{"id":"bd55b47f-aebc-457e-bfc9-785687be05e1","arxiv_id":"2511.03538","paper_version":1,"verdict":"UNVERDICTED","confidence":"HIGH","novelty_score":1.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A book-chapter survey arguing that quantum computers threaten IoT cryptography and that PQC, QKD, and QRNGs are the path to quantum-safe IoT.","lead":"This chapter is a tutorial survey of how quantum computing threatens classical IoT cryptography and how post-quantum cryptography, quantum key distribution, and quantum random number generators might replace it. It contains no new algorithm or experiment; its value is as an organized overview for students and practitioners.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Urgency argument rests on unverified 10-30 year CRQC timeline, which is internally inconsistent with Table 4.3 vs §4.6.2; if the timeline stretches, near-term migration recommendation loses force.","rationale":"The central assertion—that quantum computers, once powerful enough, would break RSA/ECC and weaken AES—is standard and supported by the cited primary literature (Shor 1997; Grover 1996). As a tutorial, the chapter makes no new algorithmic claim and explicitly frames itself that way, so the appropriate disposition is not accept/reject but an assessment of reliability. The load-bearing step is the jump from theoretical vulnerability to 'IoT deployments today must migrate now.' That jump requires a credible estimate that CRQCs arrive within the lifespan of deployed IoT devices and the data they protect. The chapter's 10–30 year figure (and §4.6.2's 10–15 year variant) is presented as established fact but is not independently derived; the cited reports are expert projections, not proof. The internal inconsistency between Table 4.3 (~8 hours/full circuit) and §4.6.2 ('seconds') further lowers confidence in the quantitative framework. However, the HNDL argument provides a partial independent reason for migration even under longer timelines, so the concern is real but not disqualifying. The reader's UNVERDICTED verdict remains right; a stronger verdict would require the paper to either present original resource estimates or clearly label the timeline as speculative.","tokens_in":37905,"tokens_out":7377,"duration_ms":69755,"concrete_test":"Perform a timeline-sensitivity analysis: keep all other arguments fixed, replace the 10–30 year CRQC window in §4.3.5 with a 50-year horizon, and test whether the 'immediate PQC migration' conclusion still follows from the harvest-now-decrypt-later argument alone. If the conclusion is invariant, the timeline is not load-bearing; if it flips, the concern is confirmed. For completeness, also check whether Table 4.3's ~8-hour RSA-2048 estimate can be reconciled with §4.6.2's 'seconds' under the same fault-tolerant architecture.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The practical conclusion of the chapter—that IoT cryptography must be migrated to PQC/QKD/QRNG now—depends on the assertion in §4.3.5 that cryptographically relevant quantum computers (CRQCs) will arrive in 10–30 years. This is load-bearing because the central 'strongest claim' is conditional: if the true CRQC date is far outside the operational lifetime of IoT devices and the data they handle, the urgency to accept the overheads of PQC/QKD on constrained hardware is substantially reduced, even though Shor's algorithm remains valid in principle. The chapter supports the timeline only by citing expert reports (Gidney–Ekerå, QED-C, IBM) without independent derivation, and it is internally inconsistent about the same numbers: Table 4.3 reports RSA-2048 factoring in ~8 hours with ~20M physical qubits, while §4.6.2 says Shor's will break RSA-2048/ECC-256 'in seconds'; §4.3.5 gives 10–30 years while §4.6.2 gives 10–15 years. These contradictions do not touch the conditional 'could fail' claim, but they weaken the quantitative foundation of the 'must act now' recommendation.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This book chapter surveys the impact of quantum computing on IoT security and privacy. It reviews classical cryptographic primitives (AES, RSA, Diffie-Hellman, ECC, hash functions), explains Shor's and Grover's algorithms, and gives resource estimates for breaking RSA-2048 and ECC-256. It then surveys post-quantum cryptography (lattice-, hash-, code-, multivariate-, and isogeny-based schemes), quantum-based mechanisms (QKD, QRNG), hybrid quantum-classical architectures, smart-city deployments, standardization efforts, and regulatory issues. The central claim is that quantum computers will threaten classical IoT cryptography, and that proactive migration to PQC/QKD/QRNG is necessary, with urgency driven by expert timelines for cryptographically relevant quantum computers and by the harvest-now-decrypt-later threat.","tokens_in":38202,"tokens_out":6508,"duration_ms":58591,"significance":"As a tutorial survey, the chapter provides a broad and readable synthesis of a large literature, with useful tables (Tables 4.1–4.10), coverage of NIST/ETSI/ITU-T standardization, real-world QKD pilots, and a clear explanation of why Shor's and Grover's algorithms matter for IoT. The main narrative is conventional and broadly correct. However, the chapter's action-oriented conclusion—that IoT must migrate now—rests on quantitative claims that are internally inconsistent, and there are several factual inaccuracies in the PQC survey. If these are corrected, the chapter would be a useful reference for students and practitioners; in its current form, the inconsistencies undermine the reliability of the guidance it offers.","major_comments":[{"comment":"The load-bearing argument for urgent PQC adoption is based on inconsistent quantitative claims. §4.3.5 states that cryptographically relevant quantum computers could become feasible in 10–30 years, while §4.6.2 states that IBM and QED-C expect CRQCs within 10–15 years. More strikingly, Table 4.3 reports that factoring RSA-2048 would take approximately 8 hours with ~20 million physical qubits, whereas §4.6.2 says Shor's algorithm will break 2048-bit RSA or 256-bit ECC 'in seconds'. These are not minor differences; they are directly connected to the chapter's recommendation that migration must happen now. The authors should reconcile the numbers, specify which sources and assumptions underlie each estimate, and state the uncertainty explicitly.","section":"§4.3.5, §4.6.2, Table 4.3"},{"comment":"The chapter presents SIKE as a promising isogeny-based scheme that is 'thought to be quantum resistant' and 'seemingly ideal for IoT devices' because of its small key sizes. It fails to mention that SIKE was broken in 2022 by Castryck and Decru and was subsequently withdrawn from the NIST PQC process. Since the chapter's stated contribution is to assess PQC families and their suitability for IoT, presenting a broken scheme as viable is a significant factual omission that misleads readers about the current state of the field.","section":"§4.6.3 (Isogeny-Based Cryptography)"},{"comment":"The text claims that QPIR can achieve sub-linear communication complexity and cites reference [152] (Baumeler and Broadbent, 'Quantum private information retrieval has linear communication complexity'). The cited paper's title and result state linear communication complexity, not sub-linear. The sub-linear result is associated with reference [155] (Le Gall). This is a direct misattribution of a central result in the section and should be corrected.","section":"§4.6.6.1 and reference [152]"}],"minor_comments":[{"comment":"AES key sizes are listed as '128, 102, and 256 bits'; the correct sizes are 128, 192, and 256 bits.","section":"§4.2.1.2"},{"comment":"In the Diffie-Hellman protocol description, Bob's secret key is said to satisfy 1 < b < q, but q is never defined; it should be the prime modulus p (or the group order, if explicitly introduced).","section":"§4.2.2.2"},{"comment":"The 'deterministic' property states H(m1)=H(m2) ⇔ m1=m2. This is incorrect: hash functions are not injective. Determinism means the same input always yields the same output; the equivalence should be one-directional (m1=m2 ⇒ H(m1)=H(m2)).","section":"§4.2.3 (Fundamental Properties)"},{"comment":"The target logical error rate for cryptographic applications is written as '10-15'; it should be 10^-15.","section":"§4.3.3"},{"comment":"The quantum threat row for confidentiality says 'Grover’s reduces AES-128 or 64-bit effort'. This is ambiguous and should be clarified, e.g., Grover's reduces AES-128 key search to about 2^64 operations.","section":"Table 4.8"},{"comment":"Several typos: 'salability' should be 'scalability'; §4.2.2.1 has 'Addleman' for 'Adleman'; §4.1 has 'Gover’s' for 'Grover’s'; Table 4.10 repeats 'Multivariate (Signature)' in the GeMSS row.","section":"Abstract and various"},{"comment":"The text cites reference [50] for TLS, but [50] is RFC 5280 (X.509 PKI certificate profile). The appropriate reference for TLS 1.3 would be RFC 8446.","section":"§4.6.4.2"}],"recommendation":"major_revision","confidential_remarks":"The chapter is a tutorial survey rather than an original research contribution, so the main evaluation criterion is faithful representation of the literature. The timeline inconsistency (§4.3.5 vs §4.6.2) and the unmentioned SIKE break (§4.6.3) are, in my view, the most serious issues. Both are fixable with careful revision, but they currently prevent the chapter from being a reliable reference. I would not reject; the chapter has clear pedagogical value if corrected."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"This is a survey chapter, not a research paper, and it says so itself: no new algorithm or scheme. What it does well is organize the standard story—Shor and Grover breaking RSA/ECC and weakening AES, the PQC families (lattice, hash, code, multivariate), and the complementary roles of QKD and QRNG—into a readable tutorial aimed at IoT folks. The coverage is broad and mostly accurate, and the tables and figures do a decent job of summarizing trade-offs. If you need a one-stop introduction to the topic for a student or a practitioner outside crypto, this is a reasonable starting point.\n\nBut it is not a reliable reference as written. The internal inconsistencies are worth flagging: Section 4.3.5 says cryptographically relevant quantum computers may arrive in 10–30 years, while Section 4.6.2 says 10–15 years, and Table 4.3 gives RSA-2048 factoring in about 8 hours with ~20M physical qubits, while Section 4.6.2 says Shor's will break RSA-2048/ECC-256 'in seconds'. Those are not the same claim. The urgency argument leans on these timelines, and the chapter doesn't independently assess them, just cites expert reports. There are also plain factual slips: AES supports 128, 192, and 256-bit keys, not 128/102/256; the QPIR citation is misrepresented—Baumeler and Broadbent actually showed linear communication complexity, not sub-linear; and Gidney–Ekerå's paper is from 2021, not 2023. These matter less for the conceptual narrative but they undermine confidence in the details.\n\nThe self-citations are minor and don't carry the argument, so circularity is not a concern. The central claim—that quantum computers threaten classical IoT cryptography and migration should begin—is standard and broadly correct, even if the urgency depends on timing estimates that are contentious.\n\nBottom line: this paper deserves a serious referee, not a desk reject, but only if the venue accepts surveys. The reviewer's job should be to force a careful cleanup: reconcile the timeline numbers, fix the factual errors, and soften the 'must act now' language to match the uncertainty. After that, it would be a serviceable educational chapter.","headline":"A competent tutorial survey of quantum threats and post-quantum IoT security, with no new results and a few factual inconsistencies that a careful referee should fix.","tokens_in":38617,"tokens_out":1343,"would_cite":false,"duration_ms":14457,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The chapter argues that quantum computers will break today's IoT cryptography and that a layered migration to post-quantum cryptography, quantum key distribution, and quantum random number generators must begin before today's devices age in","keywords":["quantum computing","post-quantum cryptography","IoT security","Shor's algorithm","Grover's algorithm","Quantum Key Distribution","smart city security","hybrid quantum-classical architecture"],"falsifier":"If a fault-tolerant quantum computer with roughly 20 million physical qubits can factor a 2048-bit RSA modulus in about a day of coherent computation, the paper's core threat is confirmed; if classical algorithms factor 2048-bit RSA or solve ECDLP in feasible time, the quantum-threat premise is moot. Short of these, tracking the progression of error-corrected logical qubit counts and gate error rates over the next decade would empirically test the 10-30 year viability window.","tokens_in":37779,"feed_emoji":"🔐","tokens_out":5688,"duration_ms":52794,"temperature":0.7,"pith_summary":"This tutorial chapter's central claim is that the Internet of Things has a quantum deadline. Shor's algorithm can break the RSA, Diffie-Hellman, and ECC public-key systems that most IoT devices rely on, and Grover's algorithm halves the effective key strength of symmetric ciphers like AES. Because IoT devices remain in service for years and attackers can store encrypted traffic for later quantum decryption, the chapter argues that waiting for quantum computers to arrive is too late. It surveys post-quantum cryptographic families (lattice-, hash-, code-, and multivariate-based) and quantum-assisted tools (QKD and QRNG), assessing which fit constrained devices, and concludes that a hybrid quantum-classical architecture is the realistic route to quantum-safe IoT, especially in smart cities, healthcare, and critical infrastructure.","feed_headline":"Quantum computers will break IoT crypto on a deadline","feed_subtitle":"Shor's algorithm ends RSA and ECC; the chapter maps post-quantum replacements for today's constrained devices.","key_machinery":"The argument's load-bearing machinery is a pair of quantum algorithms plus a resource-estimation framework. Shor's algorithm reduces integer factorization and discrete logarithms to polynomial time, directly threatening RSA, Diffie-Hellman, and ECC; Grover's algorithm gives a quadratic speedup for exhaustive key search, halving the effective key length of symmetric ciphers. The resource-estimation framework—logical versus physical qubits, surface-code error correction, circuit depth, and gate fidelity—turns these abstract threats into concrete numbers such as ~20 million physical qubits and ~8 hours for RSA-2048, which sets the migration timeline. On the defensive side, the machinery is the","core_discovery":"The chapter's thesis is that the convergence of quantum computing and IoT changes the security paradigm from 'secure today' to 'secure against a future adversary that can break today's math.' Quantum resource estimates place cryptographically relevant machines 10-30 years away; RSA-2048 would fall to Shor's algorithm in roughly 8 hours with on the order of 20 million physical qubits, while Grover's algorithm reduces AES-128 to about 64 bits of effective security. Since IoT devices are resource-constrained, no single PQC scheme dominates: lattice-based schemes are the most practical for general IoT, hash-based signatures suit firmware and archival, code-based schemes are too heavy for embedde","pith_inferences":["The paper's timeline argument implies that procurement decisions made today should enforce quantum-safe defaults; a device bought now will likely still be deployed when the first cryptographically relevant quantum computers appear, making migration-at-purchase cheaper than retrofitting.","The chapter does not quantify migration costs; a natural extension is a cost-benefit model comparing PQC upgrade expenses against expected losses from harvest-now-decrypt-later attacks for different device lifetimes and data sensitivities.","Because trusted-node QKD concentrates risk at physical relays, the paper's smart-city blueprint points to a research priority: device-independent and satellite QKD, if they scale, would eliminate the main remaining trust assumption.","The resource estimates cited imply a testable schedule: tracking the growth of error-corrected logical qubits and gate error rates on leading quantum processors over the next decade would let operators calibrate the urgency of migration instead of relying on static projections."],"forward_implications":["If the quantum resource estimates are correct, RSA-2048 and ECC-256 should be treated as broken once an error-corrected quantum computer in the 20-million-physical-qubit class exists; all long-lived IoT data should be encrypted under PQC before that date.","Grover's algorithm makes AES-128 effectively 64-bit; IoT systems that cannot afford AES-256 should plan for shorter-lived keys or alternative lightweight primitives.","The 'harvest now, decrypt later' threat implies that data confidentiality is already at risk for data encrypted today with RSA/ECC, so PQC migration is urgent for data with long retention periods, such as medical records and infrastructure logs.","Lattice-based schemes are the most suitable PQC class for constrained IoT devices; hash-based signatures remain viable for specific low-frequency uses like firmware signing; code-based and multivariate schemes face serious size or speed barriers.","Hybrid quantum-classical architectures—QKD for key agreement on high-value links, AES-256/PQC for payload encryption—are the most deployment-ready model for smart cities before full QKD networks mature."],"fun_headline_variants":["Quantum threat to IoT crypto: 10–30 years to act","Post-quantum crypto: IoT's race against Shor's algorithm","IoT crypto faces quantum break: PQC no silver bullet","Quantum deadline for IoT: PQC schemes face resource limits"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The whole migration strategy rests on the assumption that published estimates of quantum threat—RSA-2048 broken in about 8 hours with ~20 million physical qubits and cryptographically relevant machines within 10-30 years—are reliable enough to act on; if those numbers are wrong, the urgency and recommended timing change.","fun_headline_variants_meta":{"raw":{"variants":["Quantum threat to IoT crypto: 10–30 years to act","Post-quantum crypto: IoT's race against Shor's algorithm","IoT crypto faces quantum break: PQC no silver bullet","Quantum deadline for IoT: PQC schemes face resource limits"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000622,"raw_usage":{"total_tokens":2721,"prompt_tokens":749,"completion_tokens":1972,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":493,"completion_tokens_details":{"reasoning_tokens":1900}},"tokens_in":493,"tokens_out":1972,"duration_ms":13955,"temperature":1.0,"reasoning_tokens":1900,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-03T23:52:49.823891+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"If a fault-tolerant quantum computer with roughly 20 million physical qubits can factor a 2048-bit RSA modulus in about a day of coherent computation, the paper's core threat is confirmed; if classical algorithms factor 2048-bit RSA or solve ECDLP in feasible time, the quantum-threat premise is moot. Short of these, tracking the progression of error-corrected logical qubit counts and gate error rates over the next decade would empirically test the 10-30 year viability window.","supporting_citations":[],"review_version":1}