Skip to main content

Write a PREreview

Identity Refined at the Quantum Gate: Framing the AI + Post-Quantum Challenge for IAM

Posted
Server
Preprints.org
DOI
10.20944/preprints202509.0090.v1

Identity & Access Management (IAM) is being reshaped by two concurrent forces: (i) the use of artificial intelligence (AI) to turn rich telemetry into policy decisions, and (ii) the migration to post-quantum cryptography (PQC) across credentials, certificates, and protocol touchpoints. We argue that the most consequential risks live in the seams—account recovery/reset, non-human identities (NHIs), and crypto-agile upgrades—where attackers concentrate and operations are fragile. This paper contributes a problem framing, a literature/practice map, and three small, reproducible experiments designed for teaching and early planning. In a simulated risk-policy study spanning sign-in and recovery, a simple risk-based control blocks more fraud than a static baseline while lowering legitimate friction; an overhead model shows modest size-driven latency from PQC artifacts on typical enterprise links; and a micro-pilot comparing passkeys to password+OTP shows faster median sign-in and higher completion with passkeys. We close with a concrete research agenda for recovery governance, machine identity attestation and rotation, crypto-agile policy engines, and explainability/appeals. All datasets are synthetic so teams can replicate results without sensitive data.

You can write a PREreview of Identity Refined at the Quantum Gate: Framing the AI + Post-Quantum Challenge for IAM. A PREreview is a review of a preprint and can vary from a few sentences to a lengthy report, similar to a journal-organized peer-review report.

Before you start

We will ask you to log in with your ORCID iD. If you don’t have an iD, you can create one.

What is an ORCID iD?

An ORCID iD is a unique identifier that distinguishes you from everyone with the same or similar name.

Start now