PQReach-OT: Preserving Post-Quantum Security During Recovery and Failover in Industrial Control Systems
Operational technology (OT) systems, such as power-grid controls and factory automation, are replacing cryptographic mechanisms vulnerable to future quantum computers with post-quantum (PQ) cryptography. However, older backups, standby systems, trust stores, and failover paths may retain weaker cryptography after the active system is upgraded. Legitimate recovery can reactivate these weaker states and allow them to regain privileged authority, reducing achieved protection. Existing work addresses PQ deployment, crypto-agility, secure recovery, rollback protection, attestation, and continuous authorization, but these mechanisms do not by themselves determine whether legitimate recovery can restore weaker cryptographic states that may regain privileged authority. We introduce PQReach-OT, which analyzes recovery paths before failure, keeps the required cryptographic protection level separate from the recoverable state, and requires fresh evidence before privileged authority is restored. We conducted a controlled mechanism-validation study using 570 deterministic recovery variants across 19 specified recovery scenario families. Seven configured mechanisms were exercised on the same variants, yielding 3990 primary records. The purpose of this matrix is to demonstrate and distinguish the registered recovery-security properties under controlled same-input cases, but it does not estimate the comparative effectiveness or weakness prevalence in operational OT deployments. Within these controlled cases, both PQReach-OT and the strong reactive experimental control satisfied post-transition grant safety. PQReach-OT additionally exercised the recovery-closure functions defined by the model: it identified all 510 current-compliant but recovery-unsafe variants before failure, selected a compliant alternative in all 390 applicable cases, rejected all 30 historical-floor replays, and detected all 30 exposures reachable only through multi-step recovery. Inventory completeness is an explicit assurance boundary: in the registered additive inventory-completion mutations, adding a compliant recovery state preserved Recovery-Closed Migration Coverage (RCMC) at 1.0, whereas adding a previously unrepresented below-floor state capable of regaining protected authority reduced RCMC from 1.0 to 0.0. Thus, RCMC is explicitly conditional on the represented recovery reachability: additive inventory completion can preserve the existing closure assessment or reveal an additional violation, but it cannot strengthen that assessment solely by enlarging the represented recovery space. These outcomes demonstrate the behavior and separability of the proposed recovery-closure mechanisms within the defined recovery semantics; evaluation in operational OT environments addresses the complementary question of external generalizability.
Authors
- Hasan Hüseyin Balık (ORCID: https://orcid.org/0000-0003-3022-100X)
- Wisam Makki Alwash (ORCID: https://orcid.org/0000-0002-1640-7484)
- Belal Al‐Khateeb (ORCID: https://orcid.org/0000-0003-3066-0790)
- Weam Husham Aljabbari (ORCID: https://orcid.org/0000-0001-5585-9849)
Institutions
- University of Babylon (IQ)
- University of Anbar (IQ)
- Yıldız Technical University (TR)
- Istanbul Technical University (TR)
- Istanbul University (TR)
Publication Details
- Journal
- Electronics
- Published
- 2026-09-21
- DOI
- https://doi.org/10.3390/electronics15184338
- Primary Topic
- Smart Grid Security and Resilience
- Type
- article
- Field-Weighted Citation Impact
- 0.00