IP Library › Granted Patent US 12,737,479
Granted Patent B2
US 12,737,479 · App. 18/826,572 · Granted Sep 15, 2026

Methods and systems for estimating risk of enterprise application for quantum cryptography migration

Inventors: Meena Singh Dilip Thakur (Bengaluru, IN); Habeeb Basha Syed (Hyderabad, IN); Kumar Mansukhlal Vidhani (Gandhinagar, IN); Rajan Mindigal Alasingara Bhattachar (Bangalore, IN); Sachin Premsukh Lodha (Pune, IN)
Assignee: TATA CONSULTANCY SERVICES LIMITED
G06F21/577H04L9/0877G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,479
App. No.
18/826,572
Granted
Sep 15, 2026
Kind
B2
Abstract

The disclosure generally relates to methods and systems for estimating risk of enterprise application for quantum cryptography migration. Conventional software risk assessment tools that assess the quantum computer related security attacks are limited. The present disclosure solves the technical problems in the art for estimating risk of enterprise application for quantum cryptography migration. The methods and systems of the present disclosure formulated the problem based on a survival function in the probability theory, where possible chances of the enterprise application crypto surviving the quantum computer are calculated, and an estimated risk value is assigned to the enterprise software application. The methods and systems of the present disclosure discloses a risk estimator which take enterprise application specific metadata as the inputs and produces the risk score associated to the enterprise application against the quantum threats using a modified cox model and a modified rule of Mosca.

Claims (90)

1 . A processor-implemented method, comprising the steps of:

defining, via one or more hardware processors, one or more application risk input parameters, one or more platform risk input parameters, and one or more risk policy input parameters, for a host enterprise application;

receiving, via the one or more hardware processors, an application related data of the host enterprise application, a data shelf life of the application related data of the host enterprise application, a time to migrate the host enterprise application whose risk is to be estimated from a quantum threat after migration, and a time by which a quantum computer manufactured;

extracting, via the one or more hardware processors, an input parameter value of each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, from the application related data of the host enterprise application whose risk is to be estimated from the quantum threat, using a data extraction technique, wherein a code parser is configured to fetch the input parameter value of an user type and a validity by analyzing an user access policy related data, and wherein the input parameter value corresponding to a vulnerability is extracted from an audit report or from vulnerability information generated during an application testing phase, and wherein the input parameter value associated with validity of a third party library is fetched based on dependency information of one or more third party libraries present in the host enterprise application;

computing, via the one or more hardware processors, a hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on an associated input parameter value, using a modified cox model, wherein computing the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on the associated input parameter value, using the modified cox model, comprising:

receiving a number of qubits of a quantum computer, and a number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application, of one or more predefined cryptographic schemes;

determining a quantum hazard value, based on the number of qubits of the quantum computer and the number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application;

determining a partial likelihood function value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, using the modified cox model, by estimating a probability of attack on the predefined cryptographic scheme for a current instance with respect to one or more historical instances that are vulnerable to computing capability of the quantum computer; and

calculating the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters values, using the quantum hazard value, an associated partial likelihood function value and the associated input parameter value;

estimating, via the one or more hardware processors, a hazard risk value of the host enterprise application, based on the hazard value computed for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters;

determining, via the one or more hardware processors, a Mosca risk value of the host enterprise application, based on the data shelf life of application related data of the host enterprise application, the time to migrate the host enterprise application, and the time by which quantum computer manufactured, using a rule of Mosca;

calculating, via the one or more hardware processors, a cumulative risk value of the host enterprise application, using the hazard risk value of the host enterprise application and the Mosca risk value of the host enterprise application;

evaluating, via the one or more hardware processors, the risk of the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and an average cumulative risk value, wherein evaluating the risk the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and the average cumulative risk value, comprising:

(i) assigning the host enterprise application with a high priority and allowing a migration of the host enterprise application when the cumulative risk value of the host enterprise application is higher than the average cumulative risk value; and

(ii) assigning the host enterprise application with a low priority and postponing the migration of the host enterprise application when the cumulative risk value of the host enterprise application is less than or equal to the average cumulative risk value; and

performing, via the one or more hardware processors, the quantum cryptography migration based on the evaluated risk of the host enterprise application.

2 . The processor-implemented method of claim 1 , wherein the application related data of the host enterprise application is received from one or more of: (i) one or more answers received for a questionnaire related to the host enterprise application, (ii) a source code of the host enterprise application, and (iii) one or more log files of the host enterprise application.

3 . The processor-implemented method of claim 1 , wherein the one or more application risk input parameters comprise of an application type, a threat type, a user type and validity, a vulnerability, and a third-party library validity.

4 . The processor-implemented method of claim 1 , wherein the one or more platform risk input parameters comprise of a language cohesion index, a lower environment risk parameter, an input and output movement, a shelf-life parameter, and a hardware security module (HSM) migration policy.

5 . The processor-implemented method of claim 1 , wherein the one or more risk policy input parameters comprise of a policy related parameter, a legacy application transformation, and a post quantum cryptography (PQC) algorithm vulnerability, wherein the PQC algorithm vulnerability parameters represent a risk condition and an associated impact on the migration, the risk condition being based on vulnerability information associated with at least one PQC algorithm as identified by a recognized standards or analysis authority.

6 . The processor-implemented method of claim 1 , wherein the Mosca risk value of the host enterprise application is determined using the rule of Mosca, according to a relation:

Mosca

⁢

risk

⁢

value

=

Z

-

(

X

+

Y

)

wherein Z is the time by which quantum computer manufactured with sufficient qubits, which breaks the predefined crypto scheme, X is the data shelf life of application related data of the host enterprise application, and Y is the time to migrate the host enterprise application.

7 . A system, comprising:

a memory storing instructions;

one or more input/output (I/O) interfaces; and

one or more hardware processors coupled to the memory via the one or more I/O interfaces,

wherein the one or more hardware processors are configured by the instructions to:

define one or more application risk input parameters, one or more platform risk input parameters, and one or more risk policy input parameters, for a host enterprise application;

receive an application related data of the host enterprise application, a data shelf life of the application related data of the host enterprise application, a time to migrate the host enterprise application whose risk is to be estimated from a quantum threat after migration, and a time by which quantum computer manufactured;

extract an input parameter value of each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, from the application related data of the host enterprise application whose risk is to be estimated from the quantum threat, using a data extraction technique, wherein a code parser is configured to fetch the input parameter value of an user type and a validity by analyzing an user access policy related data, and wherein the input parameter value corresponding to a vulnerability is extracted from an audit report or from vulnerability information generated during an application testing phase, and wherein the input parameter value associated with validity of a third party library is fetched based on dependency information of one or more third party libraries present in the host enterprise application;

compute a hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on an associated input parameter value, using a modified cox model, wherein computing the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on the associated input parameter value, using the modified cox model, comprising:

receiving a number of qubits of a quantum computer, and a number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application, of one or more predefined cryptographic schemes;

determining a quantum hazard value, based on the number of qubits of the quantum computer and the number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application;

determining a partial likelihood function value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, using the modified cox model, by estimating a probability of attack on the predefined cryptographic scheme for a current instance with respect to one or more historical instances that are vulnerable to computing capability of the quantum computer; and

calculating the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters values, using the quantum hazard value, an associated partial likelihood function value and the associated input parameter value;

estimate a hazard risk value of the host enterprise application, based on the hazard value computed for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters;

determine a Mosca risk value of the host enterprise application, based on the data shelf life of application related data of the host enterprise application, the time to migrate the host enterprise application, and the time by which quantum computer manufactured, using a rule of Mosca;

calculate a cumulative risk value of the host enterprise application, using the hazard risk value of the host enterprise application and the Mosca risk value of the host enterprise application;

evaluate the risk of the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and an average cumulative risk value, wherein evaluating the risk the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and the average cumulative risk value, comprising:

(i) assigning the host enterprise application with a high priority and allowing a migration of the host enterprise application when the cumulative risk value of the host enterprise application is higher than the average cumulative risk value; and

(ii) assigning the host enterprise application with a low priority and postponing the migration of the host enterprise application when the cumulative risk value of the host enterprise application is less than or equal to the average cumulative risk value; and

perform the quantum cryptography migration based on the evaluated risk of the host enterprise application.

8 . The system of claim 7 , wherein the one or more hardware processors are configured to receive the application related data of the host enterprise application from one or more of: (i) one or more answers received for a questionnaire related to the host enterprise application, (ii) a source code of the host enterprise application, and (iii) one or more log files of the host enterprise application.

9 . The system of claim 7 , wherein the one or more application risk input parameters comprise of an application type, a threat type, a user type and validity, a vulnerability, and a third-party library validity.

10 . The system of claim 7 , wherein the one or more platform risk input parameters comprise of a language cohesion index, a lower environment risk parameter, an input and output movement, a shelf-life parameter, and a hardware security module (HSM) migration policy.

11 . The system of claim 7 , wherein the one or more risk policy input parameters comprise of a policy related parameter, a legacy application transformation, and a post quantum cryptography (PQC) algorithm vulnerability, wherein the PQC algorithm vulnerability parameters represent a risk condition and an associated impact on the migration, the risk condition being based on vulnerability information associated with at least one PQC algorithm as identified by a recognized standards or analysis authority.

12 . The system of claim 7 , wherein the one or more hardware processors are configured to determine Mosca risk value of the host enterprise application using the rule of Mosca, according to a relation:

Mosca

⁢

risk

⁢

value

=

Z

-

(

X

+

Y

)

wherein Z is the time by which quantum computer manufactured with sufficient qubits, which breaks the predefined crypto scheme, X is the data shelf life of application related data of the host enterprise application, and Y is the time to migrate the host enterprise application.

13 . One or more non-transitory machine-readable information storage mediums comprising one or more instructions which when executed by one or more hardware processors cause:

defining one or more application risk input parameters, one or more platform risk input parameters, and one or more risk policy input parameters, for a host enterprise application;

receiving an application related data of the host enterprise application, a data shelf life of the application related data of the host enterprise application, a time to migrate the host enterprise application whose risk is to be estimated from a quantum threat after migration, and a time by which a quantum computer manufactured;

extracting an input parameter value of each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, from the application related data of the host enterprise application whose risk is to be estimated from the quantum threat, using a data extraction technique, wherein a code parser is configured to fetch the input parameter value of an user type and a validity by analyzing an user access policy related data, and wherein the input parameter value corresponding to a vulnerability is extracted from an audit report or from vulnerability information generated during an application testing phase, and wherein the input parameter value associated with validity of a third party library is fetched based on dependency information of one or more third party libraries present in the host enterprise application;

computing a hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on an associated input parameter value, using a modified cox model, wherein computing the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on the associated input parameter value, using the modified cox model, comprising:

receiving a number of qubits of a quantum computer, and a number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application, of one or more predefined cryptographic schemes;

determining a quantum hazard value, based on the number of qubits of the quantum computer and the number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application;

determining a partial likelihood function value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, using the modified cox model, by estimating a probability of attack on the predefined cryptographic scheme for a current instance with respect to one or more historical instances that are vulnerable to computing capability of the quantum computer; and

calculating the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters values, using the quantum hazard value, an associated partial likelihood function value and the associated input parameter value;

estimating a hazard risk value of the host enterprise application, based on the hazard value computed for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters;

determining a Mosca risk value of the host enterprise application, based on the data shelf life of application related data of the host enterprise application, the time to migrate the host enterprise application, and the time by which quantum computer manufactured, using a rule of Mosca;

calculating a cumulative risk value of the host enterprise application, using the hazard risk value of the host enterprise application and the Mosca risk value of the host enterprise application;

evaluating the risk of the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and an average cumulative risk value, wherein evaluating the risk the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and the average cumulative risk value, comprising:

(i) assigning the host enterprise application with a high priority and allowing a migration of the host enterprise application when the cumulative risk value of the host enterprise application is higher than the average cumulative risk value; and

(ii) assigning the host enterprise application with a low priority and postponing the migration of the host enterprise application when the cumulative risk value of the host enterprise application is less than or equal to the average cumulative risk value; and

performing the quantum cryptography migration based on the evaluated risk of the host enterprise application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2024
From: SINGH DILIP THAKUR, MEENA; SYED, HABEEB BASHA; VIDHANI, KUMAR MANSUKHLAL; ALASINGARA BHATTACHAR, RAJAN MINDIGAL; LODHA, SACHIN PREMSUKH
To: TATA CONSULTANCY SERVICES LIMITED
Reel/Frame 068508/0838 →
Priority Claims (1)
IN 202321067239 · Oct 6, 2023 · national
Continuity (1)
Related Publication 20250284818A1 · Sep 11, 2025
References Cited (9)
US 11218300B1 · Shea · 2022 [cited by examiner]
US 11223470B1 · Shea · 2022 [cited by examiner]
US 20180137288A1 · Polyakov · 2018 [cited by applicant]
US 20200244706A1 · Young · 2020 [cited by examiner]
CN 101436240A · 2009 [cited by applicant]
Chujiao Ma, et al., CARAF: Crypto Agility Risk Assessment Framework, Journal of Cybersecurity 2021, Oxford University Press, 1-11 (Year: 2021). [cited by examiner]
Siv Hilde Houmb, and Virginia Franqueira, Estimating ToE Risk Level using CVS, 2009 International Conference on Availability, Reliability and Security, IEEE Computer Society, 718-725 (Year: 2009). [cited by examiner]
Lukas Malina, et al., Post-Quantum Era Privacy Protection for Intelligence Infrastructures, IEEE Access vol. 9, 2021, Mar. 8, 2021, 36038-36077 (Year: 2021). [cited by examiner]
Nagaraju et al., “Optimal Test Activity Allocation for Covariate Software Reliability and Security Models,” (2020). [cited by applicant]