惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
博客园_首页
GbyAI
GbyAI
罗磊的独立博客
Y
Y Combinator Blog
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
U
Unit 42
V
Visual Studio Blog
F
Fortinet All Blogs
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
LangChain Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Engineering at Meta
Engineering at Meta
aimingoo的专栏
aimingoo的专栏
The Cloudflare Blog
T
Tor Project blog
Martin Fowler
Martin Fowler
K
Kaspersky official blog
Scott Helme
Scott Helme
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
D
DataBreaches.Net
博客园 - Franky
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
P
Proofpoint News Feed
N
Netflix TechBlog - Medium
美团技术团队
S
Secure Thoughts
C
Cisco Blogs
M
MIT News - Artificial intelligence
L
Lohrmann on Cybersecurity
T
Tenable Blog
N
News and Events Feed by Topic
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Check Point Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Spread Privacy
Spread Privacy
S
Security @ Cisco Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Security Blog
Microsoft Security Blog
A
Arctic Wolf
Hacker News - Newest:
Hacker News - Newest: "LLM"
H
Hacker News: Front Page
T
Threat Research - Cisco Blogs
Simon Willison's Weblog
Simon Willison's Weblog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
O
OpenAI News
V
Vulnerabilities – Threatpost

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is Post-Quantum Cryptography (PQC)?
Marin Ivezic · 2026-05-03 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

Post-quantum cryptography (PQC) is a family of cryptographic algorithms designed to be secure against attacks from both classical computers and quantum computers. Unlike quantum cryptography, which uses quantum physics to protect information, PQC is implemented entirely in software and runs on existing classical hardware. It is the primary replacement for the public-key algorithms (RSA, ECC, and Diffie-Hellman) that Shor’s algorithm will eventually break.

Why Current Cryptography Will Break

The public-key cryptography securing virtually all digital communications relies on mathematical problems that are extremely hard for classical computers to solve. RSA depends on the difficulty of factoring large numbers. Elliptic Curve Cryptography (ECC) depends on the discrete logarithm problem over elliptic curves. Diffie-Hellman key exchange relies on a related algebraic structure.

Shor’s algorithm, discovered by mathematician Peter Shor in 1994, solves all of these problems efficiently on a quantum computer. Once a sufficiently powerful quantum machine exists (a Cryptographically Relevant Quantum Computer, or CRQC), it could break RSA-2048, factor the elliptic curves protecting TLS connections, and compromise the Diffie-Hellman exchanges underpinning VPNs. As I detail in my analysis of how ECC became the easiest quantum target, the quantum resource estimates for breaking ECC have been dropping even faster than those for RSA. Recent research from EUROCRYPT 2026 and Google’s quantum team confirms the gap between RSA and ECC vulnerability is widening.

No CRQC exists today. The largest quantum computers operate with a few thousand noisy physical qubits, while breaking RSA-2048 requires hundreds of thousands to millions of error-corrected logical qubits. But the trajectory of resource estimates has been consistently downward, and the timeline is uncertain enough that the global cryptographic community, led by NIST and the NSA, has decided to migrate now rather than wait.

How PQC Algorithms Work Differently

PQC algorithms achieve quantum resistance by relying on mathematical problems believed to be hard for both classical and quantum computers. The approaches differ significantly in their underlying mathematics, performance characteristics, and maturity.

Lattice-based cryptography, the foundation for NIST’s primary standards, uses the difficulty of finding short vectors in high-dimensional mathematical lattices. These problems have been studied for decades with no known efficient quantum attack. Hash-based cryptography builds signatures from the well-understood security of hash functions like SHA-2 and SHA-3, offering arguably the strongest theoretical guarantees because the security depends only on the one-wayness of hash functions. The tradeoff is larger signatures. Code-based cryptography relies on the difficulty of decoding random linear codes, a problem that has resisted both classical and quantum attack since the 1970s; NIST selected HQC, a code-based algorithm, as a backup to ML-KEM specifically to provide algorithmic diversity in case lattice-based approaches encounter unexpected vulnerabilities.

Other families were explored during the NIST process. Isogeny-based approaches looked promising until SIKE, the primary candidate, was broken by a classical attack in 2022. That episode remains a useful reminder that new cryptographic assumptions require sustained scrutiny, and part of the rationale for maintaining multiple algorithmic families.

The NIST Standards

NIST’s post-quantum standardization process began in 2016 with 82 submissions. In August 2024, it reached its landmark milestone with the publication of three finalized standards. I maintain a comprehensive analysis of the NIST PQC standardization covering the full history and technical details; here is the summary.

ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism, FIPS 203, formerly CRYSTALS-Kyber) is the primary standard for key exchange and encryption. It replaces RSA and ECDH in TLS handshakes and similar key agreement protocols, and is the algorithm most organizations will deploy first.

ML-DSA (Module-Lattice-Based Digital Signature Algorithm, FIPS 204, formerly CRYSTALS-Dilithium) is the primary standard for digital signatures, replacing RSA and ECDSA in code signing, certificate issuance, and authentication. Its signatures are substantially larger than classical equivalents (roughly 2,420 bytes versus 64 bytes for P-256 ECDSA), which creates practical challenges for bandwidth-constrained systems.

SLH-DSA (Stateless Hash-Based Digital Signature Algorithm, FIPS 205, formerly SPHINCS+) is a conservative backup. Its security rests entirely on hash functions, making it the safest bet against future cryptanalytic surprises, at the cost of signatures up to roughly 50 KB depending on the parameter set.

Two additional standards are in progress. FN-DSA (FIPS 206, based on the FALCON algorithm) is in Initial Public Draft as of early 2026, with finalization expected in late 2026 or early 2027. It produces signatures of roughly 666 bytes at comparable security to ML-DSA’s 2,420 bytes, which makes it attractive for TLS certificate chains, IoT, and other bandwidth-sensitive applications. HQC, a code-based key encapsulation mechanism selected by NIST in March 2025 as a backup to ML-KEM, has a draft standard expected in 2026 and finalization in 2027.

PQC Runs on Existing Hardware

PQC does not require quantum computers or any specialized quantum hardware. These are classical algorithms running on the processors, servers, and devices organizations already own. The migration is a software, protocol, and standards challenge.

The larger key sizes and signature sizes do ripple through network protocols, certificate hierarchies, embedded systems, and any architecture designed around the compact payloads of classical cryptography. Many organizations will use hybrid cryptography during the transition, combining classical and PQC algorithms to provide defense-in-depth while the new standards accumulate real-world deployment experience.

What Organizations Need to Do

PQC migration is not a patch deployment. As I have detailed in my analysis of why this is the largest cryptographic overhaul in IT history, a large enterprise migration involves tens of thousands of discrete tasks spanning network infrastructure, application code, key management, PKI, vendor contracts, embedded systems, and operational technology.

The regulatory clock is already running. NIST’s draft IR 8547 deprecates RSA, ECDSA, EdDSA, and Diffie-Hellman for federal systems by 2030 and disallows them entirely by 2035. NSA’s CNSA 2.0 requires quantum-resistant algorithms for all new National Security System acquisitions starting January 2027. These requirements cascade through defense contractors, regulated industries, and any organization connected to government systems. In Europe, the NIS2 and DORA frameworks create parallel obligations.

As I argue throughout PostQuantum.com, the deadlines are already set. They are driven by regulators, insurers, investors, and clients, not by predictions about when a CRQC will arrive. Whether a quantum computer capable of breaking RSA exists in 2032 or 2042, the migration deadlines are locked in now.

For organizations beginning this journey, the Applied Quantum PQC Migration Framework provides a structured, open-source methodology. My practical steps guide maps the first concrete actions, and my forthcoming book Quantum Ready covers organizational readiness strategy comprehensively.

Go Deeper

This reference article covers the essentials. For deeper analysis, these PostQuantum.com articles provide the next level of detail:

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum