: Geometric-algebra proposals reduce to an unproven hypothesis that a low-dimensional embedding could shrink effective lattice block size β; no construction currently breaks standardized schemes.The collapse fraction ρ specifies how large the hypothesized reduction would need to be, not an attainable value.
- Quantum annealing: Quantum annealing can encode factoring and lattice problems as QUBO or Ising optimization, but closing spectral gaps can make annealing time exponential and provides no general cryptanalytic speedup.Small semiprimes have been factored with substantial classical preprocessing, while the paper concludes annealing does not independently yield a standalone break.
- Variational quantum methods: VQE is limited by barren plateaus and lacks an established reduction from factoring or discrete logarithms to its ground-state estimation task.Its near-term appeal comes from shallow hybrid circuits and relative noise resilience, not from a demonstrated cryptanalytic advantage.
3. CRQC+AI Vulnerability Timelines · 3.1 Current Timeline Projections
The paper models CRQC+AI timelines as scenario-based risk spectra rather than single Q-Day predictions, using uncertainty-aware projections for RSA/ECC and contingency-based concerns for lattice-based PQC. It motivates migration through HNDL exposure, regulatory deadlines, historical analogies, and rapidly changing quantum-resource estimates while emphasizing that these are model-generated estimates, not empirical measurements.
- 3.1 Current Timeline Projections: Q-Day is treated as an inadequate single-deadline analogy: CRQC+AI risks span dates and systemic consequences, while HNDL makes migration rational whenever a break may occur within the secrecy horizon.Mosca’s framework compares confidentiality duration, migration time, and time to a cryptographically relevant quantum computer; the practical implication does not require knowing that final time precisely.
- 3.1 Current Timeline Projections: CRQC+AI projections define a time-varying risk band between linear extrapolation from known developments and exponential improvement under a meaningful-probability assumption.The authors explicitly characterize these outputs as model-generated scenario estimates rather than empirical measurements.
- 3.1.1 Historical Analogues for the PQC Transition: the 2008 Financial Crisis and Y2K: A single-day quantum-enabled attack on one top-five U.S. bank’s Fedwire access is estimated at $730 billion to $1.95 trillion in direct costs and $2.0 to $3.3 trillion in GDP-at-risk contagion costs.These figures are attributed to Hudson Institute modeling adopted in the Citi Institute’s 2026 analysis.
- 3.1.1 Historical Analogues for the PQC Transition: the 2008 Financial Crisis and Y2K: PQC transition pressure is primarily regulatory rather than public: awareness is approximately 25–30% today, compared with more than 85% public concern during Y2K.The PQC transition deadline is framed as Jan. 1, 2031, following the Dec. 31, 2030 effective date of EO 14412’s FIPS 203 mandate.
- 3.1.2 RSA/ECC Vulnerability Spectrum: RSA/ECC timelines have moved earlier as resource estimates fell: projections around the mid-to-late 2030s were followed by a five-year advancement of military-network deprecation planning after NIST approved initial PQC algorithms in 2024.The section explains the underlying mechanism through Shor’s polynomial scaling against RSA/ECC and the distinction between logical and physical qubit estimates after error-correction overhead.
- 3.1.2 RSA/ECC Vulnerability Spectrum: Reported CRQC resource estimates vary substantially because some figures count physical qubits with error-correction overhead, whereas others report logical or idealized circuit requirements.Examples include fewer than 100,000 physical qubits for RSA-2048 [84], as few as 10,000 reconfigurable atomic qubits for ECC-256 and RSA-2048 [19], and 1,193 logical qubits for ECC-256.
- 3.1.3 PQC Vulnerability Spectrum for Lattice-Based PQC: For lattice-based PQC, the paper identifies a gap in presumed-hardness analyses: improved quantum algorithms or AI/AGI-assisted computation could affect LWE attacks, but no formal NIST timeline is provided.For Kyber-1024, the simplified core-SVP analysis yields β ≈ 877; the assumed quantum exponent 0.265 is described as optimistic because realistic QRAM and circuit-depth costs may narrow or eliminate the advantage.
- 3.2.2 Quantum Computing Improvements for CRQC+AI: Rose’s Law is presented as motivation against assuming only linear CRQC+AI improvement, but annealer-qubit growth cannot by itself determine Shor, Grover, or lattice-sieving resources.The model therefore anchors its hardware budget to fault-tolerant logical-qubit and error-rate roadmaps for gate-model machines.
3.3 An Acceleration-Factor Model for AI-Compressed Timelines
The model makes AI timeline compression explicit and auditable by assigning calibrated acceleration factors to separate engineering channels while forbidding changes to Shor’s complexity or physical laws. Its worked calibration yields an unaccelerated crossover around 2032, shifting to about 2031 at the central factor and about 2029 at the high factor, with updates driven by observed evidence.
- Model boundary: The model permits AI to accelerate identifiable engineering bottlenecks but not underlying complexity theory or physics, including Shor’s polynomial scaling.Permitted channels include decoding, calibration and control, fabrication and materials search, code discovery, and circuit compilation and optimization.
- Channel model: CRQC progress is decomposed into four independently calibrated engineering channels, with the slowest channel determining the crossover date.For channel i, τi = ln(Fi) / (Ai · ri); treating factors as ranges produces a distribution over T and a probability P(T ≤ year) rather than a single date.
- Calibration anchors: The required qubit-count improvement is anchored to changing resource estimates rather than a fixed endpoint: RSA-2048 estimates fell from roughly twenty million physical qubits in 2019 to under one million in 2025.The paper attributes this more-than-order-of-magnitude shift over six years to algorithmic and error-correction advances as well as hardware progress.
- Worked calibration: 2032, 2031, and 2029 are the approximate CRQC crossover years under no acceleration, the central acceleration factor, and the high acceleration factor, respectively.At no acceleration, the four channels reach their targets around 2029, 2029, 2030, and 2032; the raw logical-qubit count is binding, with T = 2026 + ln(103) / (A1 · 1.1).
- Falsification and validation: The model is designed for prospective updating: physical-qubit, interconnect, and logical-error observations narrow acceleration-factor ranges, while outcome validation remains unavailable as of July 2026.Appendix A supports exact curve regeneration, which the paper distinguishes from validation against a future modeled crossover.
4. Using AI to Project the Advancement of CRQC+AI Vulnerabilities
This section uses a single parameterized hardware-and-software capability model to visualize conditional CRQC+AI vulnerability timelines across four AGI-capability tracks. It projects early RSA-2048 crossings while treating PQC exposure as contingent on an unproven geometric dimension-collapse and leaving SLH-DSA and AES-256 without mechanism- or contingency-backed exposure.
- Scenario assumptions: The four tracks span no AGI-gated capability, low, moderate, and high AGI-driven software capability, with Track 3 the most aggressive regime.The end-of-2028 AGI horizon is adopted as a contested scenario input, while Track 0 preserves a no-AGI baseline.
- Hash-based and symmetric primitives: SLH-DSA and AES-256 show no mechanism-backed or contingency-backed exposure, with their hypothesis-only stress cases confined to Appendix C.AES-256’s modeled effective cost remains near the classical value, while SLH-DSA’s modeled crossover is approximately 2036 under Track 3.
- Cryptanalytic cost model and dimension-collapse contingency: A 2032–2035 ML-KEM-1024 break requires roughly two-thirds effective lattice-dimension reduction, so PQC exposure remains contingent rather than established.The model does not assert that this geometric collapse exists; without it, algorithmic erosion alone cannot reach the 2033 budget.
- Model-derived progress timeline: The model places the earliest feasible RSA-2048 break around 2030 under Track 3, while Track 0 crosses around 2032.These are conditional scenario outputs, not forecasts.
- TLS 1.3 PQC exposure: Under hardware-only Track 0, ML-KEM-1024 has a 2048.8 median crossover and effectively zero exposure probability by 2035.The joint Monte Carlo therefore reinforces that PQC exposure depends on the contingency, not merely on hardware progress.
5. Limitations and Falsifiability
The model is a reproducible scenario instrument, not an empirical forecast: its crossover dates depend on chosen couplings and a normalized runtime axis. Its conclusions are falsifiable through observable conditions that update specific acceleration factors rather than invalidating the projection wholesale.
- Limitations: Crossover years are outputs of analyst-chosen hardware and software sensitivities, while reproducibility enables scenario regeneration rather than date forecasting.The runtime axis is a normalized index anchored to a common baseline across five schemes, not a per-scheme physical runtime estimate.
- How this model could be wrong: If AI yields no durable cryptanalytic improvement, software couplings β remain zero, lattice, hash-based, and symmetric tracks never cross within the horizon, leaving RSA and ECC exposure.This condition removes the software-driven component of the modeled risk spectrum.
- How this model could be wrong: If dimension collapse against lattices never materializes or quantum linear-algebra methods remain inapplicable to noisy LWE decoding, the lattice contingency tier is void.In the Section 4.5 cost model, this corresponds to ρ staying at zero.
- How this model could be wrong: If quantum-hardware scaling stalls or fault-tolerant correction remains below relevant scales, the RSA crossover moves later and mechanism-backed timelines lengthen.The hardware sensitivity analysis links a hardware rate r_hw approaching one to a flattening driver.
- How this model could be wrong: If AGI arrives later than assumed in 2028, every software-driven crossover slips by approximately the same amount.These conditions are observable and falsifiable through hardware milestones, error rates, decoder latency, and resource-estimate movement that update specific acceleration factors.
6. Implications for Migration and Governance
Migration and governance are present requirements independent of speculative cryptanalysis, requiring crypto-agility as an operational governance capability and sector-specific Mosca-horizon decisions. TLS 1.3 migration also depends on certificate ecosystems, interoperability, trust-anchor distribution, and sound entropy across deployments.
- Crypto-agility and governance: Crypto-agility requires inventorying primitives, assigning rotation authority, executing controlled changes, handling exceptions, and retaining evidence, with migration decisions owned by the cryptographic-inventory owner.It is a governance capability rather than merely a technical stack property.
- Mosca decision rule: Mosca’s inequality X + Y > Z is a sector-specific decision rule, but this paper models only Z and leaves secrecy horizons X and migration durations Y to sector-specific evidence.Representative X and Y values are presented in Table 5, while the model does not populate them.
- Crypto-agility and governance: Crypto-agility is already legally required because algorithm mandates, trust-anchor jurisdictions, HSM sourcing, and cross-border key custody diverge across sovereigns.The paper identifies these requirements as demonstrable today without speculative cryptanalysis.
- Certificate and trust-anchor dependencies: TLS 1.3 post-quantum migration must separately plan for post-quantum certificate issuers, path validation, trust-anchor distribution, and long-lived or embedded clients because these constraints arise on current issuance timelines.This certificate and trust-anchor dependency lies outside the paper’s primitive-erosion instrument.
- Interoperability and negotiation: Hybrid negotiation succeeds only when both endpoints, middleboxes, resumption caches, and libraries support and prefer the new groups; otherwise deployments may fail or silently downgrade to classical exchange.The example is ML-KEM concatenated with an elliptic-curve exchange in draft-ietf-tls-ecdhe-mlkem.
- Operational dependencies: Migration guarantees also depend on sound entropy, secure seeding, and key provenance, since weak randomness can undermine post-quantum primitives without any cryptographically relevant quantum computer.These risks are especially relevant to constrained and embedded devices.
7. Conclusion
The conclusion argues that CRQC+AI could create substantial TLS 1.3 financial and security risks from attacks on RSA as early as 2030 and PQC as early as 2032, while supporting immediate PQC migration with crypto-agile hybrid defenses. It also presents the model as an auditable procedure for revising risk timelines as evidence accumulates.
- Conclusion: RSA attacks could begin causing large-scale TLS 1.3 financial losses as early as 2030, while PQC compromise risks could emerge as early as 2032.RSA and ECC exposure is mechanism-backed by Shor’s algorithm, whereas the PQC timeline carries different evidential weight.
- Conclusion: Compromised cryptographic keys could enable TLS 1.3 eavesdropping, man-in-the-middle attacks, data theft, impersonation, and service disruption.Table 6 maps cryptographic break classes to compromised primitives or key material and their TLS 1.3 effects.
- Conclusion: The conclusion recommends acting now because research and crypto-agile hybrid cryptographic approaches offer relatively low-cost, high-probability defenses against PQC vulnerabilities.It cautions against assuming PQC will be the last required encryption migration and cites NIST advocacy.
- Conclusion: The study contributes an auditable procedure that converts future observations into revised quantum-risk timelines, complementing resource-estimation studies and expert-elicitation surveys.The figures are generated from the disclosed parameterized model rather than new empirical data.
- Conclusion: The authors disclose financial interests connected to EnQuanta, which develops commercial post-quantum and crypto-agile cryptographic products and services.This conflict is relevant to the paper’s discussion of crypto-agile and hybrid approaches.
Appendix A. Reproducibility of the Combined Hardware and Software Capability Model
Appendix A documents the single combined hardware and software capability model used to generate the paper’s runtime and feasibility figures. It makes every curve reproducible from explicit equations and parameters.
- Model specification: The appendix specifies the combined hardware and software capability model as the generative instrument behind the runtime and feasibility curves.The model produces Figures 6A/6B through 8A/8B, Figure 9, and Appendix C Figures C1A/C1B and C2A/C2B.
- Reproducibility: The computational model is documented so that every reported curve can be reproduced from explicit equations and parameters.
- Relation to main text: The model complements the analytical framings presented in the paper’s main body.
Appendix A.1. Governing Equations
The appendix defines modeled cryptanalytic capability as hardware- and software-driven reductions in attack runtime, then converts runtime into feasibility probabilities and equation-derived 50% crossover years.
- Governing Equations: Cryptanalytic capability C(a, k, t) measures base-10 orders of magnitude by which algorithm a’s estimated attack runtime decreases, combining hardware and software terms.C(a, k, t) = α(a) · D_hw(t) + β(a, k) · D_sw(k, t).
- Governing Equations: Algorithm-specific couplings determine sensitivity to hardware and track-specific software attacks, with α large for RSA and near zero for lattice, hash, and symmetric schemes.Both drivers are clamped at zero before their onset years; attack runtime is R(a, k, t) = R0 − C(a, k, t), with R0 = 10.
- Governing Equations: Modeled feasibility follows a logistic function of attack runtime, using the one-month threshold MON ≈ 6.415 to translate runtime reductions into probabilities.P(a, k, t) = 100 / (1 + exp(−(MON − R(a, k, t)) / 0.85)).
- Governing Equations: A scheme’s 50% modeled-feasibility crossover is the first year C reaches approximately 3.585, derived directly from these equations rather than external figures.The crossover occurs when estimated runtime reaches the one-month line.
Appendix A.2. Parameters and Their Sources
Appendix A.2 defines the model’s normalized capability axis, hardware and software drivers, and scenario-specific algorithm couplings. With these parameters, Figure 9 yields track-dependent 50% crossover years, while SLH-DSA and AES-256 show no feasible break through 2046.
- Parameters and Their Sources: The model uses 2026 as the reference year, 2028 as AGI onset, and a shared log-seconds baseline R0 = 10 with a fixed one-month capability threshold.The 50% crossing threshold is C ≈ 3.585 orders of magnitude, and R0 is a common visual baseline rather than a per-scheme 2026 runtime estimate.
- Parameters and Their Sources: Hardware growth is shared across tracks at A = 0.34 and r_hw = 1.20, while software progress combines a 0.04 pre-AGI slope with track-specific AGI-gated rates and ceilings.Track 3 uses r_k = 1.30 and B_k = 0.30, producing the sharply convex collapse.
- Parameters and Their Sources: RSA-2048 has the largest hardware sensitivity, whereas lattice, hash-based, and symmetric schemes have near-zero or zero hardware sensitivities; software couplings vary by track and algorithm.The α and β values are scenario parameters rather than measured constants.
- Parameters and Their Sources: A lattice scheme crosses before RSA only with hardware sensitivity above RSA’s 0.92 or, on Track 3, ML-KEM1024 software coupling near 4.48 instead of 1.45.The latter is roughly triple ML-KEM1024’s published coupling and 1.76× RSA’s Track 3 value of 2.55; this failure ordering is a result, not an input.
- Parameters and Their Sources: 2032.5, 2031.4, 2030.5, and 2029.9 are RSA-2048’s 50% crossover years across Tracks 0–3; Kyber-1024 reaches 2045.9, 2035.0, and 2032.3 on Tracks 1–3.ML-DSA-44 crosses at 2035.9 and 2032.9 on Tracks 2–3, while SLH-DSA and AES-256 show no feasible break within the 2046 horizon.
Appendix A.3. Procedure to Regenerate the Figures (Pseudocode)
Appendix A.3 specifies the pseudocode and fixed parameters needed to regenerate the capability, runtime, feasibility, and crossover calculations. It also documents deterministic reproduction materials using a seeded Monte Carlo procedure.
- Appendix A.3. Procedure to Regenerate the Figures (Pseudocode): The procedure fixes t0 = 2026, t_AGI = 2028, R0 = log10(1e10), MON = log10(2.6e6), A = 0.34, r_hw = 1.20, and sw_pre = 0.04.These parameters define the normalized baseline, one-month feasibility line, hardware driver, and pre-AGI software slope.
- Appendix A.3. Procedure to Regenerate the Figures (Pseudocode): The pseudocode computes hardware and track-specific software growth, combines them through per-algorithm couplings, and converts capability into clamped runtime and logistic feasibility.Software tracks use the supplied (r_k, B_k) values, while runtime is bounded from -0.4 to R0 before feasibility is calculated relative to MON.
- Appendix A.3. Procedure to Regenerate the Figures (Pseudocode): Crossover years are found by scanning 600 time points from 2026 through 2046 and returning the first year where feasibility reaches 50%, or NONE within the horizon.This procedure operationalizes the 50% feasibility threshold for each algorithm-and-track combination.
- Appendix A.3. Procedure to Regenerate the Figures (Pseudocode): The released reproduction package includes the capability model, seeded Monte Carlo, and figure scripts; base seed 20260731 is offset by cell index for independent algorithm-and-track regeneration.With N = 40,000, the scripts reproduce the deterministic crossover years exactly.
Appendix A.4. Sensitivity Analysis
The sensitivity analysis isolates how hardware, software, AGI timing, and Track 3 dynamics affect modeled 50% crossover dates. RSA-2048 is primarily hardware-driven, whereas lattice, hash-based, and symmetric schemes are mainly software-driven and AGI-gated.
- Sensitivity Analysis: RSA-2048 crosses under every track because its capability is dominated by hardware (α = 0.92), with a narrow spread of about 2.5 years.The spread is attributed to software couplings, and widening it would require larger RSA β values.
- Sensitivity Analysis: Track 3’s rate r_k = 1.30 drives its sharply convex collapse; lowering it toward Track 2’s 1.17 delays Track 3 crossovers and removes the convex curl.The AGI onset tAGI = 2028 gates software-driven crossovers, so delaying onset postpones lattice, hash, and symmetric breaks while leaving RSA’s hardware-driven Track 0 crossover unchanged.
- Sensitivity Analysis: The one-at-a-time analysis varies parameters across widened stress ranges, isolating individual effects rather than parameter interactions.The ranges are roughly double the calibrated Monte Carlo ranges: ±50% for couplings, hardware amplitude, and track ceiling; ±0.10 for track rate; ±100% for pre-AGI slope; hardware rate 1.05–1.35; and AGI onset 2026–2032.
- Sensitivity Analysis: A two-year AGI-onset delay leaves RSA Track 0 unchanged at 2032.5 but shifts software-driven crossovers later by roughly 1.8 years.Kyber-1024 Track 3 moves from 2032.3 to 2034.1, while AES-256 Track 3 moves from 2038.6 to 2040.4.
- Sensitivity Analysis: If hardware stalls at a rate of 1.05, RSA Track 0 shifts from 2032.5 to 2035.3 while software-driven crossovers barely move.If AI-assisted attack progress is 20% weaker, lattice, hash-based, and symmetric crossovers move later by roughly 0.6–1.0 years.
Appendix A.5. Joint Monte Carlo Over the Parameter Ranges
Appendix A.5 jointly samples all model parameters over their stated ranges to estimate probability curves for feasible-attack crossover by year. The resulting distributions show robust RSA-2048 exposure but keep lattice schemes outside the policy-relevant window in the reported tracks, while excluding hash-based and symmetric primitives because their crossover mechanisms lack cryptanalytic basis.
- Appendix A.5. Joint Monte Carlo Over the Parameter Ranges: Joint Monte Carlo sampling propagates simultaneous parameter uncertainty into P(T ≤ year), the probability that a scheme’s feasible-attack crossover occurs by a given year.The analysis uses N = 40,000 independent draws per algorithm and track, sampling the stated hardware, software, rate, ceiling, and AGI-onset ranges.
- Appendix A.5. Joint Monte Carlo Over the Parameter Ranges: RSA-2048 remains exposed across AGI assumptions: the no-AGI baseline has a median crossover near 2033 and about a 95% probability of feasible attack by 2035.Figure A2 plots the probability curves, while Table 7 reports crossover percentiles and selected exceedance probabilities.
- Appendix A.5. Joint Monte Carlo Over the Parameter Ranges: Lattice schemes remain outside the policy-relevant window under Track 0 and Track 1, with median crossovers in the late …The supplied passage truncates the remainder of the reported lattice crossover results.
- Appendix A.5. Joint Monte Carlo Over the Parameter Ranges: The Monte Carlo produces probability distributions rather than new evidence, and its outputs inherit the capability model’s chosen, unmeasured couplings and sensitivity to input-range changes.Widening or shifting the input ranges shifts the output curve.
- Appendix A.5. Joint Monte Carlo Over the Parameter Ranges: Hash-based and symmetric primitives are omitted because their crossovers rely on hypothesized mechanisms without cryptanalytic basis, so probabilities would misrepresent assumptions as calibrated likelihoods.Their dates are likewise withheld from Figure 9.
Appendix C. Hypothesis-Only Stress Cases: SLH-DSA (FIPS 205) and AES-256 (FIPS 197)
Appendix C treats SLH-DSA and AES-256 as hypothesis-only stress cases: no known quantum, classical, or algorithmic attack threatens either within the modeled horizon, and modeled crossovers require an unknown AI-discovered structural attack.
- Hypothesis-Only Stress Cases: No known quantum, classical, or algorithmic attack threatens SLH-DSA or AES-256 within the modeled horizon.
- Hypothesis-Only Stress Cases: The Track 2 and Track 3 crossovers exist only if advanced AI discovers a presently unknown class of structural attack.
- Hypothesis-Only Stress Cases: The cases are presented separately from mechanism-backed and contingency-backed projections and retained because Figure 9 consolidates them into the vulnerability spectrum.
Appendix C.1. SLH-DSA Estimates of CRQC+AI Vulnerability (FIPS 205)
The appendix evaluates SLH-DSA (FIPS 205) across four CRQC+AI vulnerability scenarios using runtime-attack and modeled-feasibility estimates. Under the adopted hypothesis-only treatment, SLH-DSA shows no modeled crossover within the horizon, and earlier dated projections are withdrawn as unsupported.
- Appendix C.1. SLH-DSA Estimates of CRQC+AI Vulnerability (FIPS 205): Figures C1A and C1B evaluate SLH-DSA runtime attacks and modeled feasibility across four vulnerability scenarios.The figures cover projected attack runtime and feasibility estimates for SLH-DSA FIPS 205.
- Appendix C.1. SLH-DSA Estimates of CRQC+AI Vulnerability (FIPS 205): SLH-DSA has zero software coupling and no modeled crossover within the horizon under the undated hypothesis-only treatment.Its lack of lattice structure prevents the collapse parameter ρ from acting, while Grover-type exposure is already absorbed into conservative parameters.
- Appendix C.1. SLH-DSA Estimates of CRQC+AI Vulnerability (FIPS 205): Earlier dated Track 2 and Track 3 projections are withdrawn because they relied on a presently unsupported novel attack.The appendix replaces those projections with an undated hypothesis-only treatment.
Appendix C.2. AES-256 Estimates of CRQC+AI Vulnerability (FIPS 197)
AES-256 retains 128-bit effective security under Grover-only analysis, with no feasible break for baseline and AGI-enhanced brute-force tracks across the projection horizon. Any dated break estimate remains speculative because no known quantum, classical, or algorithmic attack currently breaks AES-256.
- Assumptions and limitations: No known quantum, classical, or algorithmic attack breaks AES-256, and the hypothesis-only scenario therefore shows no feasible break within the horizon.AES-256 is assigned zero software coupling in this treatment.
- Results: AES-256 retains 128-bit effective security under Grover-only analysis, while Track 0 and Track 1 show no feasible break across the projection horizon.Grover’s algorithm reduces a 2^256 search to approximately 2^128 evaluations, making AES-256 the only FIPS 197 key length meeting NIST’s 128-bit quantum-security framework.
- Results: The updated projections show AES-256 reaching a feasible-attack threshold late in the horizon only under more aggressive AGI-software tracks.This scenario-dependent result does not establish a current cryptanalytic break.