Understanding Post-Quantum Cryptography
Quantum computing is changing the assumptions that protect today's digital systems. Post-quantum cryptography is designed to protect information against attacks from both classical and quantum computers.
Use Tectonic Learn as an introduction, a reference alongside PQ Training, or a starting point for preparing your organization for the transition to post-quantum security.
Foundations
Cryptography Fundamentals
Cryptography is the technology used to protect information. It keeps data private, proves who sent or approved something, and detects when information has been changed.
Cryptography is everywhere. It protects websites, banking systems, software updates, cloud infrastructure, messaging apps, blockchains, government networks, and many other systems. Most modern cryptography performs one or more of four jobs:
Encryption
Turns readable information into unreadable information. Only someone with the correct key can reverse it. Primarily used to protect confidentiality.
Digital Signatures
Prove that information came from a particular key holder and has not been changed. Used for software updates, transactions, certificates, and more.
Hash Functions
Turn data into a fixed-size value. Changing even a small part of the original data normally produces a very different result. Used to check data integrity.
Key Establishment
A way for two parties to establish secret keying material across an insecure network. The shared secret can then be used with fast symmetric encryption.
Foundations
Symmetric vs. Asymmetric Cryptography
Modern systems use two broad forms of cryptography.
Symmetric Cryptography
Uses the same secret key to encrypt and decrypt. Fast and well suited to protecting large amounts of data. AES is a common example.
The main challenge is securely sharing the secret key in the first place.
Asymmetric Cryptography
Uses a pair of mathematically related keys: one public, one private. Makes it possible to establish secrets or verify signatures without sharing a secret key first.
RSA and elliptic-curve cryptography are common examples used today.
Foundations
Public and Private Keys
A public key can be shared openly. A private key should remain under the control of its owner. The two keys have different jobs depending on the cryptographic system.
Public-key cryptography is one of the foundations of the modern internet. It is also one of the areas most directly affected by future quantum computers.
Foundations
Encryption vs. Digital Signatures
Encryption and digital signatures solve different problems. Encryption protects confidentiality. Digital signatures protect authenticity and integrity. A system may use both at the same time.
Encryption | Protects Confidentiality
Digital Signatures | Protects Authenticity and Integrity
Quantum Computing
What Is a Quantum Computer?
A classical computer processes information using bits. Each bit has a value of either 0 or 1. A quantum computer uses quantum bits, called qubits. Qubits behave according to quantum mechanics and can be manipulated in ways that have no direct equivalent in normal computers.
This does not mean quantum computers are simply faster versions of classical computers. They are different machines that can provide major advantages for certain types of problems.
One of those areas is particularly important for cybersecurity: some mathematical problems used by today's public-key cryptography could become much easier to solve on a sufficiently powerful quantum computer.
Quantum Computing
Bits vs. Qubits
A classical bit is either 0 or 1. A qubit can exist in a quantum state involving both basis states before it is measured. When measured, the qubit produces a classical outcome. This allows quantum algorithms to manipulate information in fundamentally different ways.
Quantum Computing
Superposition and Entanglement
Superposition
Superposition describes the ability of a quantum system to exist in a combination of possible states. Superposition does not simply mean that a computer tries every answer and reads all of them at once. Quantum algorithms must manipulate states so that useful results become more likely when they are measured.
Entanglement
Entanglement is a quantum relationship between two or more quantum systems. When qubits are entangled, their combined state cannot always be described by treating each qubit independently. It is an important resource in many quantum algorithms. It does not allow information to be sent faster than light.
Quantum Gates
Quantum gates are operations used to change the state of qubits. They play a similar role to logic gates in classical computers but operate according to quantum mechanics.
Measurement
Measuring a qubit produces a classical result and changes the quantum state. Quantum algorithms are designed so that useful information can be extracted through measurement at the end of the computation.
Quantum Computing
Physical vs. Logical Qubits
Physical qubits are the individual qubits created by quantum hardware. They are fragile and affected by noise. A logical qubit is a more reliable quantum unit created using quantum error correction across multiple physical qubits.
Quantum error correction uses groups of physical qubits and carefully designed operations to detect and correct errors while preserving the information needed for computation.
The Quantum Threat
The Mathematical Problem
Much of today's public-key cryptography relies on mathematical problems that are extremely difficult for classical computers to solve: integer factorization, discrete logarithms, and elliptic-curve discrete logarithms.
RSA relies on the difficulty of integer factorization. Diffie-Hellman and related systems rely on discrete logarithms. Elliptic-curve cryptography relies on related problems involving elliptic curves. A sufficiently capable quantum computer running the right algorithm could solve these problems far more efficiently.
The Quantum Threat
Shor's Algorithm
Shor's algorithm can efficiently solve integer factorization and discrete logarithm problems on a sufficiently powerful fault-tolerant quantum computer. Cryptographic systems potentially affected include RSA, Diffie-Hellman, ECDH, ECC, and ECDSA.
The Quantum Threat
Grover's Algorithm
Grover's algorithm can provide a quadratic speedup when searching through an unstructured set of possibilities. Shor's algorithm can fundamentally undermine public-key systems. Grover's algorithm generally reduces the effective security margin of symmetric systems rather than making them unusable. Using sufficiently large symmetric keys can help compensate.
The Quantum Threat
What Is a Cryptographically Relevant Quantum Computer?
A cryptographically relevant quantum computer (CRQC) is powerful and reliable enough to break cryptographic systems currently considered secure. Today's quantum computers are not capable of breaking modern RSA or elliptic-curve cryptography at practical scale.
Predicting exactly when such systems will exist is difficult. That uncertainty is one reason migration needs to begin before the threat becomes practical.
The Quantum Threat
Q-Day
Q-Day is an informal term for the point at which quantum computing becomes capable of breaking important cryptographic systems used today. It is not a fixed date. The important question for organizations is not simply when Q-Day will happen. Migration itself can take years.
The Quantum Threat
Harvest Now, Decrypt Later
An attacker can collect encrypted information today and store it. If quantum computers later become capable of breaking the cryptography used, the attacker may be able to decrypt the stored data. This is known as Harvest Now, Decrypt Later, or HNDL.
Examples include government information, intellectual property, financial information, health records, strategic business information, long-lived credentials, and sensitive communications.
Post-Quantum Cryptography
What Is Post-Quantum Cryptography?
Post-quantum cryptography is cryptography designed to remain secure against both classical computers and known quantum attacks. PQC algorithms run on conventional computers. You do not need a quantum computer to use them.
PQC replaces vulnerable mathematical foundations with problems that are believed to remain difficult even for quantum computers. It is primarily focused on replacing vulnerable forms of public-key cryptography, including key establishment and digital signatures.
PQC vs. Quantum Cryptography
Post-quantum cryptography uses mathematical algorithms running on normal computers. Quantum cryptography uses properties of quantum physics as part of the communication system. PQC can be deployed through software and existing computing infrastructure.
Post-Quantum Cryptography
PQC Algorithm Families
There is no single mathematical approach to post-quantum cryptography. Researchers have developed cryptographic systems based on several different families of hard mathematical problems.
Lattice-Based
Based on difficult problems involving high-dimensional lattices. Uses concepts like Learning With Errors (LWE) where small amounts of mathematical noise make hidden values extremely hard to recover. ML-KEM and ML-DSA are lattice-based standards.
Hash-Based
Builds digital signatures using cryptographic hash functions. Hash functions have been studied for decades with well-understood security properties. One tradeoff is that signatures can be relatively large. SLH-DSA is a hash-based standard.
Code-Based
Uses difficult mathematical problems related to error-correcting codes. Turns the difficulty of decoding specially constructed problems into a security mechanism. HQC is a code-based KEM selected for standardization.
Multivariate
Based on solving systems of multivariate polynomial equations. Numerous proposed schemes have been broken during cryptanalysis, demonstrating the importance of extensive public review before trusting new constructions.
Post-Quantum Cryptography
PQC Standards
NIST has led a multi-year process to evaluate and standardize post-quantum algorithms. The first three finalized standards are ML-KEM, ML-DSA, and SLH-DSA.
ML-KEM
FIPS 203 | Lattice-Based KEM
Helps two parties establish shared secret keying material over an insecure network. Based on CRYSTALS-Kyber.
ML-DSA
FIPS 204 | Lattice-Based Signatures
Proves that information was signed by the holder of a private key and detects unauthorized changes. Based on CRYSTALS-Dilithium.
SLH-DSA
FIPS 205 | Hash-Based Signatures
Does not depend on lattice problems. Based on SPHINCS+. Provides mathematical diversity alongside lattice-based standards.
ML-KEM | Key Encapsulation | Establishing Shared Secrets
ML-DSA | Digital Signatures | Proving Authenticity
FN-DSA (derived from FALCON) is being developed as an additional lattice-based digital signature standard. HQC, a code-based key-encapsulation mechanism, has also been selected for standardization.
Migration
Where Cryptography Lives
Cryptography is rarely located in one neat part of an organization's infrastructure. PQC migration requires organizations to understand where cryptography exists before they can replace it.
TLS
HTTPS
VPNs
SSH
PKI
Digital Certificates
APIs
Databases
Cloud Services
Identity Systems
Software Signing
Hardware Modules
Payment Systems
Blockchains
IoT Devices
Migration
Cryptographic Inventory
You cannot migrate what you cannot find.
A cryptographic inventory is a record of the cryptography used across an organization. It should connect cryptography to the systems, data, dependencies, and business functions that rely on it. Building this inventory is one of the first practical steps in PQC migration.
- What cryptographic algorithms are we using, and where?
- What keys and certificates exist?
- Which applications and protocols depend on them?
- How long must protected information remain secure?
- Which systems are exposed to quantum risk?
- Which vendors or third parties are involved?
Migration
Cryptographic Agility
Cryptographic agility is the ability to change cryptographic algorithms, protocols, keys, or parameters without rebuilding an entire system. A cryptographically agile system separates applications from specific cryptographic implementations wherever practical.
PQC migration should aim to solve both today's quantum problem and tomorrow's cryptographic change problem.
Migration
PQC Migration
Moving to Post-Quantum Security
PQC migration is not a single software update. It is a process of discovering cryptographic dependencies, understanding risk, introducing new standards, testing systems, and moving production infrastructure without breaking compatibility or security.
Discover
Identify where cryptography exists: algorithms, keys, certificates, libraries, protocols, applications, devices, services, and third-party dependencies.
Assess
Understand which systems are vulnerable. Consider algorithm type, data sensitivity, required confidentiality period, system lifetime, external exposure, and regulatory requirements.
Prioritize
Focus on systems with long-lived sensitive data, long deployment cycles, critical infrastructure roles, and significant external exposure.
Design
Choose how PQC will be introduced: selecting algorithms, updating protocols, designing hybrid approaches, updating PKI, modifying APIs, and improving cryptographic agility.
Test
Test compatibility, latency, bandwidth, memory, storage, certificate sizes, hardware performance, interoperability, and security.
Deploy and Monitor
Introduce PQC into production. Track standards, algorithm updates, vulnerabilities, vendor support, new systems, and quantum computing developments.
Migration
Hybrid Cryptography
Hybrid cryptography combines classical and post-quantum cryptographic techniques. The resulting security does not depend entirely on one component alone. Hybrid approaches help organizations introduce PQC while maintaining compatibility and confidence during a transition period.
Migration
PQC Migration Challenges
PQC algorithms behave differently from many of the systems they replace. Migration creates engineering challenges as well as cryptographic ones.
Larger Keys
Some PQC algorithms use larger keys than current elliptic-curve systems, affecting storage, certificates, hardware, and protocols.
Larger Signatures
Post-quantum signatures or KEM ciphertexts can be significantly larger, affecting network traffic, blockchains, and embedded devices.
Performance
Different costs for key generation, signing, verification, encapsulation, and decapsulation. Test real workloads.
Network Constraints
Larger cryptographic objects may increase bandwidth requirements or change protocol behavior in constrained environments.
Legacy Systems
Older systems may not support new algorithms, larger keys, or updated certificate formats. Some may require substantial redesign.
Third-Party Dependencies
An organization may be ready while suppliers, vendors, or infrastructure providers are not. Coordination across ecosystems is required.
Industry
PQC Across Industries
Quantum migration affects every sector that depends on public-key cryptography.
Enterprise environments use cryptography throughout the technology stack: web servers, TLS, VPNs, identity platforms, PKI, cloud services, databases, APIs, internal applications, software signing, device management, and backups.
Government systems often protect information that must remain confidential for many years, making HNDL particularly important. Migration plans may need to account for systems with very long deployment and replacement cycles.
Financial infrastructure depends heavily on cryptography for trust. PQC migration requires coordination across networks rather than simply replacing algorithms inside one organization.
Blockchains rely heavily on public-key cryptography. Public keys and signatures may be visible permanently. Protocols may be difficult to change. Assets may remain associated with cryptographic keys for many years.
Industry
The PQC Technology Stack
Changing cryptography at one layer can affect many systems above it. PQC migration may begin at a cryptographic library but create changes across every layer above.
PQC changes enter at the cryptographic libraries layer and propagate upward through the stack.
Industry
Building a PQC Migration Program
A strong PQC program combines technical migration with organizational planning.
Ownership
Define which team or individual is responsible for cryptographic migration.
Inventory
Maintain a current view of cryptographic assets and dependencies.
Risk
Identify systems and data with the greatest quantum-related exposure.
Architecture
Build cryptographic agility into new systems.
Testing
Create environments where PQC can be tested safely.
Vendors
Understand supplier and platform migration plans.
Policies
Update internal cryptographic standards and security requirements.
Training
Ensure security, engineering, architecture, compliance, and leadership teams understand the transition.
Monitoring
Track changes in standards, implementation guidance, technology, and threats.
Next Steps
From Learning to Implementation
Understanding the concepts is the first step. Tectonic's five-day PQ Training program provides structured training across the foundations, algorithms, migration challenges, implementation, and practical application of post-quantum cryptography.
Ready to Get PQ Certified?
Participants move from understanding the quantum threat to applying PQC concepts through advanced instruction and hands-on labs.
Become PQ CertifiedReference
Become PQ Certified