QianHeng乾珩 PQC Docs Hub量子文档 ✦ Ask AI✦ 问问文档 ⚐ Scan⚐ 扫一扫

Quantum Risk Assessment Model

Before choosing algorithms or planning a migration, an organization should quantify how exposed each business system is to the quantum threat. A structured quantum risk assessment (QRA) turns a vague worry into a ranked, defensible set of priorities — so scarce migration effort lands on the systems that matter most first.

A five-step model

  1. Asset identification & classification. Inventory sensitive data, core systems and key business processes, and classify them by value and sensitivity.
  2. Threat modeling. Map the relevant threats — data leakage, authentication bypass, system tampering — and weigh them against the likely quantum timeline and the gap between current key sizes and projected quantum capability.
  3. Vulnerability assessment. Examine reliance on quantum-weak cryptography, key lengths in use, and the security of the surrounding protocols.
  4. Risk quantification & ranking. Combine qualitative and quantitative scoring to rank systems and surface the high-risk domains.
  5. Risk-response strategy. Select responses — PQC migration, hybrid deployment, hardening — under the classic accept / transfer / mitigate / avoid framing.

Key factors that drive the score

  • Data lifetime. Long-lived sensitive data raises risk the most, because it can be captured today and decrypted later — see harvest-now, decrypt-later and Mosca's inequality (X + Y > Z).
  • Cryptographic dependency. Heavy reliance on RSA/ECC means a larger attack surface once a quantum computer arrives.
  • System update cycle. Systems that are slow or hard to change need an earlier start — the migration runway is longer.
  • Existing protection maturity. Strong current controls reduce, but do not eliminate, quantum exposure.
  • Compliance pressure. Finance, government and healthcare face the most urgent regulatory and contractual drivers.

Tools and methods

  • CISA/NSA/NIST — "Quantum-Readiness: Migration to PQC" (Aug 2023): inventory-first methodology and prioritization guidance.
  • ETSI GR QSC 004 (Quantum-Safe Security / Quantum Risk Assessment): a structured risk-assessment framework.
  • Commercial QRA tooling for automated discovery, scoring and reporting.

Worked example: an e-commerce order system

Applying the model to a typical online order platform produces the following profile:

FactorObservationRating
Sensitive data typePII, transaction records, payment dataHigh
Data lifetimeLong-term retention required by lawHigh
Crypto dependencyHeavy use of RSA/ECC for TLS and tokensHigh
Update cycleTwo major releases per year — long lead timeMedium
Protection maturityGood controls, but quantum posture unknownMedium
CompliancePCI DSS and GDPR obligationsHigh

Overall rating: HIGH. The combination of long-lived, regulated payment data and heavy RSA/ECC dependence means this system should be prioritized for migration.

From assessment to action

A completed QRA feeds directly into the rest of the program. Use it to seed your cryptographic discovery, confirm harvest-now exposure, shape the construction blueprint, and sequence the phased migration.

Standards & references

Note
A quantum risk assessment is not a one-time exercise. Re-run it as your asset inventory changes, as quantum capability estimates shift, and after each migration phase — the ranking it produces is only useful if it stays current.

量子风险评估模型

在选择算法或规划迁移之前,机构应当先量化每个业务系统对量子威胁的暴露程度。结构化的量子风险评估(QRA)能把模糊的担忧转化为一份可排序、可论证的优先级清单——让有限的迁移投入优先落在最关键的系统上。

五步模型

  1. 资产识别与分级。盘点敏感数据、核心系统与关键业务流程,并按价值与敏感度分级。
  2. 威胁建模。梳理相关威胁——数据泄露、认证绕过、系统篡改——并结合量子时间线,以及当前密钥长度与预期量子能力之间的差距加以权衡。
  3. 脆弱性评估。考察对量子脆弱密码的依赖程度、在用密钥长度,以及周边协议的安全性。
  4. 风险量化与排序。结合定性与定量评分,对系统排序并识别高风险领域。
  5. 风险应对策略。在经典的接受 / 转移 / 缓解 / 规避框架下,选择应对手段——PQC 迁移、混合部署、安全加固。

驱动评分的关键因素

  • 数据生命周期。长期留存的敏感数据使风险最为突出,因为它今天即可被截获、日后再解密——参见先收集后解密与 Mosca 不等式(X + Y > Z)。
  • 密码依赖度。对 RSA/ECC 的重度依赖意味着量子机器到来时攻击面更大。
  • 系统更新周期。变更缓慢或困难的系统需更早动手——所需迁移窗口更长。
  • 现有防护成熟度。当前控制越强,量子暴露越低,但无法彻底消除。
  • 合规压力。金融、政府与医疗面临最迫切的监管与合同驱动。

工具与方法

  • CISA/NSA/NIST《Quantum-Readiness: Migration to PQC》(2023年8月):资产盘点优先的方法论与优先级指引。
  • ETSI GR QSC 004(Quantum-Safe Security / 量子风险评估):结构化的风险评估框架。
  • 商用 QRA 工具:自动化发现、评分与报告。

实例演练 电商订单系统

将该模型套用于典型的在线订单平台,得到如下画像:

因素观察评级
敏感数据类型个人信息、交易记录、支付数据
数据生命周期法律要求长期留存
密码依赖度TLS 与令牌重度使用 RSA/ECC
更新周期每年两次大版本——交付周期长
防护成熟度控制良好 但量子态势未知
合规PCI DSS 与 GDPR 义务

总体评级 高。长期留存且受监管的支付数据,叠加对 RSA/ECC 的重度依赖,意味着该系统应当优先迁移

从评估到行动

一份完成的 QRA 可直接驱动后续工作:用它启动密码资产发现,确认先收集暴露面,塑造建设蓝图,并为分阶段迁移排序。

标准与参考

注意
量子风险评估并非一次性工作。每当资产清单变化、量子能力估计调整,以及每个迁移阶段结束后,都应重新评估——它产出的排序唯有保持时效才有价值。
⚑ Report an error⚑ 纠错与校正