Hybrid Classical–Post-Quantum Migration Framework for Brownfield SCADA Environments

Ankit Gupta, Shilpi Mittal · IEEE Access · 2026

Brownfield supervisory control and data acquisition environments face a migration problem that is materially different from enterprise information technology. Post-quantum cryptography must be introduced into systems that privilege safety, deterministic communications, long asset lifetimes, staged outages, vendor-certified configurations, and protocol heterogeneity. At the same time, the public standards landscape changed rapidly between 2023 and March 2026, including finalization of the NIST ML-KEM, ML-DSA, and SLH-DSA standards, publication of NIST guidance for key-encapsulation mechanisms, growth of national migration roadmaps, and active standardization of hybrid and pure post-quantum handshakes for Transport Layer Security and Internet Key Exchange. This paper develops a framework for hybrid classical-post-quantum migration in brownfield SCADA settings that is evidence-based, implementation-oriented, and explicitly staged. We distinguish coexistence from true cryptographic hybridization, quantify control-plane overhead using official algorithm sizes and current protocol drafts, and propose a conduit-first migration sequence that prioritizes gateways, remote access, management planes, trust anchors, and software-signing services before intrusive field-device replacement. To support the applied-research claim, the framework is evaluated through standards-derived protocol-overhead analysis, a representative brownfield case demonstration, explicit scoring-model parameter rationale, sensitivity analysis, phase-gate validation criteria, and a pilot evidence package. The result is a practical path for operators who must begin quantum-safe preparation now, even where endpoint-native post-quantum support remains uneven.

Read the paper · More papers on PaperTik