Cyber

Post-quantum cryptography

Family of algorithms designed to resist a cryptographically relevant quantum computer, standardised from August 2024 and whose deployment is framed by public deadlines set at 2030 then 2035.

Definition

The ambient discourse describes a machine that would break encryption, an inaccurate formulation that prevents any measurement of actual exposure. What a sufficiently powerful quantum computer would break is a precise family of algorithms, those whose security rests on factoring large integers or computing discrete logarithms. Symmetric encryption and hash functions stand in an entirely different position, the known quantum speed-up against these primitives being quadratic rather than exponential, which amounts to halving effective security and is corrected by doubling key size. The distinction moves the analysis toward what matters, key negotiation and signature, whose compromise suffices to read an entire content without ever attacking the encryption itself. Two exposures must further be separated: confidentiality is retroactively vulnerable, authenticity only prospectively.

Example

An organisation beginning migration in 2027 with a three-year horizon, and protecting data with a fifteen-year confidentiality requirement, is outside the window by simple arithmetic.

Related terms
Also known as

PQC, post-quantum cryptography, cryptographie résistante au quantique