Pith. sign in

REVIEW 4 major objections 3 minor 111 references

Quantum Attacks Targeting Nuclear Power Plants: Threat Analysis, Defense and Mitigation Strategies

T0 review · 4 major / 3 minor · reviewed 2026-08-02 · deepseek-v4-flash

Pith's one-line read This paper claims that quantum-enabled attacks on nuclear power plants have a realistic success probability of 8–78% under current defenses, and that a defense-in-depth migration to post-quantum cryptography can drive residual feasibility b

desk verdict The qualitative HNDL/forensic framework for nuclear OT is useful, but the headline success probabilities are arithmetic products of internally inconsistent expert priors and should not be trusted. read the letter →

arxiv 2602.21524 v2 pith:OOTMVNQR submitted 2026-02-25 cs.CR

classification cs.CR
keywords quantumcomputingthreatspost-quantumcryptographyindustrialcontrolsystemsnuclearpowerplantsecurityharvest-nowdecrypt-laterforensicintegrityprobabilisticattackmodelingcryptographicdiversity
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish that nuclear power plants face a quantum threat unlike other infrastructure: their 60–80 year operating lives stretch past the expected arrival of cryptographically relevant quantum computers, so data and signatures harvested today become decryptable and forgeable within the asset's lifetime. It models two attack campaigns, QUANTUMSCAR and QUANTUMDAWN, as three-phase conditional chains and claims success probabilities of 8–78% under current defenses, 1–8% after reaching the top industrial security level with cryptographic diversity, and below 1% after full migration to post-quantum cryptography. It also argues that forensic integrity is operationally essential, not merely evidentiary, because quantum-forged but cryptographically valid evidence makes sabotage indistinguishable from equipment failure or operator error. A sympathetic reader would care because the paper gives concrete, quantified stakes to a migration that is often framed in abstract terms.

What carries the argument

The load-bearing object is the conditional probability chain ℙ(Success) = ℙ(S1) × ℙ(S2|S1) × ℙ(S3|S1∩S2), where S1 is the harvest-now collection phase, S2 is quantum weaponization (factoring RSA-2048 and forging certificates/signatures via Shor's algorithm), and S3 is execution plus forensic obfuscation. The paper feeds expert-judgment phase probabilities for baseline, SL-4, and full-PQC postures into this product to produce the 8–78%, 1–8%, and below-1% numbers. The chain also yields a sensitivity ordering, ∂P/∂S1 > ∂P/∂S2 > ∂P/∂S3, used to argue that early-phase defenses — disrupting collection and breaking cryptographic monoculture — are the highest-leverage interventions.

What would settle it

Recompute the products using one documented set of phase probabilities. The paper itself gives 5–15% (Table IV), roughly 5–21% (Figure 3), and 35–68% (Section V.B) for the same QUANTUMSCAR baseline, so a reader can determine which numbers survive by checking which prior set is reproducible; if the credible priors are near the low ends, the upper bound of the claimed range collapses.

Watch

Extended reading notes

Core claim

The paper's central claim is that quantum-enabled attacks on nuclear OT are feasible within realistic timelines, quantified through two named scenarios: QUANTUMSCAR (35–68% success for typical deployments, 51–78% for targeted facilities) and QUANTUMDAWN (8–34% and 17–50% respectively). The mechanism is harvest-now, decrypt-later: adversaries collect encrypted traffic and signed firmware today, wait for a CRQC, apply Shor's algorithm to recover RSA/ECC private keys, and then both sabotage safety systems and forge valid-looking forensic evidence. The paper claims that a defense-in-depth migration — hybrid key exchange, post-quantum signatures for code and logs, authenticated time synchronizati

Load-bearing premise

The headline probabilities are products of three expert-judged phase-success rates — collection, quantum key-breaking, execution — that the paper asserts rather than measures; if those priors are wrong, every downstream number scales with them.

Editorial extensions

If this is right

  • If the model is right, RSA/ECC-protected plant communications and firmware collected today are vulnerable to retroactive decryption and forgery within a reactor's operating life, so the risk exists even if no plant is ever 'hacked' in the classical sense before CRQCs arrive.
  • Current defensive postures are quantitatively insufficient: single-attempt success is modeled at 8–78%, and persistent adversaries pushing multiple attempts raise modeled success to 41–99% for targeted facilities.
  • Reaching the top industrial security level with cryptographic diversity, not necessarily full PQC replacement, cuts modeled success to 1–8%, giving operators an intermediate goal with a concrete risk reduction.
  • Full migration to hybrid key exchange with post-quantum signatures for code, logs, and time synchronization is modeled to drive residual feasibility below 1%, which would make quantum-enabled sabotage a minor tail risk rather than a primary one.
  • The six new technique identifiers (T1001–T1006) give defenders a shared vocabulary to detect and discuss quantum cryptanalysis, HNDL collection, forged-evidence manipulation, timing attacks, authenticated persistence, and certificate forgery in industrial control systems.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the conditional-chain structure holds, the same three-phase model should transfer to other long-lived critical infrastructure — power grids, hydro dams, pipelines — where harvest-now risks compound over decades; nuclear plants are only the most extreme case because of their safety functions and evidence requirements.
  • The paper's forensic-paradox argument implies that cryptographic diversity is not just a security control but an evidence-integrity control: regulators may at some point require independent trust anchors across safety and control domains simply so that post-incident investigations can distinguish accident from sabotage.
  • A testable extension is to apply the framework to plants whose field protocols already use Grover-resistant symmetric authentication, such as DNP3-SA; the model would predict that the dominant risk shifts almost entirely to key-distribution infrastructure, which could be validated by comparing attack-success estimates against real-world key-management incident rates.
  • The harvest-now framing suggests a new metric for data-retention policy: any encrypted log or historian archive kept longer than the remaining time to CRQC arrival should be treated as potentially public, which would change how long nuclear operators retain sensitive operational data.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 3 minor

Summary. The paper argues that nuclear power plants face a serious quantum-computing threat because their 60–80 year lifecycles exceed the projected arrival of cryptographically relevant quantum computers. It proposes a forensics-first framework, presents two attack scenarios (QUANTUMSCAR and QUANTUMDAWN), models their success probabilities using a conditional-probability chain, and claims that ISA/IEC 62443 SL-4 plus full PQC migration reduces residual risk from 8–78% to below 1%. It also contributes six proposed MITRE ATT&CK for ICS technique extensions and a set of operational validation criteria.

Significance. If the quantitative results were well-supported, this would be a valuable prioritization tool for nuclear OT cybersecurity. The paper also contains useful, generally sound qualitative material: the Purdue-level vulnerability survey, the PQC performance and side-channel tables, and the defense-in-depth control objectives in Section VII are consistent with existing standards and practical migration guidance. However, the central quantitative contribution — the headline 8–78% success probabilities and the claimed reduction to <1% — rests entirely on author-assigned expert-judgment priors that are never justified with an elicitation protocol, data, or calibration. The same scenario receives three different probability sets in different parts of the paper, and the 'operational validation' is a list of acceptance criteria rather than a demonstration. These are load-bearing problems for the paper's stated novelty.

major comments (4)
  1. [§V.B.1, Table IV, Fig. 3] The QUANTUMSCAR scenario is assigned three mutually inconsistent probability sets. Table IV lists ℙ_baseline = 5–15%; Fig. 3 multiplies [0.4,0.7]×[0.4,0.6]×[0.3,0.5] ≈ 5–21%; and §V.B.1 uses [0.85,0.98]×[0.75,0.92]×[0.55,0.75] ≈ 35–68%. The abstract and conclusion adopt only the highest set. This is not a sensitivity range for a single model; it is a switch between different models with different priors, and the paper gives no criterion for preferring one over the other. Because these numbers are the paper's central quantitative claim, the inconsistency is fatal to that claim.
  2. [§VI.B.1, Table XI, Fig. 5] The same inconsistency appears for QUANTUMDAWN: Table XI states ℙ_baseline = 7–18%; Fig. 5 states 7–18%; while §VI.B.1 gives 8–34% for 'typical' and 17–50% for 'targeted' facilities. The 'Multiple Attempts' transformation further inflates the range to 41–88%. The paper does not explain whether these are alternative scenarios or alternative prior sets for the same scenario. The reader cannot reproduce the advertised 8–78% envelope or the <1% residual from any single, consistently stated input set.
  3. [§V.B.1 and §VI.B.1 (conditional chain)] The model ℙ(Success)=ℙ(S1)·ℙ(S2|S1)·ℙ(S3|S1∩S2) is a straightforward product of the selected phase probabilities. Every factor is an 'expert-judgment prior' or 'realistic probability assessment' with no documented elicitation procedure, no supporting dataset, and no sensitivity analysis over the prior ranges. The paper's quantitative conclusions are therefore arithmetic tautologies: changing the prior changes the output in exactly the way intended. Without a calibration basis, claims such as '8–78% under current defenses' and 'below 1% under PQC' are not supported by evidence.
  4. [§VII, Table XIX] The paper calls Section VII an 'operational validation' of the defense framework, but Table XIX provides only acceptance criteria (e.g., conformance rates, latency budgets, TVLA |t|<4.5). No measured telemetry, test results, or observed residuals are reported. The claim that full PQC migration and SL-4 reduce success from 8–78% to <1% is reasserted using substituted prior ranges (e.g., Fig. 3 SL-4 values), not derived from the validation tests. The criteria may be reasonable design requirements, but they do not validate the quantitative risk-reduction claim.
minor comments (3)
  1. [§III-B] Typo: 'ViRTUal' should be 'Virtual'. Also, the dagger footnote in Table II defines severity codes but the legend in the caption is somewhat cramped; the relationship between attack codes and severity is hard to parse on first reading.
  2. [§V.C / §X (Tables X, XVII)] The six 'MITRE ATT&CK for ICS technique extensions' T1001–T1006 are proposed by the authors, not yet adopted by MITRE. The paper should say 'proposed extensions' rather than implying they are already part of a 'standardized vocabulary', which overstates their status.
  3. [§I.A, contribution 4] The contribution list says Section VII provides 'seven quantitative tests demonstrating systematic risk reduction', but the tests are acceptance criteria, not demonstrations. The wording should be aligned with the actual content of Section VII to avoid confusion.

Circularity Check

2 steps flagged · score 8.0 of 10

Quantitative success probabilities are arithmetic products of author-chosen expert-judgment priors; the claimed defense reduction is assumed, not measured.

  1. self definitional [Abstract; Section V.B.1 (Probabilistic Risk Modeling); Section VI.B.1]
    "The overall success probability follows the conditional chain: ℙ(Success)=ℙ(𝑆1)×ℙ(𝑆2∣𝑆1)×ℙ(𝑆3∣𝑆1∩𝑆2) ... ℙ Current Infrastructure = [0.85,0.98]×[0.75,0.92] × [0.55,0.75] ≈ 35–68% for typical deployments; ℙTargeted Facility =[0.92,0.99]×[0.85,0.96]×[0.65,0.82]≈51–78%"

    The advertised 8–78% headline (and the QUANTUMSCAR/QUANTUMDAWN sub-ranges) is exactly the product of phase-probability intervals that the authors assign as 'expert-judgment priors.' No elicitation protocol, data set, or calibration is given for these priors, so the output range is forced by the input ranges by construction. The same scenario receives three different prior sets (Table IV: 5–15%; Fig. 3: ~5–21%; §V.B.1: 35–68%), confirming the numbers are selected inputs rather than measured or independently derived quantities. The abstract then presents this arithmetic product as a finding: 'yielding success probabilities of 8-78% under current defenses.'

  2. fitted input called prediction [Section VI.B.1; Section VII.F (Synthesis)]
    "ℙ SL-4 Compliant =[0.3,0.5]×[0.3,0.5]×[0.1,0.2]≈1–5%, while ℙ PQC-Hybrid =[0.2,0.4]×[0.1,0.2]×[0.05,0.1]<1% ... Translating attack methodologies from Sections V and VI into measurable validation criteria systematically reduces quantum attack success from 8–78% baseline to below 1%."

    The claimed residual risk reduction to 1–8% (SL-4) and <1% (PQC) is obtained by substituting smaller author-chosen phase-probability intervals into the same conditional-chain formula. The 'operational validation' tests in Table XIX measure handshake conformity, MTU, latency, code-signing, hashing, side-channel attestation, and negative testing; none of them measures attack success probability. The reduction is therefore a restatement of the substituted priors, not an empirical validation, so the paper's defense claim reduces to its own assumptions.

full rationale

The qualitative parts of the paper—Shor's algorithm breaking RSA/ECC, HNDL risk, NIST PQC standards, ISA/IEC 62443 controls, MITRE ATT&CK extensions—are not circular; they rest on external cryptographic facts and standards. Self-citations ([24], [89]) are present but not load-bearing for the central quantitative claims. The circularity is in the risk numbers: §V.B.1 and §VI.B.1 define success as ℙ(S1)·ℙ(S2|S1)·ℙ(S3|S1∩S2), and every advertised baseline range (8–34%, 35–68%, 51–78%) is the product of author-assigned 'expert-judgment' priors with no elicitation protocol, base-rate data, or calibration. The defense reductions (1–8%, <1%) are produced by plugging in smaller assumed priors, while the 'operational validation' is a conformance checklist, not a measurement of attack success. Thus the headline quantitative contribution is equivalent to its inputs by construction; the paper is transparent about using expert judgment, but that does not make the prediction independent. Score 8: the central quantitative result is forced by definitional arithmetic, even though the qualitative migration framework has independent merit.

Assumptions & free parameters 9 free parameters · 5 assumptions · 1 invented entities

The paper's quantitative claims derive entirely from author-chosen expert priors and scenario assumptions, with no empirical data or independent benchmarks.

free parameters (9)
  • Phase 1 success probability baseline (SCAR) = [0.4,0.7] (Fig. 3); [0.85,0.98] (Sec. V.B)
    Chosen by authors as expert-judgment prior; directly determines overall success probability.
  • Phase 2 success probability baseline (SCAR) = [0.4,0.6] (Fig. 3); [0.75,0.92] (Sec. V.B)
    Expert-judgment prior for quantum weaponization success.
  • Phase 3 success probability baseline (SCAR) = [0.3,0.5] (Fig. 3); [0.55,0.75] (Sec. V.B)
    Expert-judgment prior for execution and forensic obfuscation.
  • Phase 1-3 probabilities SL-4 (SCAR) = [0.2,0.4], [0.4,0.6], [0.15,0.25] (Sec. V.B)
    Chosen to represent SL-4 mitigation; used to claim residual risk 2-8%.
  • Phase 1-3 probabilities baseline (DAWN) = [0.5,0.8], [0.5,0.7], [0.3,0.6]
    Expert-judgment priors for DAWN campaign.
  • Phase 1-3 probabilities SL-4/PQC (DAWN) = SL-4: [0.3,0.5],[0.3,0.5],[0.1,0.2]; PQC: [0.2,0.4],[0.1,0.2],[0.05,0.1]
    Chosen to produce claimed residual 1-5% and <1%.
  • Risk-reduction multipliers = 8-12× and 6-10×
    Claims that Phase 1 defenses give 8-12× (SCAR) and 6-10× (DAWN) more risk reduction than downstream controls; no derivation.
  • CRQC threshold = 4,098 logical qubits within 10-15 years
    Assumed timeline from IBM roadmap and Gidney/Ekerå; central to HNDL threat window.
  • PKI monoculture share = >85%
    Statistic 'over 85% of facilities share PKI' is asserted with citations [9],[10] that do not appear to provide it.
assumptions (5)
  • domain assumption Shor's algorithm will break RSA-2048 and ECC on a CRQC
    Standard, but requires the assumed CRQC to exist within the asset lifecycle; Section III.A.
  • standard math Grover's algorithm halves symmetric key strength
    Accepted quantum algorithm result; Section III.A.
  • domain assumption HNDL campaigns are already actively harvesting OT traffic
    Paper cites documentation 'since 2015-2016' [16]; used as an anchor for priors.
  • domain assumption Conditional attack phases are independent and multiply
    The conditional-chain formula ℙ(Success)=ℙ(S1)ℙ(S2|S1)ℙ(S3|S1∩S2) assumes no unmodeled dependencies; Section V.B.
  • ad hoc to paper The physical impact timelines are representative
    Scenario-specific narrative values in Tables V and XII (e.g., core temp exceeds 302°C at T+2.3s) presented without thermal-hydraulic modeling.
invented entities (1)
  • MITRE ATT&CK for ICS technique extensions T1001-T1006
    purpose: New taxonomy entries for quantum cryptanalysis, HNDL, quantum-forged evidence, temporal sync attacks, quantum-authenticated persistence, certificate forgery
    Proposed by the authors; not adopted by MITRE and no empirical validation.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Quantum Attacks Targeting Nuclear Power Plants: Threat Analysis, Defense and Mitigation Strategies." pith.science (2026). https://pith.science/paper/OOTMVNQR

@misc{pith2026260221524,
  author       = {Pith},
  title        = {Pith review of: Quantum Attacks Targeting Nuclear Power Plants: Threat Analysis, Defense and Mitigation Strategies},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/OOTMVNQR}},
  note         = {Machine review of arXiv:2602.21524}
}
read the original abstract

Nuclear power plants face a structural lifecycle asymmetry: their 60-80 year operational lifecycles exceed the anticipated arrival of Cryptographically Relevant Quantum Computers (CRQCs), so cryptographic material harvested today becomes decryptable within the service life of the systems it protects. This paper introduces a forensics-first framework for quantum resilience that treats forensic integrity as operationally essential rather than merely evidentiary, analyzing the quantum threat landscape across the Purdue architecture (L0-L5) to show how Harvest-Now, Decrypt-Later (HNDL) campaigns enabled by Shor's algorithm can retroactively compromise cryptographic foundations and undermine forensic evidence. Through two case studies, Quantum Scar and Quantum Dawn, we model attack feasibility via a conditional-chain formulation over structured expert-judgment priors anchored to documented HNDL activity and published CRQC roadmaps, yielding success probabilities of 8-78% under current defenses, where the upper bound corresponds to high-value facilities exhibiting cryptographic monoculture. We propose a defense-in-depth migration to Post-Quantum Cryptography (PQC) integrating hybrid key exchange, code and log integrity with anti-rollback, authenticated time synchronization, and side-channel-resistant implementations aligned with ISA/IEC 62443 and NIST standards, and specify seven design-level conformance criteria for validating it; modeled residual feasibility falls to 1-8% at Security Level 4 and below 1% under full PQC migration. We further contribute six MITRE ATT&CK for ICS technique extensions (T1001-T1006) as a standardized vocabulary for quantum-enabled infrastructure attacks. Quantum threats thus extend beyond cybersecurity to system safety, operational reliability, and post-incident evidence admissibility across multi-decade nuclear asset lifecycles.

Figures

Figures reproduced from arXiv: 2602.21524 by the authors.

Figure 1
Figure 1. Purdue Model (ISA-95) architecture showing quantum [PITH_FULL_IMAGE:figures/full_fig_p005_1.png] view at source ↗
Figure 2
Figure 2. QUANTUM SCAR multi-phase attack flow 𝑁 𝑜𝑤 𝑇 𝑇+𝛼 𝑇+𝛼+𝜖 HNDL Collection (𝜏𝑐𝑒𝑟 𝑡 < 𝜏𝑟𝑜𝑡𝑎𝑡𝑖𝑜𝑛) Phase 1: HNDL Collection (𝑁 𝑜𝑤–𝑇 ) Duration: 18-20 month operational window Constraints: Cert rotation (mo 22), credential expiry (mo 20) Success: ℙ(𝑆1) ∈ [0.4, 0.7] (baseline), [0.2, 0.4] (SL-4) Objective: Harvest 4.2TB cryptographic material Phase 2: Weaponization (𝑇+𝛼) Timeline: Post-CRQC availability (𝛼 ≈ 1-3 years) Requir… view at source ↗
Figure 3
Figure 3. QUANTUM SCAR attack timeline with conditional phase dependencies. Variable 𝑇 represents CRQC onset year from expert assessments ( [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: QUANTUM DAWN multi-phase attack flow [PITH_FULL_IMAGE:figures/full_fig_p009_4.png]
Figure 5
Figure 5. Figure 5: QUANTUM DAWN attack timeline with conditional phase dependencies. Variable 𝑇0 represents initial compromise; 𝛿 denotes HNDL collection period; 𝑇𝐶𝑅𝑄𝐶 represents quantum capability onset; 𝜖 represents execution preparation window; 𝜏𝑐𝑒𝑟 𝑡 is certificate lifecycle; 𝜏𝑟𝑜𝑡𝑎𝑡𝑖…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

111 extracted references · 1 linked inside Pith

  1. [1]

    Subsequent license renewal,

    U.S. Nuclear Regulatory Commission, “Subsequent license renewal,” https://www.nrc.gov/reactors/operating/licensing/renewal/subsequent-l icense-renewal.html, U.S. NRC, Tech. Rep., 2023

  2. [2]

    Long-term operations: Subsequent license renewal technical basis documents,

    Electric Power Research Institute, “Long-term operations: Subsequent license renewal technical basis documents,” Palo Alto, CA, Technical Report 3002010401, 3002011822, 3002013084, 2018, comprehensive technical basis for nuclear plant operations beyond 60 years to 80 years

  3. [3]

    Nuclear power plant long-term operations (LTO) program,

    Electric Power Research Institute, “Nuclear power plant long-term operations (LTO) program,” https://lto.epri.com/LTO, 2024, defines operations from 60 to 80 years as the Subsequent Period of Extended Operation (SPEO); plants initially licensed for 40 years can extend licenses in 20-year increments

  4. [4]

    High-threshold and low-overhead fault-tolerant quantum memory,

    O. Higgott, M. Wilson, J. Roffe, N. P. Breuckmann, and E. T. Campbell, “High-threshold and low-overhead fault-tolerant quantum memory,” Nature, vol. 629, no. 8012, pp. 546–552, 2024

  5. [5]

    IBM quantum development roadmap,

    IBM Quantum Team, “IBM quantum development roadmap,” IBM Research, 2025, accessed: 2024. [Online]. Available: https: //www.ibm.com/quantum/roadmap

  6. [6]

    Algorithms for quantum computation: discrete logarithms and factoring,

    P. W. Shor, “Algorithms for quantum computation: discrete logarithms and factoring,” inProceedings 35th Annual Symposium on Foundations of Computer Science. IEEE, 1994, pp. 124–134

  7. [7]

    A fast quantum mechanical algorithm for database search,

    L. K. Grover, “A fast quantum mechanical algorithm for database search,” inProceedings of the twenty-eighth annual ACM symposium on Theory of Computing. ACM, 1996, pp. 212–219

  8. [8]

    Hidden shift quantum crypt- analysis and implications,

    X. Bonnetain and M. Naya-Plasencia, “Hidden shift quantum crypt- analysis and implications,” inAdvances in Cryptology – ASIACRYPT 2018, ser. Lecture Notes in Computer Science, vol. 11272. Springer, 2018, pp. 560–592

Show all 111 references
  1. [9]

    From standard to practice: Towards ISA/IEC 62443-conform public key infrastructures,

    M. P. Heinl, M. Pursche, N. Puch, S. N. Peters, and A. Giehl, “From standard to practice: Towards ISA/IEC 62443-conform public key infrastructures,” inComputer Safety, Reliability, and Security, ser. Lecture Notes in Computer Science, vol. 14181. Springer, 2023, pp. 207–221

  2. [10]

    Towards post-quantum security for cyber-physical systems: integrating PQC into industrial M2M communication,

    S. Paul, R. Seeger, and D. Rupprecht, “Towards post-quantum security for cyber-physical systems: integrating PQC into industrial M2M communication,” inComputer Security – ESORICS 2020, ser. Lecture Notes in Computer Science, vol. 12309. Springer, 2020, pp. 295–316

  3. [11]

    Washington, DC: The National Academies Press, 2019

    National Academies of Sciences, Engineering, and Medicine,Quantum Computing: Progress and Prospects. Washington, DC: The National Academies Press, 2019

  4. [12]

    Scaphy: Detecting modern ICS attacks by correlating behaviors in SCADA and PHYsical,

    M. Ike, K. Phan, K. Sadoski, R. Valme, and W. Lee, “Scaphy: Detecting modern ICS attacks by correlating behaviors in SCADA and PHYsical,” in2023 IEEE Symposium on Security and Privacy (SP), 2023, pp. 20– 37

  5. [13]

    Shedding light on inconsistencies in grid cybersecurity: Disconnects and recommendations,

    B. Singer, A. Pandey, S. Li, L. Bauer, C. Miller, L. Pileggi, and V . Sekar, “Shedding light on inconsistencies in grid cybersecurity: Disconnects and recommendations,” in2023 IEEE Symposium on Security and Privacy (SP), 2023, pp. 38–55

  6. [14]

    Guide to operational technology (OT) security,

    National Institute of Standards and Technology, “Guide to operational technology (OT) security,” NIST, Tech. Rep. NIST SP 800-82 Rev. 3,

  7. [15]

    Transition to post-quantum cryptography standards,

    D. Moody, R. Perlner, A. Regenscheid, A. Robinson, and D. Cooper, “Transition to post-quantum cryptography standards,” NIST, NIST Internal Report NIST IR 8547 ipd, 2024, initial Public Draft addressing quantum-safe handling of logs and evidence

  8. [16]

    ”steal now, decrypt later

    M. Barenkamp, “”steal now, decrypt later” post-quantum-kryptografie & ki,”Informatik Spektrum, vol. 45, no. 6, pp. 349–355, 2022

  9. [17]

    Digital signatures with outsourced hashing,

    B. Poettering and S. Rastikian, “Digital signatures with outsourced hashing,” inAdvances in Cryptology – ASIACRYPT 2024. Springer, 2025, pp. 138–167

  10. [18]

    The SPHINCS+ signature framework,

    D. J. Bernstein, C. Dobraunig, M. Eichlseder, S. Fluhrer, S.-L. Gazdag, A. Petzoldt, J. Rijneveld, J. Schanck, P. Schwabe, W. Whyteet al., “The SPHINCS+ signature framework,” inProceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2019, pp...

  11. [19]

    Time–space complexity of quantum search algorithms in symmetric cryptanalysis: applying to AES and SHA-2,

    D. H. Panjin Kim and K. C. Jeong, “Time–space complexity of quantum search algorithms in symmetric cryptanalysis: applying to AES and SHA-2,”Quantum Information Processing, vol. 17, no. 12, p. 339, 2018

  12. [20]

    Cybersecurity in an era with quantum computers: will we be ready?

    M. Mosca, “Cybersecurity in an era with quantum computers: will we be ready?”IEEE Security & Privacy, vol. 16, no. 5, pp. 38–41, 2018

  13. [21]

    Cybersecurity in critical infrastructures: A post-quantum cryptography perspective,

    J. Oliva del Moral, A. deMarti iOlius, G. Vidal, P. M. Crespo, and J. Etxezarreta Martinez, “Cybersecurity in critical infrastructures: A post-quantum cryptography perspective,”IEEE Internet of Things Journal, vol. 11, no. 18, pp. 30 217–30 244, 2024. 15

  14. [22]

    Evaluating cryptographic vulnerabilities created by quantum computing in industrial control systems,

    M. J. Vermeer, C. Heitzenrater, E. Parker, A. Moon, D. Lumpkin, and J. Awan, “Evaluating cryptographic vulnerabilities created by quantum computing in industrial control systems,”Journal of Critical Infrastructure Policy, vol. 5, no. 2, pp. 88–110, 2024

  15. [23]

    Transitioning to a quantum-resistant public key infrastructure,

    G. Banegas, D. J. Bernstein, C. Chuengsatiansup, T. Lange, and C. van Vredendaal, “Transitioning to a quantum-resistant public key infrastructure,” pp. 384–405, 2021

  16. [24]

    Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition,

    Y . Baseri, V . Chouhan, A. Ghorbani, and A. Chow, “Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition,”Computers & Security, vol. 150, p. 104272, 2025. [Online]. Available: https://www.sciencedirect.com/ science/art...

  17. [25]

    Post-quantum tls without handshake signatures,

    P. Schwabe, D. Stebila, and T. Wiggers, “Post-quantum tls without handshake signatures,” inProceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’20. New York, NY , USA: ACM, 2020, p. 1461–1480

  18. [26]

    Post-quantum WireGuard,

    A. H ¨ulsing, K.-C. Ning, P. Schwabe, F. Weber, and P. R. Zimmermann, “Post-quantum WireGuard,” in42nd IEEE Symposium on Security and Privacy (S&P). IEEE, 2021, pp. 304–321, practical integration of quantum-resistant algorithms into network protocols

  19. [27]

    NIST releases first 3 finalized post-quantum encryption standards,

    National Institute of Standards and Technology, “NIST releases first 3 finalized post-quantum encryption standards,” August 2024. [Online]. Available: https://www.nist.gov/news-events/news/2024/08/nist-relea ses-first-3-finalized-post-quantum-encryption-standards

  20. [28]

    Transition to post-quantum cryptography standards,

    D. Moody, R. Perlner, A. Regenscheid, A. Robinson, and D. Cooper, “Transition to post-quantum cryptography standards,” https://doi.or g/10.6028/NIST.IR.8547.ipd, National Institute of Standards and Technology, Interagency Report NIST IR 8547 IPD, November 2024, accessed: 2024-11-19

  21. [29]

    Side-channel and fault-injection attacks over lattice-based post-quantum schemes (kyber, dilithium): Survey and new results,

    P. Ravi, A. Chattopadhyay, J. P. D’Anvers, and A. Baksi, “Side-channel and fault-injection attacks over lattice-based post-quantum schemes (kyber, dilithium): Survey and new results,”ACM Transactions on Embedded Computing Systems, vol. 23, no. 2, pp. 1–54, 2024

  22. [30]

    The insecurity of masked comparisons: Scas on ml-kem’s fo-transform,

    J. Hermelink, K.-C. Ning, R. Petri, and E. Strieder, “The insecurity of masked comparisons: Scas on ml-kem’s fo-transform,” p. 2430–2444, 2024

  23. [31]

    The hidden parallelepiped is back again: Power analysis attacks on Falcon,

    M. Guerreau, A. Martinelli, T. Ricosset, and M. Rossi, “The hidden parallelepiped is back again: Power analysis attacks on Falcon,”IACR Transactions on Cryptographic Hardware and Embedded Systems, pp. 141–164, 2022

  24. [32]

    Don’t reject this: Key-recovery timing attacks due to rejection-sampling in HQC and BIKE,

    Q. Guo, C. Hlauschek, T. Johansson, N. Lahr, A. Nilsson, and R. L. Schr ¨oder, “Don’t reject this: Key-recovery timing attacks due to rejection-sampling in HQC and BIKE,”IACR Transactions on Cryptographic Hardware and Embedded Systems, pp. 223–263, 2022

  25. [33]

    Hybrid OPC UA: Enabling post-quantum security for the industrial internet of things,

    S. Paul and R. Seeger, “Hybrid OPC UA: Enabling post-quantum security for the industrial internet of things,” in2020 IEEE 6th World Forum on Internet of Things (WF-IoT). IEEE, 2020, pp. 1–6

  26. [34]

    Benchmarking post-quantum cryptography in TLS,

    C. Paquin, D. Stebila, and G. Tamvada, “Benchmarking post-quantum cryptography in TLS,” inInternational Conference on Post-Quantum Cryptography (PQCrypto). Springer, 2020, pp. 72–91

  27. [35]

    Digital substations and IEC 61850: A primer,

    J. C. Lozano, K. Koneru, N. Ortiz, and A. A. Cardenas, “Digital substations and IEC 61850: A primer,” vol. 61, no. 6, 2023, pp. 28–34

  28. [36]

    Quantum computing in industrial internet of things (iiot) forensics: Framework, implications, opportunities, and future directions,

    V . R. Kebande, “Quantum computing in industrial internet of things (iiot) forensics: Framework, implications, opportunities, and future directions,”WIREs Forensic Science, July 2025

  29. [37]

    Generalizable and compre- hensible industrial intrusion detection,

    K. Wolsing, E. Zoller, and M. Henze, “Generalizable and compre- hensible industrial intrusion detection,” in33rd USENIX Security Symposium, 2024, pp. 4567–4584

  30. [38]

    Guide to Operational Technology (OT) Security,

    National Institute of Standards and Technology, “Guide to Operational Technology (OT) Security,” https://csrc.nist.gov/pubs/sp/800/82/r3/ipd, U.S. Department of Commerce, Tech. Rep. NIST SP 800-82 Rev. 3, 2024

  31. [39]

    Framework for Im- proving Critical Infrastructure Cybersecurity (CSF 2.0),

    National Institute of Standards and Technology, “Framework for Im- proving Critical Infrastructure Cybersecurity (CSF 2.0),” https://doi.or g/10.6028/NIST.CSWP.29, U.S. Department of Commerce, Tech. Rep. NIST Cybersecurity Framework 2.0, February 2024. [40]ISA/IEC 62443 Series...

  32. [41]

    Post-quantum con- siderations for operational technology,

    Cybersecurity and Infrastructure Security Agency, “Post-quantum con- siderations for operational technology,” U.S. Department of Homeland Security, Tech. Rep., 2024

  33. [42]

    Elliptic Curve Cryptography Subject Public Key Information,

    S. Turner, D. Brown, K. Yiu, R. Housley, and T. Polk, “Elliptic Curve Cryptography Subject Public Key Information,” https://www.rfc-edito r.org/info/rfc5480, March 2009

  34. [43]

    Elliptic Curves for Security,

    A. Langley, M. Hamburg, and S. Turner, “Elliptic Curves for Security,” https://www.rfc-editor.org/info/rfc7748, January 2016

  35. [44]

    Negotiated finite field diffie-hellman ephemeral parame- ters for transport layer security (TLS),

    D. Gillmor, “Negotiated finite field diffie-hellman ephemeral parame- ters for transport layer security (TLS),” Tech. Rep., 2016

  36. [45]

    PKCS# 1: RSA cryptography specifications version 2.2,

    K. Moriarty, B. Kaliski, J. Jonsson, and A. Rusch, “PKCS# 1: RSA cryptography specifications version 2.2,” Tech. Rep., 2016

  37. [46]

    Use of the Advanced Encryption Standard (AES) En- cryption Algorithm in Cryptographic Message Syntax (CMS),

    J. Schaad, “Use of the Advanced Encryption Standard (AES) En- cryption Algorithm in Cryptographic Message Syntax (CMS),” https: //www.rfc-editor.org/info/rfc3565, July 2003, standards Track

  38. [47]

    US secure hash algorithms (SHA and SHA-based HMAC and HKDF),

    D. Eastlake 3rd and T. Hansen, “US secure hash algorithms (SHA and SHA-based HMAC and HKDF),” Tech. Rep., 2011

  39. [48]

    Quantum algorithm for the collision problem,

    G. Brassard, P. Hoyer, and A. Tapp, “Quantum algorithm for the collision problem,”arXiv preprint quant-ph/9705002, 1997

  40. [49]

    National Institute of Standards and Technology,FIPS 203: Module- Lattice-Based Key-Encapsulation Mechanism Standard, NIST Std., 2024

  41. [50]

    Practical CCA2-secure and masked ring-LWE implementation,

    T. Oder, T. Schneider, T. P ¨oppelmann, and T. G ¨uneysu, “Practical CCA2-secure and masked ring-LWE implementation,”IACR Transac- tions on Cryptographic Hardware and Embedded Systems, pp. 142– 174, 2018

  42. [51]

    More practical single-trace attacks on the number theoretic transform,

    P. Pessl and R. Primas, “More practical single-trace attacks on the number theoretic transform,” inInternational Conference on Cryptol- ogy and Information Security in Latin America. Springer, 2019, pp. 130–149

  43. [52]

    Chosen ciphertext k- trace attacks on masked CCA2 secure kyber,

    M. Hamburg, J. Hermelink, R. Primas, S. Samardjiska, T. Schamberger, S. Streit, E. Strieder, and C. van Vredendaal, “Chosen ciphertext k- trace attacks on masked CCA2 secure kyber,”IACR Transactions on Cryptographic Hardware and Embedded Systems, pp. 88–113, 2021

  44. [53]

    Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: the case study of Kyber,

    Z. Xu, O. Pemberton, S. S. Roy, D. Oswald, W. Yao, and Z. Zheng, “Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: the case study of Kyber,”IEEE Transactions on Computers, vol. 71, no. 9, pp. 2163–2176, 2021

  45. [54]

    Breaking a fifth- order masked implementation of CRYSTALS-Kyber by copy-paste,

    E. Dubrova, K. Ngo, J. G ¨artner, and R. Wang, “Breaking a fifth- order masked implementation of CRYSTALS-Kyber by copy-paste,” in Proceedings of the 10th ACM Asia Public-Key Cryptography Workshop, ser. APKC ’23. ACM, 2023, p. 10–20

  46. [55]

    On exploiting message leakage in (few) NIST PQC candidates for practical message recovery attacks,

    P. Ravi, S. Bhasin, S. S. Roy, and A. Chattopadhyay, “On exploiting message leakage in (few) NIST PQC candidates for practical message recovery attacks,”IEEE Transactions on Information Forensics and Security, vol. 17, pp. 684–699, 2021

  47. [56]

    Drop by drop you break the rock-exploiting generic vulnerabilities in lattice- based PKE/KEMs using EM-based physical attacks,

    P. Ravi, S. Bhasin, S. S. Roy, and A. Chattopadhyay, “Drop by drop you break the rock-exploiting generic vulnerabilities in lattice- based PKE/KEMs using EM-based physical attacks,”Cryptology ePrint Archive, 2020

  48. [57]

    Number “not used

    P. Ravi, D. B. Roy, S. Bhasin, A. Chattopadhyay, and D. Mukhopad- hyay, “Number “not used” once-practical fault attack on pqm4 im- plementations of NIST candidates,” inInternational Workshop on Constructive Side-Channel Analysis and Secure Design. Springer, 2019, pp. 232–250

  49. [58]

    Generic side- channel attacks on CCA-secure lattice-based PKE and KEMs

    P. Ravi, S. S. Roy, A. Chattopadhyay, and S. Bhasin, “Generic side- channel attacks on CCA-secure lattice-based PKE and KEMs.”IACR Transactions on Cryptographic Hardware and Embedded Systems, vol. 2020, no. 3, pp. 307–335, 2020

  50. [59]

    Cold boot attacks on ring and module LWE keys under the NTT,

    M. R. Albrecht, A. Deo, and K. G. Paterson, “Cold boot attacks on ring and module LWE keys under the NTT,”Cryptology ePrint Archive, 2018

  51. [60]

    National Institute of Standards and Technology,FIPS 204: Module- Lattice-Based Digital Signature Standard, NIST Std., 2024

  52. [61]

    Differential fault attacks on determin- istic lattice signatures,

    L. G. Bruinderink and P. Pessl, “Differential fault attacks on determin- istic lattice signatures,”IACR Transactions on Cryptographic Hardware and Embedded Systems, pp. 21–43, 2018

  53. [62]

    Masking Dilithium,

    V . Migliore, B. G ´erard, M. Tibouchi, and P.-A. Fouque, “Masking Dilithium,” inInternational Conference on Applied Cryptography and Network Security. Springer, 2019, pp. 344–362

  54. [63]

    Profiling side-channel attacks on Dilithium: A small bit-fiddling leak breaks it all,

    V . Q. Ulitzsch, S. Marzougui, M. Tibouchi, and J.-P. Seifert, “Profiling side-channel attacks on Dilithium: A small bit-fiddling leak breaks it all,” inInternational Conference on Selected Areas in Cryptography. Springer, 2022, pp. 3–32

  55. [64]

    Analysis of EM fault injection on bit-sliced number theoretic transform software in Dilithium,

    R. Singh, S. Islam, B. Sunar, and P. Schaumont, “Analysis of EM fault injection on bit-sliced number theoretic transform software in Dilithium,”ACM Transactions on Embedded Computing Systems, vol. 23, no. 2, pp. 1–27, March 2024

  56. [65]

    A practical template attack on CRYSTALS-Dilithium,

    A. Berzati, A. C. Viera, M. Chartouni, S. Madec, D. Vergnaud, and D. Vigilant, “A practical template attack on CRYSTALS-Dilithium,” 2023. 16

  57. [66]

    Exploiting determinism in lattice-based signatures: practical fault attacks on pqm4 implementations of NIST candidates,

    P. Ravi, M. P. Jhanwar, J. Howe, A. Chattopadhyay, and S. Bhasin, “Exploiting determinism in lattice-based signatures: practical fault attacks on pqm4 implementations of NIST candidates,” inProceedings of the 2019 ACM Asia Conference on Computer and Communications Security, 20...

  58. [67]

    National Institute of Standards and Technology,FIPS 205: Stateless Hash-Based Digital Signature Standard, NIST Std., 2024

  59. [68]

    Grafting trees: a fault attack against the SPHINCS framework,

    L. Castelnovi, A. Martinelli, and T. Prest, “Grafting trees: a fault attack against the SPHINCS framework,” inInternational Conference on Post- Quantum Cryptography. Springer, 2018, pp. 165–184

  60. [69]

    Practical fault injection attacks on SPHINCS,

    A. Gen ˆet, M. J. Kannwischer, H. Pelletier, and A. McLauchlan, “Practical fault injection attacks on SPHINCS,”Cryptology ePrint Archive, 2018

  61. [70]

    Differential power analysis of XMSS and SPHINCS,

    M. J. Kannwischer, A. Gen ˆet, D. Butin, J. Kr ¨amer, and J. Buchmann, “Differential power analysis of XMSS and SPHINCS,” inInternational Workshop on Constructive Side-Channel Analysis and Secure Design. Springer, 2018, pp. 168–188

  62. [71]

    NIST first call for multi-party threshold schemes,

    N. I. of Standards and Technology, “NIST first call for multi-party threshold schemes,” U.S. Department of Commerce, NIST Interagency or Internal Report (IR) 8214C, March 2025, initial public draft (ipd) of FIPS 206 expected later in 2025, based on the Falcon submission. [Onli...

  63. [72]

    BEARZ attack FALCON: Implementation attacks with countermeasures on the FALCON signature scheme,

    S. McCarthy, J. Howe, N. Smyth, S. Brannigan, and M. O’Neill, “BEARZ attack FALCON: Implementation attacks with countermeasures on the FALCON signature scheme,” 2019. [Online]. Available: https://eprint.iacr.org/2019/478

  64. [73]

    Falcon down: Breaking Falcon post- quantum signature scheme through side-channel attacks,

    E. Karabulut and A. Aysu, “Falcon down: Breaking Falcon post- quantum signature scheme through side-channel attacks,” in2021 58th ACM/IEEE Design Automation Conference (DAC). IEEE, 2021, pp. 691–696

  65. [74]

    Status report on the fourth round of the NIST post-quantum cryptography standardization process,

    G. Alagic,et al., “Status report on the fourth round of the NIST post-quantum cryptography standardization process,” https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf, National Institute of Standards and Technology, Tech. Rep. NIST IR 8545, March 2025

  66. [75]

    Fault- injection attacks against NIST’s post-quantum cryptography round 3 KEM candidates,

    K. Xagawa, A. Ito, R. Ueno, J. Takahashi, and N. Homma, “Fault- injection attacks against NIST’s post-quantum cryptography round 3 KEM candidates,” inInternational Conference on the Theory and Application of Cryptology and Information Security. Springer, 2021, pp. 33–61

  67. [76]

    A practicable timing attack against HQC and its countermeasure,

    G. Wafo-Tapa, S. Bettaieb, L. Bidoux, P. Gaborit, and E. Marcatel, “A practicable timing attack against HQC and its countermeasure,” Advances in Mathematics of Communications, 2020

  68. [77]

    A new key recovery side-channel attack on HQC with chosen ciphertext,

    G. Goy, A. Loiseau, and P. Gaborit, “A new key recovery side-channel attack on HQC with chosen ciphertext,” inInternational Conference on Post-Quantum Cryptography. Springer, 2022, pp. 353–371

  69. [78]

    Message-recovery laser fault injection attack on code-based cryptosys- tems

    P.-L. Cayrel, B. Colombier, V .-F. Dragoi, A. Menu, and L. Bossuet, “Message-recovery laser fault injection attack on code-based cryptosys- tems.”IACR Cryptol. ePrint Arch., vol. 2020, p. 900, 2020

  70. [79]

    A key-recovery timing attack on post-quantum primitives using the fujisaki-okamoto transformation and its application on FrodoKEM,

    Q. Guo, T. Johansson, and A. Nilsson, “A key-recovery timing attack on post-quantum primitives using the fujisaki-okamoto transformation and its application on FrodoKEM,” inAnnual International Cryptology Conference. Springer, 2020, pp. 359–386

  71. [80]

    A power side-channel attack on the CCA2-secure HQC KEM,

    T. Schamberger, J. Renner, G. Sigl, and A. Wachter-Zeh, “A power side-channel attack on the CCA2-secure HQC KEM,” inInternational Conference on Smart Card Research and Advanced Applications. Springer, 2020, pp. 119–134

  72. [81]

    Et tu, brute? side-channel assisted chosen ciphertext attacks using valid ciphertexts on HQC KEM,

    T. B. Paiva, P. Ravi, D. Jap, S. Bhasin, S. Das, and A. Chattopadhyay, “Et tu, brute? side-channel assisted chosen ciphertext attacks using valid ciphertexts on HQC KEM,” inInternational Conference on Post- Quantum Cryptography. Springer, 2025, pp. 294–321

  73. [82]

    Falcon: Fast-fourier lattice-based compact signatures over ntru,

    P.-A. Fouque, J. Hoffstein, P. Kirchner, V . Lyubashevsky, T. Pornin, T. Prest, T. Ricosset, G. Seiler, W. Whyte, and Z. Zhang, “Falcon: Fast-fourier lattice-based compact signatures over ntru,”Submission to the NIST’s post-quantum cryptography standardization process, vol. 36...

  74. [83]

    Nuclear security recommen- dations on physical protection of nuclear material and nuclear facilities (INFCIRC/225/Revision 5),

    International Atomic Energy Agency, “Nuclear security recommen- dations on physical protection of nuclear material and nuclear facilities (INFCIRC/225/Revision 5),” International Atomic Energy Agency, Vienna, Austria, Tech. Rep., 2011. [Online]. Available: https://www-pub.iaea...

  75. [84]

    Convention on the physical protection of nuclear material and nuclear facilities (CPPNM) and its 2005 Amendment,

    International Atomic Energy Agency, “Convention on the physical protection of nuclear material and nuclear facilities (CPPNM) and its 2005 Amendment,” 1979, adopted 26 October 1979; entered into force 8 February 1987; Amendment adopted 8 July 2005; Amendment entered into force...

  76. [85]

    Quantum-safe cryptography and security: An introduction, benefits, enablers and challenges,

    J. C. Aguilaret al., “Quantum-safe cryptography and security: An introduction, benefits, enablers and challenges,”ETSI White Paper, no. 36, 2021

  77. [86]

    Toward crypto agility: Automated analysis of quantum- vulnerable TLS via packet inspection,

    S. Cho, Y . Hyoung, H. Kim, M. Sim, A. Chattopadhyay, H. Seo, and H. Kim, “Toward crypto agility: Automated analysis of quantum- vulnerable TLS via packet inspection,” Cryptology ePrint Archive, Paper 2025/1549, 2025

  78. [87]

    Time synchronization techniques in the modern smart grid: A comprehensive survey,

    Y . Liu, B. Sun, Y . Wu, Y . Zhang, J. Yang, W. Wang, N. L. Thotakura, Q. Liu, and Y . Liu, “Time synchronization techniques in the modern smart grid: A comprehensive survey,”Energies, vol. 18, no. 5, p. 1163, 2025

  79. [88]

    How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,

    C. Gidney and M. Eker ˚a, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,”Quantum, vol. 5, p. 433, 2021

  80. [89]

    Navigating quantum security risks in networked environments: A comprehensive study of quantum- safe network protocols,

    Y . Baseri, V . Chouhan, and A. Hafid, “Navigating quantum security risks in networked environments: A comprehensive study of quantum- safe network protocols,”Computers & Security, vol. 142, p. 103883, 2024

  81. [90]

    Implementing Grover oracles for quantum key search on AES and LowMC,

    S. Jaques, M. Naehrig, M. Roetteler, and F. Virdia, “Implementing Grover oracles for quantum key search on AES and LowMC,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT). Springer, 2020, pp. 280– 310

  82. [91]

    Securing modbus in legacy industrial control systems: A decentralized approach using proxies, post-quantum cryp- tography and self-sovereign identity,

    F. Trungadi, M. Fabiano, D. Aloisio, G. Brunaccini, F. Sergi, G. Mer- lino, and F. Longo, “Securing modbus in legacy industrial control systems: A decentralized approach using proxies, post-quantum cryp- tography and self-sovereign identity,”Journal of Information Security and...

  83. [92]

    A survey on IoT security: Application areas, security threats, and solution architectures,

    V . Hassija, V . Chamola, V . Saxena, D. Jain, P. Goyal, and B. Sikdar, “A survey on IoT security: Application areas, security threats, and solution architectures,”IEEE Access, vol. 7, pp. 82 721–82 743, 2019

  84. [93]

    The Transport Layer Security (TLS) Protocol Version 1.3,

    E. Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.3,” https://www.rfc-editor.org/info/rfc8446, 2018

  85. [94]

    A cryptographic analysis of the TLS 1.3 handshake protocol,

    B. Dowling, M. Fischlin, F. G ¨unther, and D. Stebila, “A cryptographic analysis of the TLS 1.3 handshake protocol,”Journal of Cryptology, vol. 34, no. 4, p. 37, 2021

  86. [95]

    Enhancing cyber situational awareness for cyber-physical systems through digital twins,

    M. Eckhart, A. Ekelhart, and E. Weippl, “Enhancing cyber situational awareness for cyber-physical systems through digital twins,” in2019 24th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), 2019, pp. 1222–1225

  87. [96]

    Cybersecurity in critical infrastructures: A post-quantum cryptography perspective,

    J. Oliva del Moral, A. deMarti iOlius, G. Vidal, P. M. Crespo, and J. Etxezarreta Martinez, “Cybersecurity in critical infrastructures: A post-quantum cryptography perspective,”IEEE Internet of Things Journal, vol. 11, no. 18, pp. 30 217–30 244, 2024

  88. [97]

    A security model and fully verified implementation for the IETF QUIC record layer,

    A. Delignat-Lavaud, C. Fournet, B. Parno, J. Protzenko, T. Ramananan- dro, J. Bosamiya, J. Lallemand, I. Rakotonirina, and Y . Zhou, “A security model and fully verified implementation for the IETF QUIC record layer,” in2021 IEEE Symposium on Security and Privacy (SP), 2021, p...

  89. [98]

    The viability of post-quantum X.509 certificates,

    P. Kampanakis, P. Panburana, N. Daw, and D. Van Geest, “The viability of post-quantum X.509 certificates,”Cryptology ePrint Archive, Report 2018/063, 2021

  90. [99]

    Deciding equivalence-based properties using constraint solving,

    V . Cheval, V . Cortier, and S. Delaune, “Deciding equivalence-based properties using constraint solving,”Theoretical Computer Science, vol. 492, pp. 1–39, 2013

  91. [100]

    Clone detection in secure messaging: Improving post-compromise security in practice,

    C. Cremers, J. Fairoze, B. Kiesl, and A. Naska, “Clone detection in secure messaging: Improving post-compromise security in practice,” in ACM Conference on Computer and Communications Security (CCS), 2022, pp. 1481–1495

  92. [101]

    Post-quantum cryptography X.509 certificate,

    A. C. H. Chen, “Post-quantum cryptography X.509 certificate,” in 2024 International Conference on Smart Systems for applications in Electrical Sciences (ICSSES), 2024, pp. 1–6

  93. [102]

    Quantum-safe HIBE: Does it cost a latte?

    R. K. Zhao, S. McCarthy, R. Steinfeld, A. Sakzad, and M. O’Neill, “Quantum-safe HIBE: Does it cost a latte?” vol. 19, 2024, pp. 2680– 2695

  94. [103]

    Exploring advanced quantum ensemble for industrial control systems security,

    D. Vasan, M. Shameem, M. Hammoudeh, M. A. Rahim, H. Naeem, and A. F. Ahmed, “Exploring advanced quantum ensemble for industrial control systems security,” inProceedings of the 33rd ACM Interna- tional Conference on the Foundations of Software Engineering, ser. FSE Companion ’2...

  95. [104]

    Post-quantum TLS on embedded systems: Integrating and evaluat- ing Kyber and SPHINCS+ with mbed TLS,

    K. B ¨urstinghaus-Steinbach, C. Krauß, R. Niederhagen, and M. Schnei- der, “Post-quantum TLS on embedded systems: Integrating and evaluat- ing Kyber and SPHINCS+ with mbed TLS,” inProceedings of the 15th ACM Asia Conference on Computer and Communications Security, ser. ASIA CC...

  96. [105]

    Quantum attacks without superposition queries: The offline simon’s algorithm,

    X. Bonnetain, A. Hosoyamada, M. Naya-Plasencia, Y . Sasaki, and A. Schrottenloher, “Quantum attacks without superposition queries: The offline simon’s algorithm,” inAdvances in Cryptology – ASI- ACRYPT 2019. Cham: Springer, 2019, pp. 552–583

  97. [106]

    Assessing the overhead of post-quantum cryptography in TLS 1.3 and SSH,

    D. Sikeridis, P. Kampanakis, and M. Devetsikiotis, “Assessing the overhead of post-quantum cryptography in TLS 1.3 and SSH,” in ACM Conference on Data and Application Security and Privacy (CODASPY), 2020, pp. 149–158

  98. [107]

    On building automation systems and attacks,

    C. Morales-Gonzalez, M. Harper, M. Cash, Q. Z. Sun, and X. Fu, “On building automation systems and attacks,” in2024 International Conference on Computing, Networking and Communications (ICNC), 2024, pp. 536–542

  99. [108]

    EPIC: A testbed for scientifically rigorous cyber-physical security experimentation,

    C. Siaterlis, B. Genge, and M. Hohenadel, “EPIC: A testbed for scientifically rigorous cyber-physical security experimentation,”IEEE Transactions on Emerging Topics in Computing, vol. 1, no. 2, pp. 319– 330, 2013

  100. [109]

    Mitre att&ck: Design and philosophy,

    B. E. Strom, A. Applebaum, D. P. Miller, K. C. Nickels, A. G. Pennington, and C. B. Thomas, “Mitre att&ck: Design and philosophy,” The MITRE Corporation, Tech. Rep., 2018

  101. [110]

    Mitre att&ck for industrial control systems: Design and philosophy,

    O. Alexander, M. Belisle, and J. Steele, “Mitre att&ck for industrial control systems: Design and philosophy,” inThe MITRE Corporation, 2020

  102. [111]

    Mitre att&ck for industrial control systems,

    O. Alexander, M. Belisle, and J. Steele, “Mitre att&ck for industrial control systems,” MITRE Corporation, Tech. Rep., 2020, available: https://collaborate.mitre.org/attackics/

  103. [2024]

    Available: https://csrc.nist.gov/pubs/sp/800/82/r3/ipd

    [Online]. Available: https://csrc.nist.gov/pubs/sp/800/82/r3/ipd

Pith tools

Reviewed August 2, 2026 · model on record in the stance chip above.