Post-Quantum Cryptography (PQC): Why It Matters Now

What Is Post-Quantum Cryptography?

Post-quantum cryptography (PQC) is a set of cryptographic methods designed to remain secure against the computational capabilities of quantum computers. Understanding and adopting PQC is vital for organizations to safeguard critical data, protect privacy, and maintain trust in digital systems once quantum computers become available.

Overview

Why Is Post-Quantum Cryptography Important?

Quantum computers, once they achieve cryptanalytically relevant capabilities, pose a significant threat to digital security. A sufficiently powerful quantum computer, known as a Cryptanalytically Relevant Quantum Computer (CRQC), will render most of today's public-key cryptography obsolete. This moment is often called “Q-Day” and market experts estimate it will arrive sometime between 2030 and 2035.

Sensitive data encrypted today could become vulnerable tomorrow to quantum-powered decryption. This threat has brought about concerns around "harvest now, decrypt later" (HNDL), where adversaries collect encrypted data now to decrypt it when quantum computers become available. Attacks on long-lasting data like intellectual property, government secrets, and personal health records pose the highest risk. Understanding and adopting PQC is essential for safeguarding critical data and maintaining trust in digital systems.

What’s the Impact of Quantum Computing Breaking Current Encryption Standards?

When quantum computers become powerful enough to break current public-key encryption, all existing systems reliant on RSA, ECC, and Diffie-Hellman key exchange methods will be vulnerable. Consequently, every sector will face risks of widespread data breaches and compromised systems. PQC ensures that encryption standards evolve to meet this new challenge, maintaining security in communications, transactions, and identities.

Post-Quantum Cryptography vs. Quantum Cryptography

Though their names are similar, post-quantum cryptography (PQC) and quantum cryptography describe different concepts:

Aspect Post-Quantum Cryptography (PQC) Quantum Cryptography (e.g., QKD)
Core Idea Quantum-resistant math algorithms on classical systems Quantum-physics-based techniques for exchanging keys
Hardware Needs Runs on existing CPUs; may need tuning Requires specialized quantum optics hardware
Where it Fits Replaces/augments RSA/ECC/DH in various technologies Typically complements classical crypto
Scalability Internet-scale deployment via software upgrades Limited due to physical constraints
Key Trade-Offs Larger keys/signatures, integration/testing effort Attenuation limits, higher cost

Quantum Computing Threats

Quantum computing can solve complex problems much faster than classical computers, threatening traditional public-key encryption systems. This can expose sensitive information across sensitive communications and digital infrastructure. As quantum computing advances, transitioning to quantum-resistant cryptography becomes urgently necessary to mitigate these risks.

What Steps Should Organizations Take for a Successful Transition to Quantum Computing?

Organizations should take the following steps to start preparing for PQC:

Plan and adopt a quantum-safe strategy

Use a hybrid cryptography approach, pairing quantum-resistant algorithms with existing ones, to maintain security. Monitor standards and select PQC algorithms recommended by regulatory bodies.

Inventory cryptographic-dependent assets

Document algorithms, keys, and protocols in use, prioritizing critical assets for transitioning to quantum-safe options. Identify which systems relying on public-key cryptography are quantum-vulnerable.

Implement PQC key exchange

Replace current key exchange mechanisms with new algorithms designed for a PQC environment.

Implement PQC algorithms

As PQC standards evolve, begin transitioning to PQC-based certificates and enhancing performance through optimization techniques.

Regulatory and Compliance Mandates

Governments are establishing frameworks regarding PQC, with NIST publishing its first finalized PQC standards starting in 2024. Organizations must audit their cryptographic technologies, identify risks, and plan for migrations to quantum-resistant systems.

National Security Memorandum 10 (NSM-10)

NSM-10 outlines the U.S. strategy for transitioning to PQC, emphasizing the importance of mandatory migrations and adherence to NIST standards. Agencies must immediately inventory their IT systems dependent on public-key cryptography.

NIST’s Role and Standards

NIST has finalized several PQC standards, marking significant steps toward replacing vulnerable algorithms with resistant alternatives, ensuring resilience against future threats.

For Public-Key Encryption and Key Establishment

For Digital Signatures

How Zscaler Prepares Customers for PQC

Zscaler is proactively addressing quantum computing challenges by ensuring:

FAQ

Can Existing Systems be Upgraded to Post-Quantum Cryptography?

Yes, transitioning to PQC entails significant updates, including hardware and software modifications for a secure future.

What Is the Status of PQC Development?

NIST has finalized algorithms for digital signatures and public-key encryption, advancing toward implementation.

What Types of Encryption are Considered Post-Quantum Secure?

Methods based on lattice-based, code-based, and hash-based approaches show potential for quantum resistance.

How Can Organizations Start Preparing for PQC?

Organizations should inventory cryptographic systems and prepare for strategic upgrades to quantum-resistant technologies as soon as possible.

Why Act Now if Quantum Computers Are Not Yet Capable of Breaking Current Standards?

Early proactive measures ensure a smoother transition and risk mitigation ahead of imminent quantum advancements.