针对TLS 1.3密码依赖项的CRQC+AI漏洞谱的基于场景的评估
A Scenario-Based Evaluation of CRQC+AI Vulnerability Spectrum for TLS 1.3 Cryptographic Dependencies
AI总结:
本文基于四场景能力模型评估TLS 1.3密码依赖项的CRQC+AI漏洞谱,明确NIST算法未被破解,提出PQC迁移强制要求及相关补充措施。
AI中文摘要:
本文在证据分层模型下评估了量子及AI加速对TLS 1.3密码依赖项的风险,区分了有机制支撑的威胁(针对RSA和ECC的Shor算法)、有偶然事件支撑的格基后量子密码(PQC)风险,以及仅基于假说的哈希基与对称原语风险。我们未发现ML-KEM、ML-DSA、SLH-DSA或AES-256存在已知破解。相反,我们使用明确的场景假设,将其组织为具有参数和可复现伪代码的四场景能力模型,对迁移时间线进行压力测试,同时开展参数敏感性分析与明确的证伪分析。主要方法学贡献是一个可复现的场景估计工具及其明确的更新机制:每个参数都是可调整的命名锚定量,可重新运行模型;明确的协议将观察到的与模型曲线的一致性或偏差映射到特定参数的修订,从而可根据累积历史数据测试逐步细化。本文是量子资源估计研究及专家 elicit 时间线调查(如全球风险研究所量子威胁报告)的方法学配套研究,其修订规则明确说明。截至2026年中,该模型未显示任何NIST批准的算法被破解。不同场景下的漏洞谱显示,在2030-2032年间RSA风险突破50%阈值,在以未经验证的维度坍缩为条件的偶然场景下,2032-2035年后PQC风险变为非零风险。我们敦促按照2030和2031年联邦截止日期及Mosca HNDL推理,将PQC迁移作为强制要求,并认为密码 agility(密码敏捷性)与混合密码部署是任何PQC迁移工作的必要补充。
英文摘要:
This paper evaluates quantum and AI-accelerated risks to TLS 1.3 cryptographic dependencies under an evidence-tiered model, distinguishing mechanism-backed threats (Shor algorithm against RSA and ECC) from contingency-backed risks to lattice-based post-quantum cryptography (PQC) and hypothesis-only risks to hash-based and symmetric primitives. We do not identify any known breaks of ML-KEM, ML-DSA, SLH-DSA, or AES-256. Instead, we use explicit scenario assumptions, organized as a four-scenario capability model with parameters and pseudocode for reproducibility, to stress-test migration timelines accompanied by parameter sensitivity analysis and explicit falsification analysis. The primary methodological contribution is a reproducible scenario-estimation instrument together with its explicit update mechanics: every parameter is a named, anchored quantity that can be varied and the model rerun; a stated protocol maps observed conformance to, or deviation from, the modeled curves onto revisions of specific parameters, so progressive refinements can be tested against accumulating historical data. The paper is a methodological companion to quantum resource-estimation studies and to expert-elicitation timeline surveys such as the Global Risk Institute quantum threat reports, with its revision rules stated explicitly. As of mid-2026, the model does not show any NIST-approved algorithms as broken. Instead, the vulnerability spectrum under different scenarios shows RSA risk crossing the 50% threshold between 2030-2032 and the PQC risk becoming a non-zero risk after 2032-2035 under contingency scenarios conditional on the unproven dimension-collapse. We urge PQC migration as mandatory per the 2030 and 2031 federal deadlines and by Mosca HNDL reasoning, and that crypto-agility and hybrid cryptographic deployment be considered necessary complements to any PQC migration efforts.