What is Post-Quantum Cryptography?
Post-quantum cryptography (PQC) is a family of cryptographic algorithms designed to secure against the novel capabilities of quantum computers. While traditional encryption protects networks from adversaries today, a sufficiently powerful quantum computer could break through those defenses exponentially faster. PQC is the “digital armor” designed to protect the world of tomorrow.
A Shifting Threat Landscape
The transition to PQC and quantum-resistant algorithms is not just about the future.
Adversaries — from cybercriminals to state-sponsored actors — are already preparing to forge our critical networks and systems and steps to adopt PQC are already happening:
- The U.S. National Institute of Standards and Technology (NIST) finalized its first set of post-quantum cryptographic standards.
- NSA has established federal migration timelines, outlined in CNSSP 15, requiring all new commercial National Security Systems support the quantum-resistant Commercial National Security Algorithm (CNSA) 2.0 algorithms by 2027, with legacy systems being phased out by 2030.
Implementing PQC is no small feat. It represents one of the largest and most complex migrations in computing history. Think of it as replacing every lock in a city while it is still operating. This scale of deployment is daunting, but NSA is postured to act now and proactively defend against adversaries with growing quantum computing capabilities.
“This looming threat from our adversaries is concerning and we are prepared with swift and decisive action,” said Morgan Stern, Effort Lead for Quantum Resistance at NSA. “Quantum-resistant algorithms frequently can be implemented on the same hardware we already use, allowing us to strengthen our systems before quantum computing becomes a much larger threat.”
In this evolving cybersecurity landscape, PQC is a crucial investment. By transitioning to quantum-resistant algorithms now, we can:
- Protect Sensitive Data: Ensuring that encrypted data remains secure, even if intercepted today.
- Secure Authentication: Maintaining the integrity of authentication systems, preventing unauthorized access and protecting user identities.
- Safeguard Critical Infrastructure: Ensuring the security of systems that manage critical infrastructure.
In the rapidly evolving landscape of cybersecurity and computing, two threats — “Harvest Now, Decrypt Later” (HNDL) and “Trust Now, Forge Later” (TNFL) — underscore the urgent need for transitioning to quantum-resistant algorithms.
Harvest Now, Decrypt Later
The HNDL approach is a strategy where adversaries intercept encrypted data today and store it for future decryption at scale when quantum capabilities are available. At a high level, HNDL breaks down to three steps.
- Harvest: Adversaries collect classically encrypted information through currently available means such as compromised servers and traffic interception.
- Store: Successfully harvested data is stored for years, waiting for quantum computing capabilities to augment decryption capabilities.
- Decrypt: Once quantum computers can run decryption algorithms, data that was once secure becomes available to adversaries.
Adversaries are investing in HNDL now, racing to harvest at scale before quantum-resistant algorithms are implemented. Even if quantum computing doesn’t have the capability now, the HNDL threat remains urgent.
- Long-Term Data: Data that needs to remain secure for decades, such as national security information and financial records, is already at risk.
- Strategic Advantage: Adversaries are already planning ahead by capturing and storing encrypted data today. It is critical PQC capabilities safeguard that data.
“Transitioning to quantum-resistant algorithms today is the safeguard we need to protect against future threats,” said Stern. “Quantum computing will bring unprecedented capabilities, and we are staying vigilant and in front of any potential malicious data harvesting by the enemy.”
Trust Now, Forge Later
The TNFL approach refers to the potential compromise of digital authentication systems, which rely on cryptographic algorithms that quantum computers can easily break. TNFL attacks focus on:
- Digital Authentication: Modern systems use cryptographic algorithms to establish trust and authenticate users and devices.
- Vulnerable Algorithms: Some widely used security algorithms, such as RSA (prime numbers) or ECC (solving discrete logarithms), are vulnerable to attacks by quantum computers. Once quantum computing reaches scale, the math that currently protects data will no longer be secure.
- Quantum Future: Once quantum computing capabilities are available, adversaries exploit these vulnerabilities to gain unauthorized access to data and systems.
The foundation of digital trust relies on cryptographic signatures and certificates, making the potential for unauthorized access a significant risk to communications integrity.
“Based on the CNSA timeline, we are postured to implement quantum-resistant algorithms across our critical systems in less than 10 years,” said Stern. “This rapid transition underscores our commitment to fortifying the digital ecosystem and staying ahead of our adversaries.”
Preparing for a Quantum Future
The future of PQC is filled with promises and challenges. Quantum-proofing data today will ensure the digital foundations of the 21st Century remain protected, securing the present and the future.
NSA is proud to play a critical part in this proactive maneuver and has stood up the Post-Quantum Cryptography Resource Hub to empower others to join the effort. The hub contains a wealth of resources, including technical guidance and white papers about PQC and how to begin migration.
“Looking ahead, the adoption of PQC is not just a technical shift — it’s a strategic necessity,” said Stern. “The resources on our webpage are designed to help navigate the transition and ensure our digital infrastructure remains secure.”
NSA is also partnering with NIST and industry at NIST’s National Cybersecurity Center of Excellence, and the National Information Assurance Partnership (NIAP) is working with industry to continue developing CNSA 2.0 compliant Protection Profiles. Together, we can build a digital fortress to protect our networks in the quantum era.