Quantum Computing: a Challenge to Cryptography
The rise of quantum computing presents a significant threat to modern cryptographic systems. Core components of digital security—such as public key encryption, digital signatures, and key exchange protocols—rely on cryptographic schemes like the Diffie-Hellman key exchange, the RSA (Rivest-Shamir-Adleman) algorithm, and elliptic curve cryptography. The security of these systems is based on the computational difficulty of mathematical problems such as integer factorization and the discrete logarithm problem.
Quantum computers, however, are capable of efficiently solving these problems using algorithms like Shor’s algorithm, rendering current encryption methods vulnerable. It is projected that in few years a quantum computers powerful enough to break widely used cryptographic protocols could become available.
How serious is the threat?
The impact would be far-reaching. Encryption used in web browsers, email, messaging apps, VPNs, digital signatures, cryptocurrencies, and countless software systems would no longer be secure. Even symmetric encryption algorithms, such as the Advanced Encryption Standard (AES-256), would require significantly larger key sizes to maintain security against quantum attacks. (See Table 1 for reference.)
Finding Solutions: Post-Quantum Cryptography and the New Cryptographic Standards
Governments and organizations around the world—including the United States, the European Union, and Japan—are investing heavily in the development of post-quantum cryptography (PQC), also known as quantum-resistant cryptography. The goal of PQC is to create cryptographic systems that remain secure against both classical and quantum computers, while maintaining compatibility with existing communication protocols and infrastructure.
A key criterion for selecting post-quantum algorithms is that they must be based on problems that are hard to solve for both classical and quantum computers. After several years of evaluating proposals, the U.S. National Institute of Standards and Technology (NIST) has officially published three new PQC standards. Two of these are based on lattice-based cryptography, which relies on solving geometric problems in multidimensional space rather than algebraic ones. The third is based on hash functions.
NIST Post-Quantum Cryptography Standards
A. Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)
Primary Purpose: Secure key exchange over public channels; supports encryption and authentication.
B. Module-Lattice-Based Digital Signature Algorithm (ML-DSA)
Primary Purpose: Generation and verification of digital signatures.
C. Stateless Hash-Based Digital Signature Algorithm (SLH-DSA)
Primary Purpose: Ensures non-repudiation in digital communications.
D. Reality Check: Quantum and Encryption—An IT Paradox
Today, vast amounts of data are processed, transmitted, and stored under the assumption that encryption provides security. While the proposed PQC protocols offer a promising path forward, uncertainty remains about how quickly quantum computing will advance. Ironically, quantum systems are designed to solve complex problems—the very foundation on which cryptography relies to protect data. The implications are profound: without effective countermeasures, no system or data may remain secure.
What Can Organizations Now to Prepare?
In response to the looming changes in cryptography, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends the following proactive steps:
1. Stay Informed: Engage with organizations leading the development and adoption of new encryption protocols.
2. Inventory Critical Data: Identify sensitive data that could be at risk once current encryption methods are compromised.
3. Audit Cryptographic Technologies: Focus especially on systems using public key cryptography, which are most vulnerable.
4. Assess Encryption Needs: Evaluate ongoing projects and systems to ensure agility in transitioning to new cryptographic standards.
5. Establish a Cryptosystem Lifecycle: Create internal processes to regularly update cryptographic systems in line with emerging standards.
6. Engage with Vendors: Identify third-party systems and collaborate with vendors to understand their transition plans.
7. Develop a Migration Plan: Prepare a roadmap for replacing crypto-dependent systems, including priorities and timelines.
In the coming years, cryptography will remain a dynamic and rapidly evolving field. Organizations that act early and strategically will be better positioned to navigate the transition and avoid the potential chaos of a post-quantum world.
Sources:
1. The National Institute of Standardization (NIST)
2. The Cybersecurity & Infrastructure Security Agency (CISA)
3. The Economist | Post-Quantum Cryptography, August 24, 2024
4. Michigan Engineering. https://www.youtube.com/watch?v=2IyotuA8eJc
[1] NIST Preparing for Post Quantum Cryptography. Update April 10, 2025
Want to learn more about risk and information security topics that matter for your business? Subscribe to received our curated content.
©2025 S&H Management Consultants
