Paper 2026/1174

A Layered Risk Scoring Model for TLS Connections Against Quantum Threats

Yu-Lim Hyoung, Hansung University
Su-Min Jeong, Hansung University
Da-Eun Lim, Hansung University
Do-Yun Park, Hansung University
Su-Been Cho, Hansung University
Jae-Hwan Kim, Hansung University
Hyun-Ji Kim, Hansung University
Hwa-Jeong Seo, Hansung University
Abstract

The advancement of quantum computing threatens public-key cryptographic algorithms used in TLS connections, such as RSA and ECDHE. The Harvest Now, Decrypt Later (HNDL) attack exposes long-term confidential data to risk even before quantum computers are practically realized, yet a systematic methodology for immediately quantifying the quantum vulnerability of individual TLS connections remains absent. This paper proposes a layered risk scoring model that quantifies the quantum threat exposure of TLS connections on a 0–100 scale. The model decomposes risk into five independent layers—TLS protocol exposure (L1), legacy public-key vulnerability (L2a), AES-128 Grover weakening (L2b), PQC Level-1 vulnerability (L2c), and certificate expiration urgency (L3)—and incorporates an HNDL global multiplier M that reflects the confidentiality retention period of transmitted data. Applied to 502 real-world TLS sessions across four industry sectors with M = 1.50, the domestic average risk score (16.0) is approximately 34% higher than the global average (11.9), with domestic legacy key exchange usage at 77.4% versus 53.5% globally and PQC adoption at 22.6% versus 46.5%. These results quantitatively confirm the elevated quantum risk of domestic network infrastructure, underscoring the urgency of PQC transition.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Post-Quantum CryptographyLayered Risk ScoringHNDLQuantum Vulnerability AssessmentCrypto-Agility
Contact author(s)
yulim4hyoung @ gmail com
jeong9sumin @ gmail com
lima050627 @ gmail com
rhcp030418 @ gmail com
chosubin1208 @ gmail com
jaedol2023 @ gmail com
khj1594012 @ gmail com
hwajeong84 @ gmail com
History
2026-06-08: approved
2026-06-04: received
See all versions
Short URL
https://ia.cr/2026/1174
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/1174,
      author = {Yu-Lim Hyoung and Su-Min Jeong and Da-Eun Lim and Do-Yun Park and Su-Been Cho and Jae-Hwan Kim and Hyun-Ji Kim and Hwa-Jeong Seo},
      title = {A Layered Risk Scoring Model for {TLS} Connections Against Quantum Threats},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1174},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1174}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.