Search papers, labs, and topics across Lattice.
This paper evaluates the vulnerabilities of TLS 1.3 cryptographic dependencies in the context of quantum and AI threats, using an evidence-tiered model to differentiate between mechanism-backed and contingency-backed risks. The authors find no known vulnerabilities in ML-KEM, ML-DSA, SLH-DSA, or AES-256, but highlight a significant risk for RSA, projected to exceed 50% between 2030-2032, and a non-zero risk for post-quantum cryptography (PQC) after 2032-2035. The study introduces a reproducible scenario-estimation instrument that allows for parameter sensitivity analysis and explicit falsification, emphasizing the urgency of PQC migration by federal deadlines.
RSA cryptography faces a 50% vulnerability threshold by 2032, urging immediate action for PQC migration.
This paper evaluates quantum and AI-accelerated risks to TLS 1.3 cryptographic dependencies under an evidence-tiered model, distinguishing mechanism-backed threats (Shor algorithm against RSA and ECC) from contingency-backed risks to lattice-based post-quantum cryptography (PQC) and hypothesis-only risks to hash-based and symmetric primitives. We do not identify any known breaks of ML-KEM, ML-DSA, SLH-DSA, or AES-256. Instead, we use explicit scenario assumptions, organized as a four-scenario capability model with parameters and pseudocode for reproducibility, to stress-test migration timelines accompanied by parameter sensitivity analysis and explicit falsification analysis. The primary methodological contribution is a reproducible scenario-estimation instrument together with its explicit update mechanics: every parameter is a named, anchored quantity that can be varied and the model rerun; a stated protocol maps observed conformance to, or deviation from, the modeled curves onto revisions of specific parameters, so progressive refinements can be tested against accumulating historical data. The paper is a methodological companion to quantum resource-estimation studies and to expert-elicitation timeline surveys such as the Global Risk Institute quantum threat reports, with its revision rules stated explicitly. As of mid-2026, the model does not show any NIST-approved algorithms as broken. Instead, the vulnerability spectrum under different scenarios shows RSA risk crossing the 50% threshold between 2030-2032 and the PQC risk becoming a non-zero risk after 2032-2035 under contingency scenarios conditional on the unproven dimension-collapse. We urge PQC migration as mandatory per the 2030 and 2031 federal deadlines and by Mosca HNDL reasoning, and that crypto-agility and hybrid cryptographic deployment be considered necessary complements to any PQC migration efforts.