Paper 2026/1174
A Layered Risk Scoring Model for TLS Connections Against Quantum Threats
Abstract
The advancement of quantum computing threatens public-key cryptographic algorithms used in TLS connections, such as RSA and ECDHE. The Harvest Now, Decrypt Later (HNDL) attack exposes long-term confidential data to risk even before quantum computers are practically realized, yet a systematic methodology for immediately quantifying the quantum vulnerability of individual TLS connections remains absent. This paper proposes a layered risk scoring model that quantifies the quantum threat exposure of TLS connections on a 0–100 scale. The model decomposes risk into five independent layers—TLS protocol exposure (L1), legacy public-key vulnerability (L2a), AES-128 Grover weakening (L2b), PQC Level-1 vulnerability (L2c), and certificate expiration urgency (L3)—and incorporates an HNDL global multiplier M that reflects the confidentiality retention period of transmitted data. Applied to 502 real-world TLS sessions across four industry sectors with M = 1.50, the domestic average risk score (16.0) is approximately 34% higher than the global average (11.9), with domestic legacy key exchange usage at 77.4% versus 53.5% globally and PQC adoption at 22.6% versus 46.5%. These results quantitatively confirm the elevated quantum risk of domestic network infrastructure, underscoring the urgency of PQC transition.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Post-Quantum CryptographyLayered Risk ScoringHNDLQuantum Vulnerability AssessmentCrypto-Agility
- Contact author(s)
-
yulim4hyoung @ gmail com
jeong9sumin @ gmail com
lima050627 @ gmail com
rhcp030418 @ gmail com
chosubin1208 @ gmail com
jaedol2023 @ gmail com
khj1594012 @ gmail com
hwajeong84 @ gmail com - History
- 2026-06-08: approved
- 2026-06-04: received
- See all versions
- Short URL
- https://ia.cr/2026/1174
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/1174,
author = {Yu-Lim Hyoung and Su-Min Jeong and Da-Eun Lim and Do-Yun Park and Su-Been Cho and Jae-Hwan Kim and Hyun-Ji Kim and Hwa-Jeong Seo},
title = {A Layered Risk Scoring Model for {TLS} Connections Against Quantum Threats},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1174},
year = {2026},
url = {https://eprint.iacr.org/2026/1174}
}