Abstract
The imminent maturation of Cryptographically Relevant Quantum Computers (CRQCs) represents a fundamental threat to the digital security infrastructure, specifically targeting modern cryptographic standards such as AES, RSA and Elliptic Curve Cryptography (ECC). While Post -Quantum Cryptography (PQC) offers a mathematical defense, the transition is complicated by the “Harvest Now, Decrypt Later ” (HNDL) strategy, where encrypted data is intercepted today for future decryption. This thesis explores the critical necessity of an organized migration strategy to protect long-term data sensitivity against the rapid advancement of quantum capabilities and addresses the gaps in the current migration landscape: the absence of a standardized, risk -based prioritization methodology, the absence of an AI based prioritization system to accommodate the approximate nature of variables involved, and a comparison of both the implementations. Finally, the technical deadlock surrounding non -upgradable legacy systems. Current literature often lacks a semi-quantified approach that uses data criticality as the primary criterion for migration triage. This thesis covers the void by introducing a framework supported by a custom software tool based on that assigns numerical priority scores based on data shelf -life and organizational risk and also implements the prioritization using Fuzzy Logic and them comparing the results of the two implementations to see which platform better suits the problem . Furthermore, the thesis tackles the challenge of legacy hosts that cannot support NIST-standardized algorithms, proposing a crypto -agile architectural solution that utilizes intermediate VPN terminals and SSH tunnels to wrap vulnerable traffic in quantum -resistant encryption. The results of this thesis demonstrate that a structured, data -centric approach can successfully mitigate quantum risk even in complex enterprise environments , furthermore it determines how a Fuzzy Logic based implementation better suits the approximate nature of the problem. Experimental validation through the “corp.com” simulation showed that implementing the proposed PQC -based SSH VPN reduced legacy host exposure to near zero while maintaining high operational performance. Despite the inherent computational overhead of PQC algorithms, the hybrid implementation experienced only a 15.7% increase in average round -trip time for 100 packets, significantly outperforming the 20% speed loss typically associated with hybrid PQC over networks. These findings provide a scientific and repeatable basis for organizational leaders to direct resources toward quantum-safe encryption without compromising network efficiency.
Publication Date
5-2026
Document Type
Thesis
Student Type
Graduate
Degree Name
Cybersecurity (MS)
Advisor
Wesam Almobaideen
Advisor/Committee Member
Kevser Ovaz Akpinar
Advisor/Committee Member
Omar Abdul Latif
Recommended Citation
Malik, Saquib Farooq, "A Study of Post -Quantum Cryptography Migration in an Emulated Enterprise Environment" (2026). Thesis. Rochester Institute of Technology. Accessed from
https://repository.rit.edu/theses/12812
Campus
RIT Dubai
