惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Security Archives - TechRepublic
Security Archives - TechRepublic
I
InfoQ
阮一峰的网络日志
阮一峰的网络日志
云风的 BLOG
云风的 BLOG
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
AWS News Blog
AWS News Blog
S
SegmentFault 最新的问题
T
Tailwind CSS Blog
The Hacker News
The Hacker News
GbyAI
GbyAI
P
Palo Alto Networks Blog
博客园 - 三生石上(FineUI控件)
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Cyberwarzone
Cyberwarzone
H
Help Net Security
S
Securelist
月光博客
月光博客
博客园 - 【当耐特】
T
Threatpost
T
Tenable Blog
G
GRAHAM CLULEY
博客园 - 司徒正美
I
Intezer
MyScale Blog
MyScale Blog
T
Threat Research - Cisco Blogs
P
Privacy & Cybersecurity Law Blog
The GitHub Blog
The GitHub Blog
C
CERT Recently Published Vulnerability Notes
T
Tor Project blog
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
罗磊的独立博客
腾讯CDC
P
Privacy International News Feed
博客园_首页
The Cloudflare Blog
Cisco Talos Blog
Cisco Talos Blog
A
About on SuperTechFans
V
Vulnerabilities – Threatpost
A
Arctic Wolf
B
Blog RSS Feed
Recorded Future
Recorded Future
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News
S
Security Affairs
Microsoft Security Blog
Microsoft Security Blog
L
LangChain Blog

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is Grover's Algorithm?
Marin Ivezic · 2026-05-04 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

Grover’s algorithm is a quantum algorithm that searches an unstructured database quadratically faster than any classical algorithm. In cryptographic terms, this means it can find a symmetric encryption key in roughly the square root of the number of attempts a classical brute-force attack would require. The practical effect: it halves the effective security of symmetric ciphers and hash functions. AES-256 drops to roughly 128-bit equivalent security. AES-128 drops to 64-bit equivalent, which is no longer considered secure.

How It Works (Without the Math)

Classical brute-force key search is straightforward: try every possible key until one works. For a 256-bit key, that means trying up to 2²⁵⁶ combinations, a number so large that no classical computer could exhaust it before the heat death of the universe.

Grover’s algorithm exploits quantum superposition and interference to search this space more efficiently. Instead of checking keys one at a time, it evaluates many possibilities in parallel through quantum superposition, then uses a technique called amplitude amplification to progressively increase the probability of measuring the correct key. After roughly √N operations (where N is the total number of possibilities), the correct key emerges with high probability.

For AES-256, this means roughly 2¹²⁸ quantum operations instead of 2²⁵⁶ classical ones. For AES-128, it means 2⁶⁴ quantum operations instead of 2¹²⁸ classical ones. That distinction matters enormously. 2¹²⁸ operations remains computationally infeasible even on a quantum computer. 2⁶⁴ operations is within reach.

Why It Is Less Urgent Than Shor’s

Shor’s algorithm breaks public-key cryptography entirely. A quantum computer running Shor’s does not merely weaken RSA or ECC; it renders them worthless. The security drops from computationally infeasible to trivially solvable.

Grover’s effect is gentler. It degrades symmetric security by a factor of two in the exponent, which means the mitigation is correspondingly simple: use longer keys. AES-256 already provides a sufficient security margin against Grover’s. This is why NIST’s PQC security categories use AES-128 (Category 1) and AES-256 (Category 5) as reference benchmarks for post-quantum security levels.

The organizational implication is clear. If your symmetric encryption already uses AES-256, the quantum threat from Grover’s is managed. If you are still running AES-128 in any critical system, that should be upgraded regardless of quantum timelines, since 64-bit effective security is inadequate against well-resourced adversaries even without a quantum computer.

Why “Just Double Your Key Lengths” Is Almost Right

The advice to double symmetric key lengths as a quantum countermeasure is accurate in principle and insufficient in practice, for reasons I explore in my analysis of why “just ignore Grover’s” is almost right.

The first complication is that Grover’s algorithm requires a fault-tolerant quantum computer with enough qubits to implement the cipher as a reversible quantum circuit. For AES-256, this means constructing the entire AES block cipher inside a quantum computer, which demands substantial qubit resources and long coherence times. The practical overhead makes a Grover’s attack on AES-256 far more expensive than the simple 2¹²⁸ operation count suggests. Some researchers have estimated that a Grover’s search against AES-256 would require a quantum computer so large and running for so long that it may never be economically rational.

The second complication involves hash functions. Grover’s algorithm also applies to finding preimages and collisions in hash functions, though the impact differs. Preimage resistance of SHA-256 drops from 256 bits to 128 bits (still secure). Collision resistance is affected by a related quantum algorithm, the Brassard-Høyer-Tapp (BHT) algorithm, which provides a cube-root speedup for collision finding. SHA-256’s collision resistance drops from 128 bits (by the birthday bound) to roughly 85 bits under BHT, which is marginal. For applications requiring long-term collision resistance, SHA-384 or SHA-512 provides additional margin.

The third complication is that the “double your key length” advice focuses on the algorithm in isolation, ignoring the protocol and implementation. A protocol that uses AES-256 for data encryption but relies on ECDH for key agreement is not quantum safe: Shor’s breaks the key agreement, and the strength of the symmetric cipher becomes irrelevant. Grover’s is only the secondary threat; fixing it without fixing the Shor’s vulnerability accomplishes nothing.

What Security Leaders Should Take Away

Grover’s algorithm is real and relevant, but it does not demand the same urgency as Shor’s. The migration priority for any organization is post-quantum cryptography for public-key systems. The symmetric side requires verification (confirm AES-256 is deployed everywhere it matters, upgrade AES-128 where it persists) rather than wholesale replacement.

NIST’s PQC standards address the Shor’s threat. AES-256 addresses the Grover’s threat. Together, they constitute a quantum-safe posture for symmetric and asymmetric cryptography.

Go Deeper

What Is Shor’s Algorithm? — the more urgent quantum cryptographic threat

Grover’s Algorithm and Its Impact on Cybersecurity — full technical deep dive

Grover’s Algorithm vs AES: Why “Ignore It” Is Almost Right — detailed analysis of the practical threat

Brassard-Høyer-Tapp (BHT) Quantum Collision Algorithm — the quantum threat to hash functions

NIST PQC Security Strength Categories (1–5) — how NIST benchmarks post-quantum security

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum