Paper 2025/1549
Toward Crypto Agility: Automated Analysis of Quantum-Vulnerable TLS via Packet Inspection
Abstract
The advancement of quantum computing threatens traditional public-key cryptographic algorithms such as RSA and ECC, both vulnerable to Shor’s algorithm. As most Transport Layer Security (TLS) deployments still rely on these quantum-vulnerable algorithms for key exchange and digital signatures, the transition to Post-Quantum Cryptography (PQC), standardized by NIST, has become increasingly urgent. Given the critical role of TLS in securing Internet communications, identifying and replacing these algorithms in operational deployments is a key priority for ensuring long-term security. We present an automated method for analyzing TLS network packets to detect the use of quantum-vulnerable algorithms. Our approach combines hierarchical packet filtering, protocol-aware parsing, and a hybrid certificate extraction technique that enables analysis of encrypted TLS~1.3 certificates without full decryption. The framework achieved over 96\% detection accuracy, and our certificate parsing strategy improves overall throughput. Applying it to domestic and international TLS deployments revealed that domestic systems lag behind in quantum-readiness, underscoring the need for greater adoption of TLS~1.3, hybrid key exchanges (RSA/ECC with PQC), and short-lived certificates. Beyond TLS, the underlying methodology can be extended to other secure communication protocols, offering a versatile foundation for post-quantum migration strategies. These results highlight the practicality of our method for large-scale, real-time TLS assessments and its potential to guide PQC adoption.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Cryptographic AgilityTransport Layer SecurityPost-Quantum CryptographyPacket InspectionAutomated Analysis
- Contact author(s)
-
chosubin1208 @ gmail com
Yulim4Hyoung @ gmail com
kimhaha4420 @ gmail com
minjoos9797 @ gmail com
anupam @ ntu edu sg
hwajeong84 @ gmail com
khj1594012 @ gmail com - History
- 2025-09-03: approved
- 2025-08-29: received
- See all versions
- Short URL
- https://ia.cr/2025/1549
- License
-
CC0
BibTeX
@misc{cryptoeprint:2025/1549,
author = {Subeen Cho and Yulim Hyoung and Hagyeong Kim and Minjoo Sim and Anupam Chattopadhyay and Hwajeong Seo and Hyunji Kim},
title = {Toward Crypto Agility: Automated Analysis of Quantum-Vulnerable {TLS} via Packet Inspection},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1549},
year = {2025},
url = {https://eprint.iacr.org/2025/1549}
}