REVIEW 2 major objections 1 minor 44 references
Quantifying quantum risk: a measure of crypto agility
T0 review · 2 major / 1 minor · reviewed 2026-06-27 · grok-4.3
Pith's one-line read Rotation time measures crypto agility by approximating how quickly keys must rotate to match an organization's security risk tolerance.
desk verdict The paper defines rotation time as a crypto agility metric and approximates it from CVE data, but the classical-to-quantum threat mapping is the main weakness. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Rotation time, the period required to rotate cryptographic algorithms or keys, serves as the central measure that converts risk tolerance into an operational agility target.
What would settle it
A calculation or dataset showing that quantum threat timelines require rotation times differing by an order of magnitude from the hours-to-days range derived from CVE data would invalidate the approximation.
Extended reading notes
Core claim
Rotation time is defined as the interval in which cryptographic primitives must be updated to keep risk within bounds; an approximation relates this interval to security risk tolerance, and calculations from CVE data place acceptable rotation times at the order of hours to days for typical organizational risk levels.
Load-bearing premise
Historical patterns of classical vulnerabilities can be used to set rotation tolerances that will apply to future quantum attacks.
Editorial extensions
If this is right
- Hybrid encryption schemes become viable for quantum resilience only when systems achieve rotation times within the derived tolerance window.
- Security architectures must incorporate rapid algorithm-update mechanisms to stay inside organizational risk limits.
- Operational processes for key and algorithm management face strict time constraints of hours to days.
- The approximation supplies a quantitative target that can be used to evaluate whether a given system's agility meets risk goals.
Reading between the lines
- Rotation time could be adapted as a general metric for agility against any future class of cryptanalytic advance.
- Standards bodies might adopt rotation-time targets as a compliance check for quantum-ready systems.
- Empirical measurement of actual rotation performance in deployed systems would allow direct comparison against the CVE-derived tolerances.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces the concept of rotation time as a measure of crypto agility, derives an approximation linking rotation time tolerance to security risk tolerance, and uses historical CVE data to calculate illustrative values on the order of hours to days. It concludes that crypto agility combined with hybrid encryption is an effective approach for quantum-resilient systems, though it may require challenging technical and operational tolerances.
Significance. If the approximation is sound and the CVE mapping holds, the work supplies a quantitative framework for deriving crypto-agility tolerances against quantum threats, addressing an explicit gap in the literature on system design requirements. The concrete illustrative numbers from CVE data add practical value for assessing organisational risk.
major comments (2)
- [Abstract] Abstract: the manuscript asserts a derivation of an approximation that links rotation time tolerance directly to security risk tolerance, yet supplies no equations, derivation steps, or explicit formula, preventing verification of whether the result is independent or whether risk tolerance is effectively defined in terms of the rotation time being quantified.
- [CVE-based calculation] CVE data section: historical CVE statistics, which predominantly record implementation bugs, configuration errors and side-channel issues, are used to compute rotation-time tolerances for quantum-enabled cryptanalysis; no justification is given for why the empirical distribution of classical vulnerability remediation times applies to deterministic algorithmic breaks such as Shor on RSA/ECC once a large quantum machine exists.
minor comments (1)
- [Abstract] Abstract: a short statement of the key assumptions underlying the approximation would improve readability without altering the central claim.
Simulated Author's Rebuttal
We thank the referee for the detailed and constructive report. We address each major comment below, indicating planned revisions where appropriate.
read point-by-point responses
-
Referee: [Abstract] Abstract: the manuscript asserts a derivation of an approximation that links rotation time tolerance directly to security risk tolerance, yet supplies no equations, derivation steps, or explicit formula, preventing verification of whether the result is independent or whether risk tolerance is effectively defined in terms of the rotation time being quantified.
Authors: The abstract is a concise summary and does not include equations for readability. The full derivation of the approximation, including the explicit formula and steps linking rotation time tolerance to security risk tolerance, appears in Section 3 of the manuscript. To address the concern, we will revise the abstract to state the key formula explicitly. revision: yes
-
Referee: [CVE-based calculation] CVE data section: historical CVE statistics, which predominantly record implementation bugs, configuration errors and side-channel issues, are used to compute rotation-time tolerances for quantum-enabled cryptanalysis; no justification is given for why the empirical distribution of classical vulnerability remediation times applies to deterministic algorithmic breaks such as Shor on RSA/ECC once a large quantum machine exists.
Authors: We agree that CVE data reflects classical issues and that quantum breaks differ in nature. The data is used strictly as an empirical illustration of observed cryptographic update timescales in deployed systems to produce concrete benchmark values. We will add a limitations paragraph clarifying the proxy nature of the mapping and the assumptions involved. revision: yes
Circularity Check
No circularity identified from available text
full rationale
The abstract describes introducing rotation time as a measure of crypto agility and deriving an approximation linking rotation time tolerance to security risk tolerance, with historical CVE data used only for illustrative calculations. No equations, self-citations, or derivation steps are present in the provided text that would allow identification of a reduction by construction (e.g., a fitted parameter renamed as prediction or a result defined in terms of itself). The use of external CVE data for illustration does not constitute a load-bearing self-citation or self-definitional step. The derivation is therefore treated as self-contained against external benchmarks.
Assumptions & free parameters
free parameters (1)
- parameters inside the rotation-time-to-risk approximation
assumptions (1)
- domain assumption Historical CVE data from classical attacks is representative for estimating tolerances against future quantum cryptanalysis
Cite this review
Pith. "Pith review of Quantifying quantum risk: a measure of crypto agility." pith.science (2026). https://pith.science/paper/YWN56IJA
@misc{pith2026260617116,
author = {Pith},
title = {Pith review of: Quantifying quantum risk: a measure of crypto agility},
year = {2026},
howpublished = {\url{https://pith.science/paper/YWN56IJA}},
note = {Machine review of arXiv:2606.17116}
}
read the original abstract
Because of their ability to enable new forms of cryptanalysis, quantum computers pose a threat to the cryptographic algorithms that are widely used to secure contemporary computer systems. A practical quantum computer may emerge within the next ten years or so, but due to theorised "harvest now, decrypt later" style attacker behaviour, mitigations are necessary today. Recent advances in cryptography and security architecture show promise in supporting the design of systems that exhibit resilience against quantum-enabled cryptanalysis, however there is a key gap in the literature around the subject of deriving tolerances for such systems. In this paper, we introduce the concept of rotation time as a measure of crypto agility, and derive an approximation that links rotation time tolerance to security risk tolerance. Historical CVE data is used to calculate illustrative values for rotation time tolerance, which is found to be of the order of hours to days. This demonstrates that using crypto agility in conjunction with hybrid encryption is an effective approach for designing quantum-resilient systems, but may necessitate challenging technical and operational tolerances in order to meet organisational risk tolerances.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[1]
Quantum-readiness for the financial system: a roadmap,
D. D. A. D. M. H. N. M. D. M. S. M. a. A. V. Raphael Auer, “Quantum-readiness for the financial system: a roadmap,” BIS Papers, no. 158, July 2025
2025
-
[2]
Quantum Computing: Navigating the Future of Computation, Challenges, and Technological Breakthroughs,
M. A. A. M. P. Qurban A. Memon, “Quantum Computing: Navigating the Future of Computation, Challenges, and Technological Breakthroughs,” Quantum Reports, 2024
2024
-
[3]
A fault-tolerant neutral-atom architecture for universal quantum computation.,
D. G. A. L. S. e. a. Bluvstein, “A fault-tolerant neutral-atom architecture for universal quantum computation.,” Nature, 2025
2025
-
[4]
The Grand Challenge of Quantum Applications,
R. K. S. B. W. H. T. K. G. H. L. J. R. M. T. O. N. C. R. Ryan Babbush, “The Grand Challenge of Quantum Applications,” arXiv, 2025
2025
-
[5]
Advancements in superconducting quantum computing,
C. D. H. F. B.-Y. L. L. S. X.-S. T. W. W. G.-M. X. F. Y. H.-F. Y. Y.-S. Z. Y.-R. Z. C.- L. Z. Yao-Yao Jiang, “Advancements in superconducting quantum computing,” National Science Review, vol. 12, no. 8, 2025
2025
-
[6]
Post-quantum cryptography : dealing with the fallout of physics success,
D. J. &. L. T. Bernstein, “Post-quantum cryptography : dealing with the fallout of physics success,” Cryptology ePrint Archive, p. 20, 2017
2017
-
[7]
A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,
A. S. L. A. R. L. Rivest, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,” Communications of the ACM, 1978
1978
-
[8]
AES Proposal: Rijndael,
V. R. Joan Daemen, “AES Proposal: Rijndael,” 1999
1999
Show all 44 references
-
[9]
Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,
P. W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,” Proceedings of the 35th Annual Symposium on Foundations of Computer Science, 1994
1994
-
[10]
A Fast Quantum Mechanical Algorithm for Database Search,
L. K. Grover, “A Fast Quantum Mechanical Algorithm for Database Search,” in Proceedings of the 28th Annual ACM Symposium on Theory of Computing, 1996
1996
-
[11]
R. A. Grimes, Cryptography Apocalypse: Preparing for the Day When Quantum Computing Breaks Today's Crypto, Wiley, 2019
2019
-
[12]
Quantum computing over the next five years: Scenario planning for strategic resilience,
Deloitte Center for Integrated Research, “Quantum computing over the next five years: Scenario planning for strategic resilience,” 2025
2025
-
[13]
An electoral exception? Quantum computing- readiness and internet voting,
A. R.-P. a. N. C. a. T. Finogina, “An electoral exception? Quantum computing- readiness and internet voting,” eJournal of eDemocracy and Open Government, Page 20 vol. 16, no. 3, 2024
2024
-
[14]
Status report on the third round of the NIST post-quantum cryptography standardization process.,
G. e. a. Alagic, “Status report on the third round of the NIST post-quantum cryptography standardization process.,” NIST, p. 90, 2022
2022
-
[15]
Announcing Issuance of Federal Information Processing Standards (FIPS) FIPS 203, Module-Lattice-Based Key- Encapsulation Mechanism Standard,
National Institute of Standards and Technology, “Announcing Issuance of Federal Information Processing Standards (FIPS) FIPS 203, Module-Lattice-Based Key- Encapsulation Mechanism Standard,” Federal Register, Washington, D.C., 2024
2024
-
[16]
In-line rate encrypted links using pre- shared post-quantum keys and DPUs,
A. R. G. C. L. D. e. a. Cano Aguilera, “ In-line rate encrypted links using pre- shared post-quantum keys and DPUs,” Scientific Reports, 2024
2024
-
[17]
Quantum Computing and the Financial System: Spooky Action at a Distance?,
M. G. M. M. a. T. S. S. Jose Deodoro, “Quantum Computing and the Financial System: Spooky Action at a Distance?,” IMF Working Paper, no. WP/21/71
-
[18]
Annual Report 2025,
National Cyber Security Centre, “Annual Report 2025,” p. 27
2025
-
[19]
Decrypting the Future: Insights from RSAC2025 Cryptographers’ Panel,
D. Bhasker, “Decrypting the Future: Insights from RSAC2025 Cryptographers’ Panel,” ISC2 Insights, 14 May 2025
2025
-
[20]
Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange,
N. a. B. J. a. F. M. a. G. B. a. S. D. Bindel, “Hybrid Key Encapsulation Mechanisms and Authenticated Key Exchange,” in Post-Quantum Cryptography, Springer International Publishing, 2019, pp. 206-226
2019
-
[21]
Quantum Safe Cryptography and Security,
European Telecommunications Standards Institute, “Quantum Safe Cryptography and Security,” 2015
2015
-
[22]
Toward a Common Understanding of Cryptographic Agility – A Systematic Review,
C. Naether, “Toward a Common Understanding of Cryptographic Agility – A Systematic Review,” IEEE Dataport, 2025
2025
-
[23]
Considerations for Achieving Crypto Agility: Strategies and Practices,
C. L. C. D. M. D. R. A. S. M. N. B. H. R. T. S. B. W. K. Barker E, “Considerations for Achieving Crypto Agility: Strategies and Practices,” National Institute of Standards and Technology, 2025
2025
-
[24]
On the State of Crypto-Agility,
N. A. a. N. S. a. A. W. a. A. H. a. T. Grasmeyer, “On the State of Crypto-Agility,” Cryptology {ePrint} Archive, Paper 2023/487, 2023
2023
-
[25]
SoK: Systematizing Hybrid Strategies for the Transition to Post- Quantum Cryptography,
A. A. Fall, “SoK: Systematizing Hybrid Strategies for the Transition to Post- Quantum Cryptography,” Cryptology ePrint Archive, 2025
2025
-
[26]
Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey,
G. C. a. S. S. a. P. H. a. S. B. a. S. Das, “Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey,” arXiv preprint Page 21 arXiv:2510.10436, 2025
2025 arXiv
-
[27]
Security in open versus closed systems—the dance of Boltzmann, Coase and Moore,
R. Anderson, “Security in open versus closed systems—the dance of Boltzmann, Coase and Moore,” Cambridge University
-
[28]
Is finding security holes a good idea?,
E. Rescorla, “Is finding security holes a good idea?,” IEEE Security & Privacy, vol. 3, no. 1, pp. 14-19, 2005
2005
-
[29]
Prediction capabilities of vulnerability discovery models,
Y. K. M. Omar Alhazmi, “Prediction capabilities of vulnerability discovery models,” in Annual Reliability and Maintainability Symposium, 2006
2006
-
[30]
A logarithmic Poisson execution time model for software reliability measurement,
K. O. John D Musa, “A logarithmic Poisson execution time model for software reliability measurement,” in Proceedings of the 7th international conference on Software engineering
-
[31]
26.2.4 Assurance Growth,
R. J. Anderson, “26.2.4 Assurance Growth,” in Security engineering: a guide to building dependable distributed systems, John Wiley & Sons, 2010
2010
-
[32]
Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management,
National Institute of Standards and Technology, “Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management,” Federal Register, Washington, DC, 2021
2021
-
[33]
Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic Libraries,
J. Blessing, M. A. Specter and D. J. Weitzner, “Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic Libraries,” MIT, 2024
2024
-
[34]
[Online]
National Institute of Standards and Technology, 22 October 2025. [Online]. Available: https://nvd.nist.gov/
2025
-
[35]
Vulnerability Metrics,
National Institute of Standards and Technology, “Vulnerability Metrics,” 22 October
-
[36]
Available: https://nvd.nist.gov/vuln-metrics/cvss
[Online]. Available: https://nvd.nist.gov/vuln-metrics/cvss
-
[37]
Common Vulnerability Scoring System v4.0 Specification Document,
FIRST (Forum of Incident Response and Security Teams), “Common Vulnerability Scoring System v4.0 Specification Document,” Forum of Incident Response and Security Teams, 2023
2023
-
[38]
Guide to enterprise patch management planning,
K. S. Murugiah Souppaya, “Guide to enterprise patch management planning,” Special Publication (NIST SP), 2022
2022
-
[39]
2020 cyber hygiene report: What you need to know now - lessons learned from a survey of the state of endpoint patching and hardening,
Automox, “2020 cyber hygiene report: What you need to know now - lessons learned from a survey of the state of endpoint patching and hardening,” Automox, 2020. Page 22
2020
-
[40]
Software Security Patch Management -- A Systematic Literature Review of Challenges, Approaches, Tools and Practices,
A. J. M. Z. M. A. B. Nesara Dissanayake, “Software Security Patch Management -- A Systematic Literature Review of Challenges, Approaches, Tools and Practices,” 2020
2020
-
[41]
Bi-criterion problem to determine optimal vulnerability discovery and patching time.,
S. e. a. Narang, “Bi-criterion problem to determine optimal vulnerability discovery and patching time.,” International Journal of Reliability, Quality and Safety Engineering, 2018
2018
-
[42]
Patching zero-day vulnerabilities: an empirical analysis,
Y. Roumani, “Patching zero-day vulnerabilities: an empirical analysis,” Journal of Cybersecurity, vol. 7, no. 1, 2021
2021
-
[43]
The digital pound: Technology Working Paper,
Bank of England, “The digital pound: Technology Working Paper,” Bank of England, 2023
2023
-
[44]
Exploit Prediction Scoring System (EPSS),
J. J. a. S. R. a. B. E. a. M. R. a. I. Adjerid, “Exploit Prediction Scoring System (EPSS),” CoRR, vol. abs/1908.04856, 2019
1908
Reviewed June 27, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.