How to Prepare for Post-Quantum Cryptography

TL;DR
Organizations should begin by discovering where and how cryptography is used, then test the post-quantum algorithms selected through NIST’s standardization process. Migration cannot happen with a simple switch, and delaying preparation increases exposure to adversaries who may record encrypted information now and decrypt it later when large-scale quantum computers become available.
Transcript
Uh, thank you so much for, for joining us today. Um, we're excited, uh, to be here. I'm gonna go through... Let's see if we can get the clicker going here. Is our standard disclaimer for ISA. And, um, before we get started, just a little bit about, uh, SafeCode before we do introductions. Uh, SafeCode is a nonprofit formed in two thousand and seven... Read More
Key Insights
- Quantum computing is a threat to current public key cryptography because it could make the underlying mathematical problems much easier to solve. A sufficiently capable quantum computer would put cryptography-based protections for systems, devices, and Internet communications at risk.
- Recorded encrypted data is vulnerable to future decryption because an adversary can capture information today and retain it until quantum computing capabilities improve. This possibility creates urgency even before a large-scale quantum computer exists, especially when protected information must remain confidential for many years.
- Post-quantum migration is an incremental process because existing cryptography cannot be replaced with a simple flip of a switch. Organizations need to prepare before standards and products complete the transition, beginning with understanding where cryptography exists and how their systems use it.
- NIST’s post-quantum project is a worldwide cryptographic evaluation process that began accepting candidate algorithms around 2016. Approximately 82 submissions were received, 69 met the stated requirements, and complete specifications were published so researchers worldwide could analyze, benchmark, and attempt to break them.
- Security is NIST’s foremost selection criterion because new cryptosystems must protect information for several decades against known classical attacks and future quantum attacks. Performance is the second major criterion, including key sizes, signature sizes, implementation speed, and operation on both high-end and low-end software.
- Public cryptanalysis is central to NIST’s evaluation because researchers outside NIST were invited to examine every published candidate. About 15 algorithms were broken within the first few weeks, demonstrating why broad scrutiny and multiple evaluation rounds are necessary before adopting new cryptographic standards.
- Structured lattice schemes are the primary mathematical approach among most finalists discussed by NIST. Their keys are somewhat larger than those used with RSA and elliptic curve cryptography, but their implementations are described as fast and efficient without causing slowdowns.
- Cryptographic discovery is the first practical migration phase because organizations must identify where cryptography resides and how it is used. NIST’s National Cybersecurity Center of Excellence planned a migration project focused initially on this discovery work and on demonstrating capabilities through real-world scenarios.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: Why should organizations prepare for post-quantum cryptography now?
Organizations should prepare now because a large-scale quantum computer could break public key algorithms used to protect systems, devices, and Internet communications. Migration will require incremental work rather than a simple switch. Adversaries may also record encrypted information today and preserve it for future decryption, so waiting until quantum computers exist could be too late for long-lived confidential data.
Q: What cryptographic algorithms could quantum computers break?
The public key algorithms identified as vulnerable include RSA, elliptic curve cryptography, and Diffie-Hellman. These technologies support functions such as digital signatures, public key encryption, and key establishment. NIST’s post-quantum cryptography project aims to standardize resistant replacements that can protect information against attacks from both conventional computers and future large-scale quantum computers.
Q: How did NIST evaluate post-quantum cryptography candidates?
NIST published complete candidate specifications and evaluated the algorithms internally while inviting cryptographers worldwide to analyze their security, performance, and implementations. Security was the leading criterion, followed by factors such as key sizes, signature sizes, and execution speed on high-end and low-end software. Candidates then progressed through several rounds, with promising representatives from different mathematical families advancing.
Q: How many algorithms entered the NIST post-quantum process?
NIST received approximately 82 submissions from around the world, and 69 met the requirements established for the project. During the first few weeks of public examination, researchers broke about 15 candidates. NIST later advanced the most promising algorithms from different mathematical families, reducing the field to 26 candidates in the second round before conducting further evaluation and selection.
Q: What was the difference between NIST finalists and alternates?
Finalists were candidates that NIST considered most likely to be ready for standardization at the end of the third round and suitable for most use cases. Alternates remained of interest but were expected to require more evaluation time, or their standardization was considered less urgent. Some continuing candidates could advance into a fourth evaluation round and potentially be standardized afterward.
Q: What are the performance characteristics of lattice-based cryptography?
Structured lattices were the primary mathematical technique used by most of the finalists discussed in the presentation. Their key sizes are somewhat larger than those associated with RSA and elliptic curve cryptography. Despite that difference, the lattice-based schemes were described as very efficient and fast when implemented, with the expectation that they would not cause system slowdowns.
Q: What is the first step in preparing for post-quantum migration?
The first practical step is cryptographic discovery, which means determining where cryptography exists throughout an organization and how it is being used. This inventory provides the foundation for planning replacements and testing candidate algorithms. The National Cybersecurity Center of Excellence migration project was expected to begin with these discovery activities and connect NIST’s research and standards work to real-world scenarios.
Q: When did NIST expect its first post-quantum standards?
At the time of the discussion, NIST expected to publish its first post-quantum cryptography standards around 2024 as Federal Information Processing Standards or special publications. Before publication, NIST planned to announce which algorithms it would standardize for digital signatures and for public key encryption or key establishment. Organizations were encouraged to examine and test the selected algorithms before the transition was complete.
Summary & Key Takeaways
-
Quantum computers could break widely used public key cryptography by making currently difficult mathematical problems easier to solve. Systems, devices, and Internet communications that depend on asymmetric algorithms are therefore at risk. Organizations must also consider adversaries recording encrypted information today with the intention of decrypting it after suitable quantum computers become available.
-
NIST launched a worldwide post-quantum cryptography competition around 2016. Of roughly 82 submissions, 69 met its requirements. Security was the foremost evaluation criterion, followed by performance factors such as key sizes, signature sizes, execution speed, and suitability for both high-end and low-end software. Public evaluation and cryptanalysis accompanied NIST’s internal review.
-
NIST advanced candidates through multiple evaluation rounds and expected to publish its first post-quantum standards around 2024. The selected algorithms would address digital signatures, encryption, and key establishment, replacing vulnerable technologies such as RSA, elliptic curve cryptography, and Diffie-Hellman. Organizations were encouraged to inventory cryptography, examine candidate algorithms, and begin practical testing.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator