Quantum computing is a field of study that focuses on the development of computer-based technologies centered around quantum theory principles. To perform specific computational tasks, quantum computing employs a combination of bits. All of this is done at a much higher efficiency than their traditional counterparts. The development of quantum computers represents a significant advancement in computing capability, with massive performance gains for specific use cases.
Quantum bits, or qubits, can exist in a superposition of the 0 and 1 states simultaneously, which in turn provides much of the quantum computer’s processing power. Because of this, a sufficiently powerful quantum computer could break the asymmetric algorithms (such as RSA and ECC) underlying most public-key infrastructure in a matter of hours to days, using Shor’s algorithm. Symmetric algorithms such as AES-256 are not broken by quantum computers, only weakened, and remain secure at current key sizes.
Quantum-safe cryptography
Post-quantum cryptography, also known as quantum-safe cryptography, refers to cryptographic algorithms designed and standardized to resist attacks from both classical and quantum computers. NIST finalized its first three post-quantum standards, ML-KEM, ML-DSA, and SLH-DSA, in August 2024. The goal of these algorithms is to resist known classical and quantum cryptanalytic attacks under well-studied hardness assumptions, allowing robust security of information assets in the post-quantum world.
It is widely known that in the absence of quantum-safe cryptography, serious security issues will arise such as transmitted information through public channels could be vulnerable to eavesdropping, and encrypted data could be stored for later decryption considering the power of a quantum computer. Threats arising from quantum computing will target various sectors such as Finance and Healthcare owing to the monetary benefits majorly which can easily be derived from cryptographic vulnerabilities.
The majority of the cryptographic hashes (such as SHA2, SHA3, BLAKE2), MAC algorithms (such as HMAC and CMAK), and key-derivation functions (bcrypt, Scrypt, Argon2) are basically quantum-safe and are slightly affected by quantum computing. Symmetric ciphers such as AES-256 and Twofish-256 are also considered to be quantum-safe. In this case the recommended key length is 256-bits or more.
However, the widely used public-key cryptosystems, which include RSA, DSA, ECDSA, EdDSA, DHKE, ECDH, and ElGamal, are vulnerable to a sufficiently capable quantum computer running Shor’s algorithm, though no such machine exists today.
The following table compares the effective key strength of some popularly used cryptographic algorithms in classical and quantum computers.
| Algorithm | Key Length | Effective key strength | |
|---|---|---|---|
| Classical computer | Quantum computer | ||
| RSA-1024 | 1024-bits | 80-bits | 0-bits |
| RSA-2048 | 2048-bits | 112-bits | 0-bits |
| ECC-256 | 256-bits | 128-bits | 0-bits |
| ECC-384 | 384-bits | 256-bits | 0-bits |
| AES-128 | 128-bits | 128-bits | 64-bits |
| AES-256 | 256-bits | 256-bits | 128-bits |
Progress in Quantum-safe cryptography
The possibility of a single quantum-safe algorithm suitable for all applications is quite unlikely. Many algorithms have been proposed till date but there is a large variation observed in the performance characteristics when compared with conventional public key cryptography as quantum safe algorithms use a larger key size therefore require a higher network bandwidth.
The National Institute of Standards and Technology (NIST) ran a multi-year process to standardise quantum-safe algorithms for key agreement and digital signatures. Since 2016, the institute worked on creating quantum-safe algorithms capable of resisting threats posed by quantum computers, and in August 2024 it finalized the first three standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). A fourth signature standard, FN-DSA (FIPS 206), remains in draft.
Migration to quantum-safe cryptography
Transitioning to new cryptography is complicated and will take a significant amount of time and money. Fortunately, organisations have some time before quantum-computers are implemented on a large scale. As per NCSC, ‘Organisations that manage their own cryptographic infrastructure should factor quantum-safe transition into their long-term plans and conduct investigatory work to identify which of their systems will be high priority for transition.
Priority systems could be those that process sensitive personal data, or the parts of the public-key infrastructure that have certificate expiry dates far into the future and would be hardest to replace.’Here, crypto-agility might play a key role for organisations in transiting to quantum-safe cryptography as it the ability of a security system to switch between algorithms and cryptographic primitives without impacting the rest of the infrastructure. It is important for corporate leaders to start planning now for a smooth transition to a quantum-resistant security.
How Encryption Consulting Can Help
- Cryptographic discovery and inventory: CBOM Secure scans your environment for quantum-vulnerable algorithms, keys, and certificates, and builds a structured Cryptographic Bill of Materials so you know exactly which systems to prioritize for migration.
- PQC migration strategy: Encryption Consulting’s Post-Quantum Cryptography (PQC) Advisory Services help you build a phased migration roadmap aligned with NIST’s finalized standards (ML-KEM, ML-DSA, SLH-DSA) and your industry’s compliance deadlines.
- Hybrid and crypto-agile implementation: We help design and test hybrid cryptographic deployments that combine classical and post-quantum algorithms, so your systems stay protected during the transition without disrupting existing operations.
- Ongoing monitoring and validation: As NIST and industry standards continue to evolve, we help you track algorithm deprecations, validate implementations, and keep your cryptographic posture current.
Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Conclusion
We must recognise that quantum computing indeed poses a serious threat to conventional information security systems. Organisations are recommended to plan a robust and secure transition to quantum-safe cryptography to mitigate any quantum threats. NIST’s post-quantum standards (FIPS 203, 204, and 205) have been finalized since August 2024, so organisations should now be actively planning and executing migration to these standards rather than waiting for them.
FAQs
What is quantum-safe cryptography?
Quantum-safe cryptography, also known as post-quantum cryptography, refers to cryptographic algorithms designed and standardized to resist attacks from both classical and quantum computers. NIST finalized its first three post-quantum standards, ML-KEM, ML-DSA, and SLH-DSA, in August 2024.
Which public-key algorithms are vulnerable to quantum computers?
Widely used public-key cryptosystems, including RSA, DSA, ECDSA, EdDSA, DHKE, ECDH, and ElGamal, are vulnerable to a sufficiently capable quantum computer running Shor’s algorithm, though no such machine exists today.
Is symmetric encryption like AES also broken by quantum computers?
No. Symmetric algorithms such as AES-256 are not broken by quantum computers, only weakened, and remain secure at current key sizes.
Which NIST post-quantum standards have been finalized?
NIST finalized ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) in August 2024. A fourth signature standard, FN-DSA (FIPS 206), remains in draft.
What should organizations do to prepare for the transition?
Organizations should build a cryptographic inventory, adopt crypto-agility so algorithms can be switched between without impacting the rest of the infrastructure, and prioritize systems that process sensitive personal data or use certificates with expiry dates far into the future, since those are hardest to replace.
