What is post-quantum cryptography?
Encryption that runs on ordinary computers and is designed to resist attacks by quantum computers.
These methods rely on math problems that no known quantum algorithm solves quickly, many of them about lattices, which are regular grids of points in hundreds of dimensions. In August 2024 the US standards agency NIST published the first three standards: ML-KEM for agreeing on keys, and ML-DSA and SLH-DSA for signatures.
You may already be using it. Chrome, Signal and OpenSSH use a post-quantum method alongside a classic one for key exchange by default, so a connection stays safe if either holds.
Related
- RSAA public-key encryption method from 1977 whose security relies on how hard it is to factor the product of two large primes.
- Elliptic-curve cryptographyPublic-key cryptography based on a hard problem about points on a curve. It protects most web traffic and Bitcoin.
- Harvest now, decrypt laterRecording encrypted data today in order to decrypt it once a capable quantum computer exists.
- Q-DayThe day a quantum computer can break the public-key encryption in wide use today, such as RSA-2048 or 256-bit elliptic curves.