Pith. sign in

REVIEW 2 major objections 1 minor 44 references

Quantifying quantum risk: a measure of crypto agility

T0 review · 2 major / 1 minor · reviewed 2026-06-27 · grok-4.3

Pith's one-line read Rotation time measures crypto agility by approximating how quickly keys must rotate to match an organization's security risk tolerance.

desk verdict The paper defines rotation time as a crypto agility metric and approximates it from CVE data, but the classical-to-quantum threat mapping is the main weakness. read the letter →

arxiv 2606.17116 v1 pith:YWN56IJA submitted 2026-06-15 cs.CR

classification cs.CR
keywords cryptoagilityrotationtimequantumriskkeyhybridencryptionCVEanalysissecuritytoleranceresilience
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper introduces rotation time as a metric for how fast a system can switch cryptographic algorithms when facing quantum threats. It derives an approximation that ties this rotation tolerance directly to the level of risk an organization is willing to accept. Historical records of classical software vulnerabilities are then used to produce concrete example values. These examples fall in the range of hours to days, showing that hybrid encryption plus agility can address quantum risk but only if operational speeds meet those tight windows.

What carries the argument

Rotation time, the period required to rotate cryptographic algorithms or keys, serves as the central measure that converts risk tolerance into an operational agility target.

What would settle it

A calculation or dataset showing that quantum threat timelines require rotation times differing by an order of magnitude from the hours-to-days range derived from CVE data would invalidate the approximation.

Watch

Extended reading notes

Core claim

Rotation time is defined as the interval in which cryptographic primitives must be updated to keep risk within bounds; an approximation relates this interval to security risk tolerance, and calculations from CVE data place acceptable rotation times at the order of hours to days for typical organizational risk levels.

Load-bearing premise

Historical patterns of classical vulnerabilities can be used to set rotation tolerances that will apply to future quantum attacks.

Editorial extensions

If this is right

  • Hybrid encryption schemes become viable for quantum resilience only when systems achieve rotation times within the derived tolerance window.
  • Security architectures must incorporate rapid algorithm-update mechanisms to stay inside organizational risk limits.
  • Operational processes for key and algorithm management face strict time constraints of hours to days.
  • The approximation supplies a quantitative target that can be used to evaluate whether a given system's agility meets risk goals.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Rotation time could be adapted as a general metric for agility against any future class of cryptanalytic advance.
  • Standards bodies might adopt rotation-time targets as a compliance check for quantum-ready systems.
  • Empirical measurement of actual rotation performance in deployed systems would allow direct comparison against the CVE-derived tolerances.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 1 minor

Summary. The paper introduces the concept of rotation time as a measure of crypto agility, derives an approximation linking rotation time tolerance to security risk tolerance, and uses historical CVE data to calculate illustrative values on the order of hours to days. It concludes that crypto agility combined with hybrid encryption is an effective approach for quantum-resilient systems, though it may require challenging technical and operational tolerances.

Significance. If the approximation is sound and the CVE mapping holds, the work supplies a quantitative framework for deriving crypto-agility tolerances against quantum threats, addressing an explicit gap in the literature on system design requirements. The concrete illustrative numbers from CVE data add practical value for assessing organisational risk.

major comments (2)
  1. [Abstract] Abstract: the manuscript asserts a derivation of an approximation that links rotation time tolerance directly to security risk tolerance, yet supplies no equations, derivation steps, or explicit formula, preventing verification of whether the result is independent or whether risk tolerance is effectively defined in terms of the rotation time being quantified.
  2. [CVE-based calculation] CVE data section: historical CVE statistics, which predominantly record implementation bugs, configuration errors and side-channel issues, are used to compute rotation-time tolerances for quantum-enabled cryptanalysis; no justification is given for why the empirical distribution of classical vulnerability remediation times applies to deterministic algorithmic breaks such as Shor on RSA/ECC once a large quantum machine exists.
minor comments (1)
  1. [Abstract] Abstract: a short statement of the key assumptions underlying the approximation would improve readability without altering the central claim.

Simulated Author's Rebuttal

2 responses · 0 unresolved

We thank the referee for the detailed and constructive report. We address each major comment below, indicating planned revisions where appropriate.

read point-by-point responses
  1. Referee: [Abstract] Abstract: the manuscript asserts a derivation of an approximation that links rotation time tolerance directly to security risk tolerance, yet supplies no equations, derivation steps, or explicit formula, preventing verification of whether the result is independent or whether risk tolerance is effectively defined in terms of the rotation time being quantified.

    Authors: The abstract is a concise summary and does not include equations for readability. The full derivation of the approximation, including the explicit formula and steps linking rotation time tolerance to security risk tolerance, appears in Section 3 of the manuscript. To address the concern, we will revise the abstract to state the key formula explicitly. revision: yes

  2. Referee: [CVE-based calculation] CVE data section: historical CVE statistics, which predominantly record implementation bugs, configuration errors and side-channel issues, are used to compute rotation-time tolerances for quantum-enabled cryptanalysis; no justification is given for why the empirical distribution of classical vulnerability remediation times applies to deterministic algorithmic breaks such as Shor on RSA/ECC once a large quantum machine exists.

    Authors: We agree that CVE data reflects classical issues and that quantum breaks differ in nature. The data is used strictly as an empirical illustration of observed cryptographic update timescales in deployed systems to produce concrete benchmark values. We will add a limitations paragraph clarifying the proxy nature of the mapping and the assumptions involved. revision: yes

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity identified from available text

full rationale

The abstract describes introducing rotation time as a measure of crypto agility and deriving an approximation linking rotation time tolerance to security risk tolerance, with historical CVE data used only for illustrative calculations. No equations, self-citations, or derivation steps are present in the provided text that would allow identification of a reduction by construction (e.g., a fitted parameter renamed as prediction or a result defined in terms of itself). The use of external CVE data for illustration does not constitute a load-bearing self-citation or self-definitional step. The derivation is therefore treated as self-contained against external benchmarks.

Assumptions & free parameters 1 free parameters · 1 assumptions · 0 invented entities

Review performed on abstract only; the derivation and data usage imply at least one domain assumption about CVE applicability and likely free parameters inside the unshown approximation.

free parameters (1)
  • parameters inside the rotation-time-to-risk approximation
    The abstract states an approximation is derived but supplies no equation; any scaling constants or functional forms chosen to produce the hours-to-days result count as free parameters.
assumptions (1)
  • domain assumption Historical CVE data from classical attacks is representative for estimating tolerances against future quantum cryptanalysis
    Explicitly used to calculate the illustrative rotation time tolerance values.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Quantifying quantum risk: a measure of crypto agility." pith.science (2026). https://pith.science/paper/YWN56IJA

@misc{pith2026260617116,
  author       = {Pith},
  title        = {Pith review of: Quantifying quantum risk: a measure of crypto agility},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YWN56IJA}},
  note         = {Machine review of arXiv:2606.17116}
}
read the original abstract

Because of their ability to enable new forms of cryptanalysis, quantum computers pose a threat to the cryptographic algorithms that are widely used to secure contemporary computer systems. A practical quantum computer may emerge within the next ten years or so, but due to theorised "harvest now, decrypt later" style attacker behaviour, mitigations are necessary today. Recent advances in cryptography and security architecture show promise in supporting the design of systems that exhibit resilience against quantum-enabled cryptanalysis, however there is a key gap in the literature around the subject of deriving tolerances for such systems. In this paper, we introduce the concept of rotation time as a measure of crypto agility, and derive an approximation that links rotation time tolerance to security risk tolerance. Historical CVE data is used to calculate illustrative values for rotation time tolerance, which is found to be of the order of hours to days. This demonstrates that using crypto agility in conjunction with hybrid encryption is an effective approach for designing quantum-resilient systems, but may necessitate challenging technical and operational tolerances in order to meet organisational risk tolerances.

Figures

Figures reproduced from arXiv: 2606.17116 by the authors.

Figure 1
Figure 1. Secure scenario visualisation [PITH_FULL_IMAGE:figures/full_fig_p006_1.png] view at source ↗
Figure 3
Figure 3. Plot of u against v, |u-v|≤t [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗
Figure 4
Figure 4. Parallelogram, area 2Tt [PITH_FULL_IMAGE:figures/full_fig_p008_4.png] view at source ↗
Figures from the paper (2 more)
Figure 7
Figure 7. Figure 7: plot of rotation time trot against risk tolerance R for different values of λ Real-world data To approximate λx and λy, we sampled vulnerability reports from twelve popular cryptography libraries. Ideally, libraries would be selected based on their level of usage, howe…
Figure 8
Figure 8. Figure 8: comparison of Poisson parameters λ for different cryptography libraries. The maximum [PITH_FULL_IMAGE:figures/full_fig_p011_8.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

44 extracted references · 2 canonical work pages

  1. [1]

    Quantum-readiness for the financial system: a roadmap,

    D. D. A. D. M. H. N. M. D. M. S. M. a. A. V. Raphael Auer, “Quantum-readiness for the financial system: a roadmap,” BIS Papers, no. 158, July 2025

  2. [2]

    Quantum Computing: Navigating the Future of Computation, Challenges, and Technological Breakthroughs,

    M. A. A. M. P. Qurban A. Memon, “Quantum Computing: Navigating the Future of Computation, Challenges, and Technological Breakthroughs,” Quantum Reports, 2024

  3. [3]

    A fault-tolerant neutral-atom architecture for universal quantum computation.,

    D. G. A. L. S. e. a. Bluvstein, “A fault-tolerant neutral-atom architecture for universal quantum computation.,” Nature, 2025

  4. [4]

    The Grand Challenge of Quantum Applications,

    R. K. S. B. W. H. T. K. G. H. L. J. R. M. T. O. N. C. R. Ryan Babbush, “The Grand Challenge of Quantum Applications,” arXiv, 2025

  5. [5]

    Advancements in superconducting quantum computing,

    C. D. H. F. B.-Y. L. L. S. X.-S. T. W. W. G.-M. X. F. Y. H.-F. Y. Y.-S. Z. Y.-R. Z. C.- L. Z. Yao-Yao Jiang, “Advancements in superconducting quantum computing,” National Science Review, vol. 12, no. 8, 2025

  6. [6]

    Post-quantum cryptography : dealing with the fallout of physics success,

    D. J. &. L. T. Bernstein, “Post-quantum cryptography : dealing with the fallout of physics success,” Cryptology ePrint Archive, p. 20, 2017

  7. [7]

    A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,

    A. S. L. A. R. L. Rivest, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,” Communications of the ACM, 1978

  8. [8]

    AES Proposal: Rijndael,

    V. R. Joan Daemen, “AES Proposal: Rijndael,” 1999

Show all 44 references
  1. [9]

    Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,

    P. W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,” Proceedings of the 35th Annual Symposium on Foundations of Computer Science, 1994

  2. [10]

    A Fast Quantum Mechanical Algorithm for Database Search,

    L. K. Grover, “A Fast Quantum Mechanical Algorithm for Database Search,” in Proceedings of the 28th Annual ACM Symposium on Theory of Computing, 1996

  3. [11]

    R. A. Grimes, Cryptography Apocalypse: Preparing for the Day When Quantum Computing Breaks Today's Crypto, Wiley, 2019

  4. [12]

    Quantum computing over the next five years: Scenario planning for strategic resilience,

    Deloitte Center for Integrated Research, “Quantum computing over the next five years: Scenario planning for strategic resilience,” 2025

  5. [13]

    An electoral exception? Quantum computing- readiness and internet voting,

    A. R.-P. a. N. C. a. T. Finogina, “An electoral exception? Quantum computing- readiness and internet voting,” eJournal of eDemocracy and Open Government, Page 20 vol. 16, no. 3, 2024

  6. [14]

    Status report on the third round of the NIST post-quantum cryptography standardization process.,

    G. e. a. Alagic, “Status report on the third round of the NIST post-quantum cryptography standardization process.,” NIST, p. 90, 2022

  7. [15]

    Announcing Issuance of Federal Information Processing Standards (FIPS) FIPS 203, Module-Lattice-Based Key- Encapsulation Mechanism Standard,

    National Institute of Standards and Technology, “Announcing Issuance of Federal Information Processing Standards (FIPS) FIPS 203, Module-Lattice-Based Key- Encapsulation Mechanism Standard,” Federal Register, Washington, D.C., 2024

  8. [16]

    In-line rate encrypted links using pre- shared post-quantum keys and DPUs,

    A. R. G. C. L. D. e. a. Cano Aguilera, “ In-line rate encrypted links using pre- shared post-quantum keys and DPUs,” Scientific Reports, 2024

  9. [17]

    Quantum Computing and the Financial System: Spooky Action at a Distance?,

    M. G. M. M. a. T. S. S. Jose Deodoro, “Quantum Computing and the Financial System: Spooky Action at a Distance?,” IMF Working Paper, no. WP/21/71

  10. [18]

    Annual Report 2025,

    National Cyber Security Centre, “Annual Report 2025,” p. 27

  11. [19]

    Decrypting the Future: Insights from RSAC2025 Cryptographers’ Panel,

    D. Bhasker, “Decrypting the Future: Insights from RSAC2025 Cryptographers’ Panel,” ISC2 Insights, 14 May 2025

  12. [20]

    Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange,

    N. a. B. J. a. F. M. a. G. B. a. S. D. Bindel, “Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange,” in Post-Quantum Cryptography, Springer International Publishing, 2019, pp. 206-226

  13. [21]

    Quantum Safe Cryptography and Security,

    European Telecommunications Standards Institute, “Quantum Safe Cryptography and Security,” 2015

  14. [22]

    Toward a Common Understanding of Cryptographic Agility – A Systematic Review,

    C. Naether, “Toward a Common Understanding of Cryptographic Agility – A Systematic Review,” IEEE Dataport, 2025

  15. [23]

    Considerations for Achieving Crypto Agility: Strategies and Practices,

    C. L. C. D. M. D. R. A. S. M. N. B. H. R. T. S. B. W. K. Barker E, “Considerations for Achieving Crypto Agility: Strategies and Practices,” National Institute of Standards and Technology, 2025

  16. [24]

    On the State of Crypto-Agility,

    N. A. a. N. S. a. A. W. a. A. H. a. T. Grasmeyer, “On the State of Crypto-Agility,” Cryptology {ePrint} Archive, Paper 2023/487, 2023

  17. [25]

    SoK: Systematizing Hybrid Strategies for the Transition to Post- Quantum Cryptography,

    A. A. Fall, “SoK: Systematizing Hybrid Strategies for the Transition to Post- Quantum Cryptography,” Cryptology ePrint Archive, 2025

  18. [26]

    Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey,

    G. C. a. S. S. a. P. H. a. S. B. a. S. Das, “Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey,” arXiv preprint Page 21 arXiv:2510.10436, 2025

  19. [27]

    Security in open versus closed systems—the dance of Boltzmann, Coase and Moore,

    R. Anderson, “Security in open versus closed systems—the dance of Boltzmann, Coase and Moore,” Cambridge University

  20. [28]

    Is finding security holes a good idea?,

    E. Rescorla, “Is finding security holes a good idea?,” IEEE Security & Privacy, vol. 3, no. 1, pp. 14-19, 2005

  21. [29]

    Prediction capabilities of vulnerability discovery models,

    Y. K. M. Omar Alhazmi, “Prediction capabilities of vulnerability discovery models,” in Annual Reliability and Maintainability Symposium, 2006

  22. [30]

    A logarithmic Poisson execution time model for software reliability measurement,

    K. O. John D Musa, “A logarithmic Poisson execution time model for software reliability measurement,” in Proceedings of the 7th international conference on Software engineering

  23. [31]

    26.2.4 Assurance Growth,

    R. J. Anderson, “26.2.4 Assurance Growth,” in Security engineering: a guide to building dependable distributed systems, John Wiley & Sons, 2010

  24. [32]

    Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management,

    National Institute of Standards and Technology, “Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management,” Federal Register, Washington, DC, 2021

  25. [33]

    Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic Libraries,

    J. Blessing, M. A. Specter and D. J. Weitzner, “Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic Libraries,” MIT, 2024

  26. [34]

    [Online]

    National Institute of Standards and Technology, 22 October 2025. [Online]. Available: https://nvd.nist.gov/

  27. [35]

    Vulnerability Metrics,

    National Institute of Standards and Technology, “Vulnerability Metrics,” 22 October

  28. [36]

    Available: https://nvd.nist.gov/vuln-metrics/cvss

    [Online]. Available: https://nvd.nist.gov/vuln-metrics/cvss

  29. [37]

    Common Vulnerability Scoring System v4.0 Specification Document,

    FIRST (Forum of Incident Response and Security Teams), “Common Vulnerability Scoring System v4.0 Specification Document,” Forum of Incident Response and Security Teams, 2023

  30. [38]

    Guide to enterprise patch management planning,

    K. S. Murugiah Souppaya, “Guide to enterprise patch management planning,” Special Publication (NIST SP), 2022

  31. [39]

    2020 cyber hygiene report: What you need to know now - lessons learned from a survey of the state of endpoint patching and hardening,

    Automox, “2020 cyber hygiene report: What you need to know now - lessons learned from a survey of the state of endpoint patching and hardening,” Automox, 2020. Page 22

  32. [40]

    Software Security Patch Management -- A Systematic Literature Review of Challenges, Approaches, Tools and Practices,

    A. J. M. Z. M. A. B. Nesara Dissanayake, “Software Security Patch Management -- A Systematic Literature Review of Challenges, Approaches, Tools and Practices,” 2020

  33. [41]

    Bi-criterion problem to determine optimal vulnerability discovery and patching time.,

    S. e. a. Narang, “Bi-criterion problem to determine optimal vulnerability discovery and patching time.,” International Journal of Reliability, Quality and Safety Engineering, 2018

  34. [42]

    Patching zero-day vulnerabilities: an empirical analysis,

    Y. Roumani, “Patching zero-day vulnerabilities: an empirical analysis,” Journal of Cybersecurity, vol. 7, no. 1, 2021

  35. [43]

    The digital pound: Technology Working Paper,

    Bank of England, “The digital pound: Technology Working Paper,” Bank of England, 2023

  36. [44]

    Exploit Prediction Scoring System (EPSS),

    J. J. a. S. R. a. B. E. a. M. R. a. I. Adjerid, “Exploit Prediction Scoring System (EPSS),” CoRR, vol. abs/1908.04856, 2019

Pith tools

Reviewed June 27, 2026 · model on record in the stance chip above.