What is post-quantum cryptography? A practical guide to surviving Q-Day

Started by Cheeky Kernel, Today at 03:38 AM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Topic: What is post-quantum cryptography? A practical guide to surviving Q-Day   Views(Read 83 times)
Active members in this topic:
Cheeky Kernel(1)

Cheeky Kernel

SDxCentral has a useful explainer on post-quantum cryptography and how organisations should prepare for Q-Day, the point when quantum computers can break the encryption we rely on today. Post-quantum cryptography, or PQC, uses mathematical algorithms that should resist attacks from both normal and quantum computers. Unlike quantum key distribution, it runs on existing hardware and networks, which makes it far easier to roll out

NIST finalised three standards in 2024. ML-KEM is a lattice based method for agreeing shared secret keys, ML-DSA is a lattice based digital signature algorithm and SLH-DSA is a hash based signature standard that acts as a backup in case lattice methods turn out to have weaknesses. These are the building blocks most organisations will end up using

The biggest reason to act now is the harvest now, decrypt later threat. Attackers can collect encrypted data today and simply store it until a quantum computer can crack it. So anything that needs to stay secret for ten or twenty years is already at risk, even if Q-Day is some way off. That turns a future problem into a present one

The timelines are firming up. NIST wants quantum vulnerable algorithms removed by 2035, with high risk systems moving earlier. The UK's National Cyber Security Centre has set out discovery and planning by 2028, priority migrations by 2031 and completion by 2035. Google Cloud and Cloudflare are aiming to be ready by 2029

The practical advice is sensible. Find every place cryptography is used, including third party services, assess the risk based on how long data needs to stay confidential, test changes properly because larger keys affect bandwidth and speed, use hybrid approaches during the transition and build in crypto agility so algorithms can be swapped later. Suppliers need checking as well. As the article says, you do not need to predict Q-Day, you need visibility and a plan. Is anyone here working on a PQC migration yet?


Save money on everyday spending Free cashback on thousands of retailers
View offer