Overview & Methodology
Migration programmes conventionally sequence cryptographic assets by system criticality. We argue this is the wrong ordering under a harvest-now-decrypt-later threat model, and present a ranking function over data sensitivity lifetime, capture probability and re-key cost. Applied to three production financial estates totalling 5,400 hosts, the resulting order differs from criticality ranking in 38% of the top quartile, and concentrates residual risk in assets that conventional sequencing would have addressed last.
S. Malviya, U. Wad, S. Prabhudesai, U. Sinha. Exposure-lifetime ranking: reordering post-quantum migration by data sensitivity horizon. IEEE Transactions on Dependable and Secure Computing, 2026. doi:10.0000/uelement.2026.014
@article{malviya2026exposure,
title = {Exposure-lifetime ranking: reordering post-quantum migration by data sensitivity horizon},
author = {Malviya, S. and Prabhudesai, S. and Wad, U. and Sinha, U.},
journal= {IEEE Transactions on Dependable and Secure Computing},
year = {2026},
doi = {10.0000/uelement.2026.014}
}This theoretical finding runs in active enterprise production.
Discover how our engineering teams deployed these concepts under real-world operational constraints.
Publication Access
Science translated into battle-tested code.
- ◆Exhaustive Cryptographic Bill of Materials (CBOM)
- ◆Post-quantum vulnerability exposure ranking
- ◆Hardware-neutral algorithm assessment
- ◆Phased migration roadmap with operational safeguards
