- The paper derives a factorized HNDL compromise probability that combines a CRQC arrival hazard with a saturating contest term for quantum vulnerability and operational exposure.
- Its model shows that vulnerability and exposure interact nonlinearly, with diminishing elasticities near saturation and the greatest migration benefits occurring in defense-dominant regimes.
- Internal diagnostics across approximately 40,000 organizations support the predicted interaction structure, while the authors caution that the IEQ is a prioritization index rather than a calibrated probability.
The HNDL threat and the measurement problem
The Harvest-Now-Decrypt-Later (HNDL) attack has a simple operational structure: an adversary records encrypted traffic today, stores it, and decrypts it once a cryptographically relevant quantum computer (CRQC) becomes available. The relevant risk question is therefore not whether a cipher is breakable today, but whether it will be broken before the harvested data loses strategic value. Although NIST has finalized its first post-quantum standards [nistfips2024] and migration frameworks have been published by CISA, NSA, NIST, and ENISA, organizations still lack a principled answer to the prioritization question: how urgently must a given organization migrate?
The paper by Rufino, Marcelino, and Garcia addresses this gap at the level of structural form rather than calibration. Its central claim is that the functional form of an HNDL exposure score is not a free modeling choice: under three assumptions about adversarial production and value-decay dynamics, the compromise probability necessarily factorizes into a temporal hazard multiplied by a saturating contest term in vulnerability and exposure. Additive scoring frameworks cannot reproduce this structure regardless of calibration.
Model setup
Four quantities characterize an organization. V∈(0,1] is the quantum-vulnerability fraction — the share of cryptographic attack surface relying on Shor-breakable algorithms (RSA, ECDH, ECDSA, DSA). E∈(0,1] is operational exposure, i.e., how accessible that surface is to external harvesting. TD>0 is the adversarial shelf life of captured ciphertext, and μ>0 is the effective rate at which already-harvested ciphertext loses exploitability through data-value decay, rekeying, lifecycle controls, and remediation. The target quantity is the HNDL compromise probability PHNDL: the probability that a CRQC arrives within the data's adversarial horizon and exploitation precedes remediation.
Three structural hypotheses
Competing exponential processes. Attack and defense are modeled as constant-rate races with λA=λ0VaEb and λD=μ. The multiplicative structure follows from an intersection principle: compromise requires simultaneous reachability (E) and cryptographic vulnerability (V), treated as approximately independent conditions. The exponents encode infrastructure structure — a≥1 reflects concentration of critical assets (HSMs, CAs, TLS gateways) in the vulnerable subset; E∈(0,1]0 reflects saturation of the attack surface. Baseline priors are E∈(0,1]1, E∈(0,1]2. The authors further ground the contest form in Skaperdas's axioms for contest success functions (anonymity, independence of irrelevant alternatives, homogeneity), which restrict the admissible class to power-ratio forms once the effort variable E∈(0,1]3 is specified. A direct consequence is a strictly positive cross-partial E∈(0,1]4: vulnerability and exposure are complements in attack production.
A remark connects the defender-win probability E∈(0,1]5 to the Tsallis E∈(0,1]6-exponential at E∈(0,1]7. The authors are explicit that this analogy is suggestive rather than constitutive — the value E∈(0,1]8 is fixed by the binary contest structure, not imported from non-extensive thermodynamics.
Asymptotic independence. Cryptographic architecture and external accessibility are treated as approximately independent in cross-section. The paper concedes this fails within tightly integrated supply chains, though the empirical population-level Spearman correlation E∈(0,1]9 (TD>00) supports approximate independence at scale.
Proportional hazards composition. Conditional on CRQC arrival, the attacker wins with Tullock probability TD>01, structurally analogous to the Gordon-Loeb framework.
Main result
The theorem establishes the factorization
TD>02
where the temporal hazard TD>03 is a logistic CDF over CRQC arrival times parametrized by sector-specific median maturity year, with slope chosen so roughly 80% of probability mass lies within a 20-year window around the median. A local log-linearization yields endogenous elasticities
TD>04
which decrease continuously from their prior values TD>05 in the defense-dominant regime (TD>06) to zero near saturation. This regime duality distinguishes the model from CES or log-additive specifications, which assume constant elasticity and are recovered only in the limit TD>07.
The operational index, IEQ, applies floors, the local log-linear approximation, and a governance multiplier TD>08 on top of TD>09. The authors are careful here: the IEQ is explicitly not a calibrated probability. It is a prioritization index whose ordering is locally consistent with μ>00 within fixed μ>01 regimes, not a global scalar transform across heterogeneous sectors.
Two practical consequences follow directly from the theorem. First, migration efficiency: marginal sensitivity to μ>02 and μ>03 is highest when the organization sits in the defense-dominant regime, so early migration yields the greatest marginal return. Second, as developed in the corollary below, additive scores fail structurally.
Impossibility of additive scoring
The corollary shows that any additively separable score μ>04, or any ordinal transformation thereof, has zero cross-partial in natural coordinates and hence cannot reproduce the interaction structure of μ>05, whose log-log cross-partial
μ>06
is strictly negative for all finite positive parameters. The opposing signs of the two cross-partials are reconciled analytically: complementarity holds in the attack-production technology μ>07, while the negative log-probability cross-partial arises from Tullock-denominator saturation as μ>08 approaches its upper bound μ>09. In composite-indicator terms, additive scores embody full compensability (OECD handbook terminology): a deficit in one dimension offsets a surplus in another. Under HNDL, vulnerability and exposure are complements — an organization with high vulnerability but zero external exposure cannot be harvested, and no weight vector recovers this interaction. The resulting error is structural, not numerical: such scores produce both false positives and false negatives.
Specification diagnostics
The framework was instantiated over approximately 40,000 organizations using automated external observation as the source of PHNDL0 signals. Because ground-truth HNDL outcomes are unobservable in the pre-CRQC regime, evaluation is necessarily internal: Sobol total-effect indices quantify signal influence including interactions, Monte Carlo perturbation assesses uncertainty, and a penalized spline fitted to all input signals found no stable residual structure beyond the structural model. Non-nested comparison via the Vuong statistic against CES, log-additive, and threshold alternatives served as a self-consistency check rather than predictive validation. The observed log-cross-partial had the sign predicted by the theory, while the CES alternative yielded the opposite sign — consistent with the structural distinction established by the corollary. The authors frame this epistemic standard explicitly after Gordon-Loeb and the OECD handbook: internal structural consistency, not causal identification.
Limitations
Four limitations are stated plainly. The Poisson approximation assumes constant rates; correlated attack campaigns violate independent increments. The independence of PHNDL1 and PHNDL2 holds asymptotically in large heterogeneous populations but can fail in supply-chain-integrated sectors despite the low aggregate correlation. The adversarial shelf life PHNDL3 is a sector-level prior, not an auditable metric, with inherent multi-decade uncertainty for assets like trade secrets and medical records. Most fundamentally, there is no dataset of confirmed HNDL exploitations, so absolute calibration of Eq. (2) is infeasible before a CRQC exists; all evaluation is target-free, based on the internal variance structure of observable signals. The contribution is accordingly the form of the score, not calibrated constants.
Conclusion
The paper derives, from three axioms about competing exponential processes, asymptotic independence, and proportional-hazards composition, the necessary functional form of an HNDL exposure measure: a temporal hazard times a saturating multiplicative contest term, with elasticities endogenous to the organization's position in the vulnerability-exposure plane. It proves that additive and ordinal composites cannot preserve the required interaction structure, and reports an internal diagnostic over ~40,000 organizations consistent with the predicted saturation signature. Open questions left by the paper include network-contagion extensions relaxing axiom (A2) for supply-chain-integrated sectors and empirical estimation of PHNDL4 from observed PQC migration rates.