Exceptional Access Risk Analysis
Abstract
Lawful exceptional access (EA) systems hold the cryptographic keys that let authorised parties decrypt protected communications. The debate over their risks has been long and qualitative, and it is complicated by two problems: no public dataset of EA-specific compromise events exists, so risk assessment must proceed from sparse and indirect evidence, and prior work has treated structurally different designs as equivalent, although transmission-layer EA in carrier infrastructure (T-EA) and over-the-top EA at the platform layer (OTT-EA) differ in how cryptographic keys relate to ciphertext data. This paper builds a structured uncertainty framework for evaluating systemic compromise risk in EA architectures. It does not produce predictive forecasts, which the available evidence cannot support; it separates findings robust to assumption choices from findings that depend on calibration. Four analytical layers are applied in parallel to T-EA and OTT-EA: three empirical pillars (historical analogues, a Monte Carlo scenario layer, and a channel-independence decomposition) plus a Bayesian Structural Risk Model on a parallel-subgraph attack graph. The central findings are structural. First, EA-equipped architectures of either class carry strictly higher modelled risk than their no-EA counterfactual, an ordering independent of calibration. Second, the classes differ in distribution shape: T-EA risk is dominated by central tendency, OTT-EA by the tail under correlated campaigns, a divergence driven by the cross-cutting coupling prior. Third, calibration-conditional annual probability ranges span 1.4% to 12.9% for T-EA across the 3–15 structured-judgement targeting-premium interval, with FrchetHoeffding intervals of [2.2%, 7.5%] for T-EA and [1.1%, 4.0%] for OTT-EA under any dependence structure, conditional on the Pillar II per-scenario probabilities. Over multi-decade horizons, cumulative compromise is well above zero, and key-material exfiltration is irreversible, an asymmetry weighing heavily on OTT-EAs larger user populations. The framework quantifies compromise probability, not expected harm; consequence modelling and benefit estimation are outside its scope.