🤖 AI Summary
本文提出了一种准备-主权能力模型(RSCM),用于评估国家在后量子密码学迁移中的准备程度和密码主权,通过该模型对57个密码行为者进行了分类。
📝 Abstract
Cryptographic dependence predates the quantum era, but the migration to post-quantum cryptography (PQC) opens a rare window to reshape it, because the algorithms, implementations, hardware, and standards adopted now can lock in dependence or sovereignty for decades. This paper introduces the Readiness-Sovereignty Capability Model (RSCM), a national measurement model that operationalizes PQC readiness together with cryptographic sovereignty, which current maturity models score only as readiness and the sovereignty literature defines without measuring. RSCM decomposes sovereignty into three distinct constructs, indigenous cryptographic capacity, indigenous post-quantum control, and external dependency, and certifies a post-quantum maker only through a gate requiring demonstrated, institutionally sustained creation in at least one core layer, whether design, implementation, or validation. Applying it to fifty-seven documented cryptographic actors coded from cited public evidence, and testing that coding with an independent second coder, a plausible-state bootstrap, and convergent-validity checks, we find that twenty countries clear the gate, fifteen as full-stack makers and five as research makers, eleven hold strong general capacity without post-quantum control, one is a ready adopter, and twenty-five are dependent. The gate cells show substantial weighted agreement, a quadratic-weighted kappa of 0.71, and the maker classification is stable in its core though uncertain at the threshold. Readiness tracks independent cyber indices at rank correlations up to 0.70, while post-quantum creation shows no significant correlation with the commitment index, a rank correlation of only 0.22 that separates control from readiness. The paper contributes the framework, the evidence-graded assessment, and policy directions for building indigenous quantum-safe capacity.