Post-Quantum Extension of the Conditional CRO Trilemma: Impossibility Bounds on Confidentiality, Reliability, and Opposability Under Quantum Institutional Extraction Limits
Cryptographic evidence systems face fundamental trade-offs between confidentiality (Conf), reliability (Rel), and opposability (Opp), with Conf<inline-formula> <tex-math notation="LaTeX">$\cdot $ </tex-math></inline-formula>Rel<inline-formula> <tex-math notation="LaTeX">$\cdot $ </tex-math></inline-formula>Opp products ranging from 0.27 to 0.57 in deployed systems. The Conditional CRO Trilemma recently established that institutional capacity <inline-formula> <tex-math notation="LaTeX">$\Delta $ </tex-math></inline-formula> fundamentally constrains achievable trade-offs through the bound <inline-formula> <tex-math notation="LaTeX">$\text {Conf}\cdot \text {Rel}\cdot \text {Opp} \leq \Delta /\lambda + \mathcal {O}(\lambda ^{-2})$ </tex-math></inline-formula>. However, the imminent deployment of post-quantum cryptographic systems raises critical questions: do quantum adversaries and quantum channel effects modify these bounds? This paper presents the Post-Quantum Conditional CRO Trilemma, establishing that both institutional capacity and quantum interpretability loss fundamentally constrain achievable trade-offs. Under explicit assumptions about quantum-aware institutional limits, we prove<disp-formula> <tex-math notation="LaTeX">\begin{equation*} \text {Conf}^{q} \cdot \text {Rel}^{q} \cdot \text {Opp}^{q} \leq \frac {\Delta _{q} + \eta _{q} \cdot H(C)}{\lambda } + \mathcal {O}(\lambda ^{-2}) + \text {negl}(\lambda)\end{equation*} </tex-math></disp-formula>where <inline-formula> <tex-math notation="LaTeX">$\Delta _{q}$ </tex-math></inline-formula> quantifies the quantum-aware institutional extraction capacity, <inline-formula> <tex-math notation="LaTeX">$\eta _{q}$ </tex-math></inline-formula> is the quantum interpretability loss coefficient, <inline-formula> <tex-math notation="LaTeX">$H(C)$ </tex-math></inline-formula> is the contextual entropy, and <inline-formula> <tex-math notation="LaTeX">$\lambda $ </tex-math></inline-formula> is the security parameter. Our main contributions are as follows: 1) a quantum extension of the institutional capacity model with parameters <inline-formula> <tex-math notation="LaTeX">$\Delta _{q}$ </tex-math></inline-formula> and <inline-formula> <tex-math notation="LaTeX">$\eta _{q}$ </tex-math></inline-formula>; 2) complete information-theoretic proofs using Quantum Pinsker’s inequality, the Gentle Measurement Lemma, and quantum Fano bounds; 3) an internal coherence analysis showing that NIST PQC finalists (Dilithium, Kyber, and SPHINCS+) imply <inline-formula> <tex-math notation="LaTeX">$\Delta _{q} \in [{28, 67}]$ </tex-math></inline-formula> bits under quantum adversaries, consistent with quantum-aware bounded rationality; and 4) a framework for matching post-quantum protocols to quantum-aware institutional capacity. We demonstrate the internal coherence of our framework against the same deployed systems analyzed in the Conditional CRO work, Helios voting, zk-SNARKs compliance, and ECDSA signatures, showing how quantum effects modify their implied institutional capacities. This trilemma shifts post-quantum protocol design from purely computational security to quantum-constraint-aware engineering, with applications to GDPR-compliant quantum-safe systems and eIDAS quantum readiness.