Glossary
Post-Quantum Cryptography

Post-Quantum Cryptography

Alex Khazanovich

An HTTPS connection can last seconds while the information it carries must stay confidential for years. That difference makes quantum resistance relevant to the cryptographic choices you make today.

Key Takeaways

  • PQC runs on ordinary computers and replaces vulnerable public-key mechanisms.
  • Prioritize long-lived secrets, and verify key exchange separately from authentication.

What Is Post-Quantum Cryptography?

Post quantum cryptography (PQC) uses mathematical algorithms designed to withstand attacks from both conventional and quantum computers. You deploy it through compatible software and hardware, without needing quantum equipment.

PQC covers key establishment and digital signatures. In Transport Layer Security (TLS), symmetric ciphers still encrypt application data; post-quantum mechanisms help establish shared keys and authenticate participants.

{{cool-component}}

Why Quantum Computers Break Today's Encryption

RSA relies on factoring large integers; Diffie-Hellman and elliptic-curve cryptography rely on discrete logarithms. A sufficiently capable future quantum computer running Shor's algorithm could solve these problems, compromising key exchange and signatures. For vulnerable key exchanges, recorded public handshake values could reveal the shared secret later, even when ephemeral keys were erased. AES is not broken by that same attack.

The harvest now decrypt later threat involves recording encrypted information today for future decryption. Your immediate exposure depends partly on how long that information must remain secret.

The Main Post-Quantum Algorithm Families

Lattice cryptography uses hard problems on high-dimensional grids of points, including recovering secret values from equations with added noise. Hash-based signatures rely on cryptographic hash functions; code-based schemes use error-correcting codes. These families provide different security assumptions and performance characteristics.

AlgorithmFamilyRoleNIST Status
ML-KEMLattice-basedKey establishmentFinal FIPS 203
ML-DSALattice-basedDigital signaturesFinal FIPS 204
SLH-DSAHash-basedDigital signaturesFinal FIPS 205
HQCCode-basedKey establishmentSelected for standardization

ML-KEM establishes a shared secret for symmetric encryption. Neither signature algorithm encrypts your payload, and HQC is not one of those three final standards.

What Crypto Agility Means and Why It Matters for PQC Migration

Crypto agility means you can replace cryptographic algorithms while preserving security and service continuity. It matters because migration involves dependencies and evolving implementations, not just selecting an algorithm.

NIST's National Cybersecurity Center of Excellence emphasizes cryptographic discovery and interoperability testing. I'd start with:

  • Inventory libraries, certificates, and TLS termination points, recording owners and upgrade paths.
  • Rank systems by data lifetime and exposure, then test changes with representative clients.

Keep algorithm choices configurable through supported interfaces. Stage deployments and define rollback criteria without silently abandoning required protection.

{{cool-component}}

How PQC Affects CDN and TLS Infrastructure

A content delivery network (CDN) typically terminates TLS at its edge and creates another connection to your origin. Hybrid TLS key exchange combines classical and post-quantum mechanisms, such as X25519 and ML-KEM. It does not automatically upgrade certificate signatures.

Treat browser-to-CDN and CDN-to-origin handshakes independently when assessing CDN security risks. Inventory each connection and verify the negotiated algorithms, including internal hops where visible. Edge support alone proves nothing about origin protection.

When evaluating CDN security solutions, check actual client and provider compatibility. Larger handshake messages can span additional packets, so measure connection failures and latency under realistic network conditions.

Conclusion

Prioritize information that must stay confidential longest. Use standardized algorithms for their intended roles, preserve crypto agility, and validate each TLS connection before expanding your rollout.

FAQs

When Can Quantum Computers Realistically Break Current Encryption?

No reliable date is established. Breaking deployed RSA or elliptic-curve systems requires sufficiently powerful, fault-tolerant quantum computers, not simply a larger advertised qubit count. Plan around your data's confidentiality lifetime and the time migration takes rather than treating any predicted year as a dependable deadline.

How Does Quantum Cryptography Differ From Post-Quantum Cryptography?

Quantum cryptography uses quantum physical effects. Quantum key distribution, for example, requires specialized equipment to distribute key material. Post-quantum cryptography instead uses mathematical algorithms on ordinary computers. You can adopt PQC through compatible cryptographic software without deploying a quantum communication channel or quantum key distribution hardware.

How Does Post-Quantum Cryptography Affect TLS Certificate Management?

Hybrid key exchange can operate with conventional certificates, so enabling it does not make authentication quantum-resistant. Certificate migration requires compatible signature algorithms across issuing authorities, certificate chains, and clients. Update your inventory and automation, then test issuance, renewal, and validation before replacing certificates in production.

Which NIST Post-Quantum Standards Should Teams Prioritize First?

Prioritize ML-KEM under FIPS 203 for key establishment, particularly where recorded traffic contains long-lived secrets. Plan ML-DSA under FIPS 204 for signatures; evaluate SLH-DSA under FIPS 205 when hash-based signatures suit your requirements. Deployment order should reflect protocol support and risk, rather than treating these algorithms as interchangeable.

Does Post-Quantum Encryption Increase TLS Handshake Latency?

It can, but there is no universal penalty. Larger key shares increase transmitted bytes and may require additional packets; negotiation retries can add a round trip. Actual results depend on implementations and network conditions. Compare handshake latency and failure rates with your existing configuration under representative traffic.

‍

Published on:
October 3, 2026

Related Glossary

See All Terms
This is some text inside of a div block.