Prioritizing Post-Quantum Migration in Synthetic Cryptographic Inventories with Machine Learning and QUBO Optimization

  • Larissa de Oliveira Figueira Facti
  • Luiz Otavio Duarte Facti
  • Rafael Lucas Silva Facti

Resumo


Post-quantum cryptography migration requires prioritizing cryptographic assets under budget and dependency constraints. This paper presents a reproducible pipeline combining supervised learning, heuristics, MILP, and QUBO. The evaluation covers three synthetic inventories with 1,609 assets, 1,179 migration candidates, and 1,050 dependencies. Logistic regression was selected for system-grouped priority estimation. Linear MILP achieved the highest predicted priority, closely followed by the priority-to-cost greedy method, while dependency-aware methods produced more coherent portfolios. Adding dependencies to QUBO reduced mean mandatory violations from 10.963 to 7.859 and increased coherence from 0.344 to 0.479, with a small priority decrease. Under the adopted soft objective, soft-dependency MILP achieved the best trade-off and substantially lower runtime. These results show that explicit dependency modeling improves migration coherence and that QUBO provides a flexible representation of budget and dependency interactions.
Palavras-chave: post-quantum cryptography, migration prioritization, cryptographic inventories, machine learning, QUBO

Referências

CISA, NSA, and NIST (2023). Quantum-readiness: Migration to post-quantum cryptography. Cybersecurity and Infrastructure Security Agency, National Security Agency, and National Institute of Standards and Technology. Available at: [link]. Accessed: 16 Jun. 2026.

ETSI (2020). ETSI TR 103 619 V1.1.1: CYBER; migration strategies and recommendations to quantum safe schemes. Technical report, European Telecommunications Standards Institute, Sophia Antipolis. Available at: [link]. Accessed: 16 Jun. 2026.

Figueira, L. d. O., Duarte, L. O., and Silva, R. L. (2026). PQC migration prioritization with machine learning and QUBO. GitHub repository. Version 1.0.0. Replication package containing the source code, notebook, synthetic datasets, experimental outputs, and replication instructions. Available at: [link]. Accessed: 5 Aug. 2026.

Glover, F., Kochenberger, G., and Du, Y. (2019). Quantum bridge analytics I: A tutorial on formulating and using QUBO models. 4OR, 17:335–371.

Hasan, K. F., Simpson, L., Rezazadeh Baee, M. A., Islam, C., Rahman, Z., Armstrong, W., Gauravaram, P., and McKague, M. (2024). A framework for migrating to post-quantum cryptography: Security dependency analysis and case studies. IEEE Access, 12:23427–23450.

Hastie, T., Tibshirani, R., and Friedman, J. (2009). The Elements of Statistical Learning: Data Mining, Inference, and Prediction. Springer, New York, 2nd edition.

Kirkpatrick, S., Gelatt, C. D., and Vecchi, M. P. (1983). Optimization by simulated annealing. Science, 220(4598):671–680.

Lucas, A. (2014). Ising formulations of many NP problems. Frontiers in Physics, 2:5.

Martello, S. and Toth, P. (1990). Knapsack Problems: Algorithms and Computer Implementations. John Wiley & Sons, Chichester.

NIST (2024a). FIPS 203: Module-lattice-based key-encapsulation mechanism standard. Federal Information Processing Standards Publication 203, National Institute of Standards and Technology, Gaithersburg, MD.

NIST (2024b). FIPS 204: Module-lattice-based digital signature standard. Federal Information Processing Standards Publication 204, National Institute of Standards and Technology, Gaithersburg, MD.

NIST (2024c). FIPS 205: Stateless hash-based digital signature standard. Federal Information Processing Standards Publication 205, National Institute of Standards and Technology, Gaithersburg, MD.

Shor, P. W. (1994). Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings of the 35th Annual Symposium on Foundations of Computer Science, pages 124–134, Los Alamitos, CA. IEEE Computer Society Press.

Silva, R. and Duarte, L. (2026a). Engineering trust in LLM supply chains through hybrid post-quantum artifact signatures. In Proceedings of the 20th IEEE International Workshop on Security, Trust, and Privacy for Software Applications (STPSA 2026), held in conjunction with the 50th IEEE Computer Society Annual International Conference on Computers, Software, and Applications (COMPSAC 2026), Madrid, Spain. IEEE. Workshop paper listed in the official COMPSAC 2026 program.

Silva, R. and Duarte, L. (2026b). Securing LLM software supply chains: A layered lifecycle framework with hybrid post-quantum artifact signing. In Proceedings of IEEE IDS 2026. IEEE. Camera-ready manuscript.

Silva, R. L. (2026). Toward quantum-resilient software supply chains: A DevSecOps case study with hybrid post-quantum artifact signing. In Proceedings of the 2026 IEEE International Conference on Quantum Communications, Networking, and Computing (QCNC), Kobe, Japan. IEEE. IEEE Xplore document 11500303. Available at: [link].
Publicado
01/09/2026
FIGUEIRA, Larissa de Oliveira; DUARTE, Luiz Otavio; SILVA, Rafael Lucas. Prioritizing Post-Quantum Migration in Synthetic Cryptographic Inventories with Machine Learning and QUBO Optimization. In: WORKSHOP CIBERSEGURANÇA QUÂNTICA: TEORIA, TECNOLOGIAS E APLICAÇÕES - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 843-849. DOI: https://doi.org/10.5753/sbseg_estendido.2026.30625.