Abstract

The imminent maturation of Cryptographically Relevant Quantum Computers (CRQCs) represents a fundamental threat to the digital security infrastructure, specifically targeting modern cryptographic standards such as AES, RSA and Elliptic Curve Cryptography (ECC). While Post -Quantum Cryptography (PQC) offers a mathematical defense, the transition is complicated by the “Harvest Now, Decrypt Later ” (HNDL) strategy, where encrypted data is intercepted today for future decryption. This thesis explores the critical necessity of an organized migration strategy to protect long-term data sensitivity against the rapid advancement of quantum capabilities and addresses the gaps in the current migration landscape: the absence of a standardized, risk -based prioritization methodology, the absence of an AI based prioritization system to accommodate the approximate nature of variables involved, and a comparison of both the implementations. Finally, the technical deadlock surrounding non -upgradable legacy systems. Current literature often lacks a semi-quantified approach that uses data criticality as the primary criterion for migration triage. This thesis covers the void by introducing a framework supported by a custom software tool based on that assigns numerical priority scores based on data shelf -life and organizational risk and also implements the prioritization using Fuzzy Logic and them comparing the results of the two implementations to see which platform better suits the problem . Furthermore, the thesis tackles the challenge of legacy hosts that cannot support NIST-standardized algorithms, proposing a crypto -agile architectural solution that utilizes intermediate VPN terminals and SSH tunnels to wrap vulnerable traffic in quantum -resistant encryption. The results of this thesis demonstrate that a structured, data -centric approach can successfully mitigate quantum risk even in complex enterprise environments , furthermore it determines how a Fuzzy Logic based implementation better suits the approximate nature of the problem. Experimental validation through the “corp.com” simulation showed that implementing the proposed PQC -based SSH VPN reduced legacy host exposure to near zero while maintaining high operational performance. Despite the inherent computational overhead of PQC algorithms, the hybrid implementation experienced only a 15.7% increase in average round -trip time for 100 packets, significantly outperforming the 20% speed loss typically associated with hybrid PQC over networks. These findings provide a scientific and repeatable basis for organizational leaders to direct resources toward quantum-safe encryption without compromising network efficiency.

Publication Date

5-2026

Document Type

Thesis

Student Type

Graduate

Degree Name

Cybersecurity (MS)

Advisor

Wesam Almobaideen

Advisor/Committee Member

Kevser Ovaz Akpinar

Advisor/Committee Member

Omar Abdul Latif

Campus

RIT Dubai

Share

COinS