Pricing…Open Lab
Chapter 07 of 10 · ~30 min

Post-Quantum Cryptography: The Migration That Needs No Qubits

Post-quantum cryptography (PQC) replaces RSA and elliptic-curve schemes with new algorithms. NIST has now standardized them as ML-KEM (FIPS 203) and ML-DSA (FIPS 204). They run on ordinary computers but resist known quantum attacks. Moving to them matters now, because encrypted traffic recorded today can be decrypted later, once a large quantum computer exists. This is the one quantum-driven step most engineering teams should take this year. It needs zero quantum hardware.

Why migrate before any quantum computer can attack?

The previous chapter, quantum cryptanalysis, set out the threat. Shor's algorithm breaks RSA and elliptic curves. But it only works on a large fault-tolerant machine, which doesn't exist and isn't close. So why act now?

Because of harvest now, decrypt later. An attacker can record your encrypted traffic today. It is quiet, cheap, and hard to detect. They store it. Years from now, when the hardware arrives, they decrypt it. Encryption protects a secret only as long as the cipher stays unbroken. And the recording happens now.

An everyday example: someone photographs a locked diary today, page by page, and keeps the photos. They can't read it yet. But if they get a key in 15 years, every page they photographed opens up. Where the picture breaks: you'd notice someone photographing your diary. Recording internet traffic leaves no trace.

This changes the timeline question. The deadline that matters is not "when does a code-breaking quantum computer arrive?" It is "when does it arrive, minus how long my data must stay secret, minus how long my move to new crypto takes?" That subtraction is often called Mosca's inequality. We work it as arithmetic below. For many kinds of data, the answer is already negative.

Post-quantum cryptography is the fix. It means new public-key algorithms built on math problems with no known fast quantum attack. They run entirely on the normal hardware you already own. No qubits, no super-cold fridges, and no betting on a company's quantum roadmap. Without hype, it is the most concrete quantum-driven engineering task of this decade.

What the rest of this chapter covers
  1. What did NIST actually standardize?
  2. Worked example: how does the harvest-now-decrypt-later timeline work?
  3. Is superposition a brute-force attack?INTERACTIVE
  4. What does one Grover round really buy?INTERACTIVE
  5. Worked example: what does ML-KEM cost on the wire?
  6. What should a developer actually do this year?
  7. How much quantum hardware does PQC need?
Keep learning with Pro

You’ve read the opening of chapter 7. Pro unlocks the other 7 sections — plus every chapter of every course, with circuits you can run right on the page. That’s $11.99 a month, about the price of a coffee, or $99.99 a year (save 30%). The first chapter of every course, and the whole math course, stay free.

Start learning with ProSee plansRead chapter 1 free
Post-Quantum Cryptography: The Migration That Needs No Qubits · QPU137