Full Report
We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far.
Analysis Summary
# Best Practices: Post-Quantum Cryptography Migration and Discovery
## Overview
These practices address the operational challenge of preparing an organization’s digital infrastructure for the transition to post-quantum cryptography (PQ migration) by a target deadline (such as 2029). This guidance covers discovering legacy cryptography embedded across extensive codebases, managing upstream dependencies, implementing compensating edge controls, and prioritizing migration pathways to mitigate "store-now-decrypt-later" threats.
## Key Recommendations
### Immediate Actions
1. **Deploy Edge-Layer PQ Encryption:** Enable post-quantum encryption (e.g., TLS 1.3 with hybrid post-quantum key exchange) at your network perimeter or edge infrastructure. This serves as an immediate compensating control to safeguard data in transit while internal codebase discovery is underway.
2. **Isolate a High-Priority Pilot Repository:** Select a single critical system codebase—specifically one handling sensitive, long-lived data, internet-facing traffic, or core authentication/authorization mechanics—to launch an initial cryptography discovery test.
### Short-term Improvements (1-3 months)
1. **Implement Hybrid Cryptography Discovery:** Build or adopt a scanning pipeline that utilizes Abstract Syntax Tree (AST) parsing and regular expressions (regex) for explicit cryptographic libraries (e.g., standard language crypto modules), combined with Large Language Models (LLMs) to analyze and classify ambiguous, custom, or deeply embedded cryptographic code patterns.
2. **Establish Developer Validation Workflows:** Route automated discovery findings directly to product and engineering code owners via internal ticketing systems. Require teams to validate findings, verify if the implementation is required long-term, and distinguish between encryption and authentication use cases.
### Long-term Strategy (3+ months)
1. **Map and Track PQ Metrics:** Generate centralized, per-repository compliance dashboards capturing metrics such as the ratio of classical versus post-quantum encryption and authentication mechanisms.
2. **Log and Address Ecosystem Blockers:** Systematically inventory dependencies, libraries, third-party vendors, or protocols that currently lack post-quantum variants or consensus standards. Establish engagement pathways with vendors and standards bodies to resolve these upstream blockers before target migration deadlines.
---
## Implementation Guidance
### For Small Organizations
- Rely heavily on infrastructure-as-a-service (IaaS) and content delivery network (CDN) vendors to enable post-quantum security at the application layer automatically.
- Conduct a manual inventory of core repositories and dependencies to identify external SaaS integrations that require quantum-resistant updates.
### For Medium Organizations
- Utilize standard open-source static application security testing (SAST) tools and regex frameworks to scan repositories for explicit legacy cryptographic functions (e.g., RSA, ECC).
- Prioritize remediation efforts on external-facing components and core data stores over internal, isolated microservices.
### For Large Enterprises
- Deploy an automated, AI-driven discovery engine (similar to Cloudflare's internal *CryptoLabe* concept) capable of parsing massive, multi-repository environments.
- Establish a dedicated Post-Quantum Migration Office or working group to orchestrate remediation across disparate engineering teams and track remediation progress metrics globally.
---
## Configuration Examples
While specific proprietary code for discovery tools is internal, a programmatic hybrid discovery workflow can be modeled using the following structural steps:
### Conceptual Discovery Pipeline Logic
[Codebase/Repository]
│
▼
┌────────────────────────────────────────────────────────┐
│ Phase 1: Static AST & Regex Scan │
│ - Flag standard libraries (e.g., crypto/tls, crypto/x509)│
└───────────────────────┬────────────────────────────────┘
│
├─► [Explicit Match Found] ──► Auto-generate Ticket
│
▼
┌────────────────────────────────────────────────────────┐
│ Phase 2: LLM Contextual Analysis │
│ - Prompt: "Analyze this snippet. Does it implement │
│ custom/legacy crypto protocols or key exchanges?" │
└───────────────────────┬────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────┐
│ Phase 3: Classification & Enrichment │
│ - Categorize: Encryption vs. Authentication │
│ - Metadata: Repositories, Owner Teams, Dependencies │
└───────────────────────┬────────────────────────────────┘
│
▼
[Central PQ Metrics Dashboard]
---
## Compliance Alignment
- **NIST Post-Quantum Cryptography (PQC) Standardization:** Aligns with transitioning to approved algorithms (such as ML-DSA for authentication and ML-KEM for key encapsulation).
- **CISA/NIST/NSA Joint Guidance:** Supports the mandated directives for timeline-driven quantum readiness and cryptographic inventory collection.
- **ISO/IEC 27001 (Cryptographic Controls):** Enhances compliance with asset management and cryptographic control visibility requirements.
---
## Common Pitfalls to Avoid
- **The Completeness Trap:** Delaying mitigation actions until a 100% complete cryptographic inventory is achieved. Instead, focus immediately on high-value targets and edge security.
- **Conflating Encryption with Authentication:** Assuming that because TLS/encryption layers are upgraded, authentication mechanisms are also secure. Post-quantum authentication (signatures, CAs) introduces different packet overhead complexities and often moves at a slower deployment timeline than encryption.
- **Ignoring Dependency Defaults:** Relying solely on your primary source code while overlooking legacy cryptography embedded inside third-party binary libraries and vendor-supplied software defaults.
---
## Resources
- **Cloudflare Post-Quantum Roadmap Documentation:** `https[:]//blog[.]cloudflare[.]com/post-quantum-roadmap/`
- **Post-Quantum Authentication Reference Materials:** `https[:]//blog[.]cloudflare[.]com/ml-dsa-will-have-to-do/`
- **NIST Post-Quantum Cryptography Project:** `https[:]//csrc[.]nist[.]gov/projects/post-quantum-cryptography`