RACAF-PQC: A Risk-Aware Crypto-Agility Framework for Post-Quantum Secure Communication with Experimental Validation of Security, Performance and Migration Decisions
Keywords:
Post-quantum cryptography, ML-KEM, hybrid cryptography, crypto-agility, migration readiness, risk-aware security, quantum-resistant cryptography, cybersecurity, multi-criteria decision-makingAbstract
The emergence of cryptographically relevant quantum computing presents a fundamental challenge to contemporary public-key cryptography because Shor's algorithm can solve the integer-factorization and discrete-logarithm problems on which widely deployed RSA and elliptic-curve cryptographic systems rely. Although standardized post-quantum cryptographic (PQC) algorithms are now available, migration from classical cryptography to quantum-resistant systems is not a simple algorithm-selection problem. Different applications impose different requirements with respect to security strength, computational cost, communication overhead, interoperability, algorithmic diversity, and crypto-agility. This paper proposes RACAF-PQC, a Risk-Aware Crypto-Agility Framework for post-quantum migration decision-making. The framework introduces a Post-Quantum Migration Readiness Index (PMRI) that integrates six normalized criteria: security adequacy, computational performance, communication efficiency, algorithmic diversity, interoperability, and crypto-agility. Six cryptographic configurations are evaluated across five application scenarios: low-risk web communication, enterprise systems, high-confidentiality systems, constrained Internet-of-Things (IoT) environments, and critical infrastructure. The proposed framework is experimentally validated using a reproducible multi-criteria computational experiment and a 10,000-trial sensitivity analysis. Results show that the framework selects ML-KEM-512 for resource-sensitive environments and an ECDHE+ML-KEM-768 hybrid configuration for enterprise, high-confidentiality, and critical-infrastructure scenarios. Relative to a fixed ML-KEM-768 strategy, RACAF-PQC produces scenario-dependent decision improvements ranging from 0.7% to 8.8%, with a mean improvement of approximately 5.0%. Relative to classical-only migration, the corresponding mean improvement is approximately 42.0%. Sensitivity analysis demonstrates that the principal selections remain stable under perturbation of the decision weights, with selection stability reaching 100% for enterprise systems and 99.42% for critical infrastructure. The results demonstrate that post-quantum migration can be improved by treating cryptographic agility and application-specific risk as explicit decision variables rather than adopting a single universal algorithm. The study provides a mathematically transparent and reproducible framework for PQC migration planning while avoiding unsupported claims of hardware-level performance.
References
C. Jackson, S. Miller, and Y. Wang, “Evaluating the security of CRYSTALS-Dilithium in the quantum random oracle model,” in Advances in Cryptology – EUROCRYPT 2024, Springer, 2024. doi:10.1007/978-3-031-58751-1_15.
C. Paquin et al., “Post-quantum hybrid key exchange for TLS 1.3,” IETF Internet-Draft, 2024.
E. Alkim, L. Ducas, T. Pöppelmann, and P. Schwabe, “Post-quantum key exchange—A new hope,” in 25th USENIX Security Symposium, 2016, pp. 327–343.
European Union Agency for Cybersecurity (ENISA), Post-Quantum Cryptography: Current State and Quantum Mitigation, 2021.
European Union Agency for Cybersecurity (ENISA), Post-Quantum Cryptography: Integration Study, 2022.
J. Bos et al., “CRYSTALS-Kyber: A CCA-secure module-lattice-based KEM,” in 2018 IEEE European Symposium on Security and Privacy Workshops, 2018, pp. 353–367. doi:10.1109/EuroSPW.2018.00053.
L. Ducas et al., “CRYSTALS-Dilithium: A lattice-based digital signature scheme,” IACR Transactions on Cryptographic Hardware and Embedded Systems, 2018, pp. 238–268. doi:10.13154/tches.v2018.i1.238-268.
M. Alagic et al., Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process, NISTIR 8309, 2022.
National Institute of Standards and Technology, Module-Lattice-Based Key-Encapsulation Mechanism Standard, FIPS 203, Aug. 2024.
National Institute of Standards and Technology, Module-Lattice-Based Digital Signature Standard, FIPS 204, Aug. 2024.
National Institute of Standards and Technology, Recommendations for Key-Encapsulation Mechanisms, Draft NIST SP 800-227, Jan. 2025.
National Institute of Standards and Technology, Stateless Hash-Based Digital Signature Standard, FIPS 205, Aug. 2024.
National Institute of Standards and Technology, Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process, NISTIR 8545, Mar. 2025.
National Security Agency, Commercial National Security Algorithm Suite 2.0, 2022.
NIST, “Post-Quantum Cryptography Standardization,” National Institute of Standards and Technology, 2024–2025.
P. Schwabe et al., related CRYSTALS-Kyber and post-quantum key-establishment literature, 2018–2024.
P. W. Shor, “Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer,” SIAM Journal on Computing, vol. 26, no. 5, pp. 1484–1509, 1997. doi:10.1137/S0097539795293172.
Zheng et al., “Faster Post-Quantum TLS 1.3 Based on ML-KEM: Implementation and Assessment,” arXiv:2404.13544, 2024.
Downloads
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.




