What Is Post-Quantum Cryptography PQC?

Posted On 27 out 2025
By :
Comment: Off

post quantum cryptography

These developments illustrate that PQC is not a single algorithmic solution but a dynamic research frontier where mathematical innovation, hardware optimization, and implementation security converge. Lattice-based schemes, https://dominicandesign.net/license-plate-search-services-key-aspects-and-recommendations.html exemplified by Kyber and Dilithium, provide a balance of computational efficiency and security grounded in the hardness of structured lattice problems, while SPHINCS+ highlights the versatility of hash-based designs for digital signatures. Before making the selections, NIST considered not only the security of the algorithms’ underlying math, but also the best applications for them.

As researchers around the world race to build quantum computers that could break the current encryption providing security and privacy for our digital lives, NIST is helping to secure our future by developing algorithms to protect our data and systems. This finding does not affect any of NIST’s finalized PQC standards, such as ML-KEM and ML-DSA, which rely on different mathematical foundations that remain secure, and which are ready for implementation now. The HAWK development team subsequently withdrew its algorithm from consideration, and it will not be standardized or deployed. PQC algorithms are based on mathematical techniques that can be very old, such as elliptic curves, which trace their history back to ancient Greek times. Post-quantum cryptography is a defense against potential cyberattacks from quantum computers. “We encourage organizations to begin their transition to these standards immediately to ensure their data remains secure in the quantum era,” said NIST mathematician Dustin Moody, who heads the PQC standardization project.

In contrast to the threat quantum computing poses to current public-key algorithms, most current symmetric cryptographic algorithms and hash functions are considered to be relatively secure against attacks by quantum computers.

Proton was built to protect your data from the start — and from what’s coming next. This ensures post-quantum protection works between Proton and other providers, not just within Proton’s own ecosystem. Your data is protected unless an attacker simultaneously breaks both, which requires both a quantum breakthrough and a classical one. The uncertainty is precisely why the transition to post-quantum cryptography needs to start now. Scaling to the millions of physical qubits needed is an enormous engineering challenge that no institution has solved. Quantum computers will pose a significant threat to current cryptographic standards, and specifically to encryption and digital signatures.

Why is NIST leading the effort to develop PQC standards?

Active research continues on PQC integration with domain name system security extensions (DNSSEC), including fragmentation strategies for large signatures, though PQ-based signatures are not yet widely deployed in production DNSSEC (Goertzen and Stebila, 2022). Although its public keys (2,592 bytes) and signatures (3,309 bytes) are larger than those of pre-quantum schemes, ML-DSA strikes a balance between efficiency and scalability, making it well-suited for real-time applications such as blockchain-based federated learning (Li et al., 2024; Commey and Crosby, 2025). The ML-DSA (see Figure 3), formerly known as CRYSTALS-Dilithium, is a lattice-based signature scheme standardized in FIPS 204. The selected algorithms-CRYSTALS-Dilithium (ML-DSA), Falcon (FN-DSA), and SPHINCS+ (SLH-DSA)-each bring unique trade-offs in efficiency, key and signature sizes, and assurance levels, ensuring flexibility for varied deployment requirements in the emerging quantum era (Commey et al., 2025). Despite theoretical advantages and recent efficiency improvements, MPC-in-the-Head constructions continue to produce substantially larger signatures than alternative post-quantum approaches, often ranging from tens to hundreds of kilobytes, depending on the specific construction and security parameters.

When will a quantum computer appear that is powerful enough to threaten current encryption methods?

This ensures that the connection is secure as long as at least one of the algorithms remains unbroken. A hybrid approach involves using both a classical algorithm (like X25519) and a post-quantum algorithm (like ML-KEM) in a single handshake. This shift requires developers to implement new cryptographic libraries that are resistant to side-channel attacks specific to lattice operations. This increase can impact protocol handshakes, potentially leading to packet fragmentation in UDP-based protocols or increased latency in web page loads. PQC algorithms generally require larger public keys and signature sizes.

post quantum cryptography

Industry voices, including American Banker, emphasize that successful migration requires more than cryptographic substitution, demanding attention to compliance, operational costs, and international interoperability (Pape, n. d.). Hash-based signatures exhibit fundamentally different performance characteristics that reflect their conservative security approach and mathematical structure. ML-DSA provides competitive signing performance with verification times remaining under 1.2 milliseconds even for the highest security parameters, demonstrating that post-quantum digital signatures can achieve computational efficiency comparable to or exceeding classical alternatives. The performance analysis demonstrates that ML-KEM achieves remarkable computational efficiency with sub-millisecond operation times across all security levels, reflecting the mathematical elegance of lattice-based constructions and their compatibility with modern hardware architectures. The comprehensive performance analysis (see Table 2) of PQC algorithms reveals distinct computational and communication trade-offs among algorithm families that fundamentally determine their suitability for different deployment scenarios and application requirements. Unlike lattice-based approaches, SLH-DSA derives its security solely from the collision resistance of hash functions, avoiding reliance on newer hardness assumptions.

  • PQC algorithms generally require larger public keys and signature sizes.
  • Table 2 details widely available categories with respective types of hardware and software products that use PQC standards to protect sensitive information well into the foreseeable future, including after the advent of a cryptographically relevant quantum computer (CRQC).
  • Potential use-cases for SLH-DSA are those where maximum security assurance is required and performance is secondary.
  • This is to ensure that the data are not compromised even if the relatively new PQ algorithm turns out to be vulnerable to non-quantum attacks before Y2Q.

PQC schemes depart from the assumptions of classical cryptography by building on mathematical problems that remain resistant to both conventional and quantum algorithms. Other families, including multivariate and isogeny-based designs, add diversity and cautionary evidence about structural fragility, whereas MPC-in-the-Head signatures and related symmetric-primitive constructions expand the design space through zero-knowledge techniques and fine-grained engineering trade-offs. Hybrid approaches, which combine classical and post-quantum primitives, are also discussed as transitional strategies for maintaining interoperability and reducing adoption risks (Schwabe et al., 2021; Zacharopoulos, 2024).

post quantum cryptography

Why not just replace classical algorithms?

post quantum cryptography

NIST’s strategy is to recommend ML-DSA as the default signature scheme and use FN-DSA in niche applications that need its smaller signature size. Alongside ML-DSA, NIST selected FN-DSA (Fast Fourier Lattice-based Compact Signatures over NTRU) as a second lattice-based signature to be standardized (as FN-DSA in FIPS 206 and for consistency, I’ll keep calling it FN-DSA). For example, a root certificate that only signs rarely could use SLH-DSA to ensure even if all else fails, that root of trust remains secure. Potential use-cases for SLH-DSA are those where maximum security assurance is required and performance is secondary. It has no structure that has succumbed to cryptanalysis so far – in contrast, alternate signature finalists like Rainbow (multivariate equations) were badly broken before the process concluded.

Given its widespread deployment in the world, some researchers recommend expanded use of Kerberos-like symmetric key management as an efficient way to get post-quantum cryptography today. Moni Naor and Moti Yung invented UOWHF hashing in 1989 and designed a signature based on hashing (the Naor-Yung scheme) which can be unlimited-time in use (the first such signature that does not require trapdoor properties). The stateful hash-based signature scheme XMSS developed by a team of researchers under the direction of Johannes Buchmann is described in RFC 8391. There appear to be no patents on the Merkle signature schemecitation needed and there exist many non-patented hash functions that could be used with these schemes. Hash based digital signatures were invented in the late 1970s https://www.montsec.info/zero-party-data-the-structural-reset-of-privacy-and-personalization/ by Ralph Merkle and have been studied ever since as an interesting alternative to number-theoretic digital signatures like RSA and DSA.

About the Author