Skip to content
PQC TriageGitHub
Menu

Reference

Standards, estimates and the model

Every number this application produces comes from one of the tables below. If a row is wrong, the app is wrong, and the citation is right there so you can check it.

Transition dates

112-bit public key

2030

Deprecated after this year: RSA-2048, P-224, 1024-bit finite-field DH.

All quantum-vulnerable public key

2035

Disallowed after this year, including the 128-bit-and-above levels.

112-bit-level symmetric

2030

3DES and SHA-1-family primitives go here.

Source: NIST IR 8547 ipd, Transition to Post-Quantum Cryptography Standards. Dates are read from the published transition tables; this app does not interpret them.

Scoring table

35 primitives, each with the NIST comparable classical strength, the security it retains against a quantum adversary, how broken it already is, and what replaces it.

PrimitiveFamilyClassicalQuantumAlready weakNIST deprecateNIST disallowReplace with
RSA-1024signature-public8001.0020302035ML-KEM-768 (FIPS 203)(FIPS 203, 2y)
RSA-2048kex-public11200.1020302035ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y)
RSA-3072kex-public12800.02—2035ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y)
RSA-4096kex-public15200.01—2035ML-KEM-1024 (FIPS 203), hybrid with X25519(FIPS 203, 3y)
RSA-2048 signaturesignature-public11200.1020302035ML-DSA-65 (FIPS 204)(FIPS 204, 3y)
ECDSA P-224signature-public11200.3520302035ML-DSA-44 (FIPS 204)(FIPS 204, 3y)
ECDSA P-256signature-public12800.05—2035ML-DSA-65 (FIPS 204)(FIPS 204, 3y)
ECDSA P-384signature-public19200.03—2035ML-DSA-65 (FIPS 204)(FIPS 204, 3y)
ECDH P-256kex-public12800.05—2035ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y)
ECDH P-384kex-public19200.03—2035ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y)
Finite-field Diffie-Hellman 2048kex-public11200.1520302035ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 3y)
Ed25519signature-public12800.02—2035ML-DSA-65 (FIPS 204)(FIPS 204, 4y)
X25519kex-public12800.02—2035ML-KEM-768 (FIPS 203), hybrid with X25519(FIPS 203, 2y)
ML-KEM-512kex-public1281280.00——Keep ML-KEM-512(FIPS 203, 0y)
ML-KEM-768kex-public1921920.00——Keep ML-KEM-768(FIPS 203, 0y)
ML-DSA-44signature-public1281280.00——Keep ML-DSA-44(FIPS 204, 0y)
ML-DSA-65signature-public1921920.00——Keep ML-DSA-65(FIPS 204, 0y)
SLH-DSA-SHA2-128ssignature-public1281280.00——Keep SLH-DSA-SHA2-128s(FIPS 205, 0y)
MD5hash001.00——SHA-256(FIPS 180-4, 1y)
SHA-1hash80300.90—2030SHA-256 or SHA-384(FIPS 180-4, 1y)
SHA-256hash1281280.00——Keep SHA-256(FIPS 180-4, 0y)
SHA-384hash1921920.00——Keep SHA-384(FIPS 180-4, 0y)
HMAC-SHA-256mac1281280.00——Keep HMAC-SHA-256(FIPS 198-1, 0y)
HMAC-SHA-1mac80400.75—2030HMAC-SHA-256(FIPS 198-1, 1y)
AES-128symmetric-cipher128640.05——AES-256-GCM(FIPS 197 + SP 800-38D, 1y)
AES-256symmetric-cipher2561280.00——Keep AES-256-GCM(FIPS 197 + SP 800-38D, 0y)
DESsymmetric-cipher56281.00—2030AES-256-GCM(FIPS 197 + SP 800-38D, 1y)
3DESsymmetric-cipher112560.80—2030AES-256-GCM(FIPS 197 + SP 800-38D, 1y)
RC4stream-cipher001.00—2030ChaCha20-Poly1305 or AES-256-GCM(SP 800-38D / RFC 8439, 1y)
ChaCha20-Poly1305stream-cipher2561280.00——Keep ChaCha20-Poly1305(RFC 8439, 0y)
PBKDF2-HMAC-SHA-256kdf1281280.20——Argon2id or scrypt(RFC 9106 / RFC 7914, 1y)
PBKDF2-HMAC-SHA-1kdf80400.60—2030Argon2id(RFC 9106, 1y)
bcryptpassword-hash1281280.00——Keep bcrypt or move to Argon2id(OpenBSD bcrypt, 0y)
Argon2idpassword-hash1281280.00——Keep Argon2id(RFC 9106, 0y)
Math.random() for a secretrng001.00——crypto.randomBytes / secrets.token_bytes(FIPS 140-3 approved DRBG, 0.25y)

Quantum resource estimates

Gidney & Ekerä closed form, RSA

logical qubits = 3n + 0.002 n lg n
Toffoli gates = 0.3 n³ + 0.0005 n³ lg n

ModulusLogical qubitsToffolis
RSA-20486,1892.62B
RSA-30729,2878.87B
RSA-409612,38621.03B

At n = 2048 this yields 6,189 logical qubits, which is the figure the paper reports. The app converts logical to physical with a 3,232:1 ratio, taken from that paper's own 20-million-physical-qubit run, so the two numbers stay consistent with each other.

ECDLP, linear model

Published constructions for the elliptic-curve discrete logarithm problem are linear in the key length, so this app scales the anchor from Häner et al.: 2,124 logical qubits at 256 bits, or 8.297 logical qubits per key bit. No Toffoli figure is claimed, because the published counts for this problem span orders of magnitude depending on the construction.

P-256 → 2,124 · P-384 → 3,186 · P-521 → 4,323 logical qubits

These are literature estimates under stated assumptions, not predictions of a date. The app labels them as such everywhere they appear.

Engine hndl@1.0.0

Six weighted factors, summed to a 0-100 score and banded. The weights are constants in one file, and the same function runs in the browser, on the server, and inside the agent tools.

FactorWeightQuestion it answers
Harvest-now-decrypt-later window0.26How long until ciphertext captured today is decryptable?
Quantum security strength0.22How many bits of security survive a quantum adversary?
Migration headroom0.18Is there still time to finish before NIST forbids it?
Classical weakness0.14Is it already broken without a quantum computer at all?
Dependency supply signal0.12Is the package maintained, and does it carry known advisories?
What this primitive protects0.08What depends on this key establishment or signature?

Deadline arithmetic: work must start by H − (X + Y), where X is the years the data must stay confidential and Y is the migration lead time recorded against the replacement primitive. The chain is SHA-384.

Classifier nbc@1.0.0

A multinomial Naive Bayes model implemented in this repository. It has no weights file, calls no service and needs no key: it trains from a seed corpus of realistic call sites plus every correction a user teaches it, and the learned table is exportable. Training rows are sorted before counting so the model is deterministic.

nbc@1.0.0

Sources

This is an engineering aid, not an assurance or security advice. It does not certify a system as quantum-safe. Resource estimates are literature values under stated assumptions, not forecasts.

Ready to try it on your own code? Import a manifest.