Understanding Post-Quantum Cryptography

Quantum computing is changing the assumptions that protect today's digital systems. Post-quantum cryptography is designed to protect information against attacks from both classical and quantum computers.

Use Tectonic Learn as an introduction, a reference alongside PQ Training, or a starting point for preparing your organization for the transition to post-quantum security.

Cryptography Fundamentals

Cryptography is the technology used to protect information. It keeps data private, proves who sent or approved something, and detects when information has been changed.

Cryptography is everywhere. It protects websites, banking systems, software updates, cloud infrastructure, messaging apps, blockchains, government networks, and many other systems. Most modern cryptography performs one or more of four jobs:

Encryption

Turns readable information into unreadable information. Only someone with the correct key can reverse it. Primarily used to protect confidentiality.

Digital Signatures

Prove that information came from a particular key holder and has not been changed. Used for software updates, transactions, certificates, and more.

Hash Functions

Turn data into a fixed-size value. Changing even a small part of the original data normally produces a very different result. Used to check data integrity.

Key Establishment

A way for two parties to establish secret keying material across an insecure network. The shared secret can then be used with fast symmetric encryption.

How Cryptography Protects Information Sender Encryption / Decryption Receiver

Symmetric vs. Asymmetric Cryptography

Modern systems use two broad forms of cryptography.

Symmetric Cryptography

Uses the same secret key to encrypt and decrypt. Fast and well suited to protecting large amounts of data. AES is a common example.

The main challenge is securely sharing the secret key in the first place.

Asymmetric Cryptography

Uses a pair of mathematically related keys: one public, one private. Makes it possible to establish secrets or verify signatures without sharing a secret key first.

RSA and elliptic-curve cryptography are common examples used today.

Public and Private Keys

A public key can be shared openly. A private key should remain under the control of its owner. The two keys have different jobs depending on the cryptographic system.

Public-key cryptography is one of the foundations of the modern internet. It is also one of the areas most directly affected by future quantum computers.

Public and Private Key Relationship Public Key | Shareable Private Key | Secret Mathematically Linked

Encryption vs. Digital Signatures

Encryption and digital signatures solve different problems. Encryption protects confidentiality. Digital signatures protect authenticity and integrity. A system may use both at the same time.

Encryption | Protects Confidentiality

Readable Data → Encrypt with Key → Encrypted Data → Transit / Storage → Decrypt with Key → Readable Data

Digital Signatures | Protects Authenticity and Integrity

Document → Sign with Private Key → Signature Created → Transmitted → Verify with Public Key → Valid / Invalid

What Is a Quantum Computer?

A classical computer processes information using bits. Each bit has a value of either 0 or 1. A quantum computer uses quantum bits, called qubits. Qubits behave according to quantum mechanics and can be manipulated in ways that have no direct equivalent in normal computers.

This does not mean quantum computers are simply faster versions of classical computers. They are different machines that can provide major advantages for certain types of problems.

One of those areas is particularly important for cybersecurity: some mathematical problems used by today's public-key cryptography could become much easier to solve on a sufficiently powerful quantum computer.

Bits vs. Qubits

A classical bit is either 0 or 1. A qubit can exist in a quantum state involving both basis states before it is measured. When measured, the qubit produces a classical outcome. This allows quantum algorithms to manipulate information in fundamentally different ways.

Classical Bit vs. Quantum Qubit Classical Bit |1⟩ |0⟩ Qubit | Bloch Sphere |1⟩ |0⟩ State Vector

Superposition and Entanglement

Superposition

Superposition describes the ability of a quantum system to exist in a combination of possible states. Superposition does not simply mean that a computer tries every answer and reads all of them at once. Quantum algorithms must manipulate states so that useful results become more likely when they are measured.

Entanglement

Entanglement is a quantum relationship between two or more quantum systems. When qubits are entangled, their combined state cannot always be described by treating each qubit independently. It is an important resource in many quantum algorithms. It does not allow information to be sent faster than light.

Quantum Gates

Quantum gates are operations used to change the state of qubits. They play a similar role to logic gates in classical computers but operate according to quantum mechanics.

Measurement

Measuring a qubit produces a classical result and changes the quantum state. Quantum algorithms are designed so that useful information can be extracted through measurement at the end of the computation.

Physical vs. Logical Qubits

Physical qubits are the individual qubits created by quantum hardware. They are fragile and affected by noise. A logical qubit is a more reliable quantum unit created using quantum error correction across multiple physical qubits.

Quantum error correction uses groups of physical qubits and carefully designed operations to detect and correct errors while preserving the information needed for computation.

Physical Qubits Forming a Logical Qubit Logical Qubit Physical Qubit Physical Qubit

The Mathematical Problem

Much of today's public-key cryptography relies on mathematical problems that are extremely difficult for classical computers to solve: integer factorization, discrete logarithms, and elliptic-curve discrete logarithms.

RSA relies on the difficulty of integer factorization. Diffie-Hellman and related systems rely on discrete logarithms. Elliptic-curve cryptography relies on related problems involving elliptic curves. A sufficiently capable quantum computer running the right algorithm could solve these problems far more efficiently.

Shor's Algorithm

Shor's algorithm can efficiently solve integer factorization and discrete logarithm problems on a sufficiently powerful fault-tolerant quantum computer. Cryptographic systems potentially affected include RSA, Diffie-Hellman, ECDH, ECC, and ECDSA.

Systems Vulnerable to Shor's Algorithm
RSA ECC ECDSA ECDH DH → Quantum Computer + Shor's Algorithm → Broken

Grover's Algorithm

Grover's algorithm can provide a quadratic speedup when searching through an unstructured set of possibilities. Shor's algorithm can fundamentally undermine public-key systems. Grover's algorithm generally reduces the effective security margin of symmetric systems rather than making them unusable. Using sufficiently large symmetric keys can help compensate.

Classical Search vs. Grover's Quantum Speedup Classical | Linear Quantum | Converging Target

What Is a Cryptographically Relevant Quantum Computer?

A cryptographically relevant quantum computer (CRQC) is powerful and reliable enough to break cryptographic systems currently considered secure. Today's quantum computers are not capable of breaking modern RSA or elliptic-curve cryptography at practical scale.

Predicting exactly when such systems will exist is difficult. That uncertainty is one reason migration needs to begin before the threat becomes practical.

Q-Day

Q-Day is an informal term for the point at which quantum computing becomes capable of breaking important cryptographic systems used today. It is not a fixed date. The important question for organizations is not simply when Q-Day will happen. Migration itself can take years.

Q-Day Timeline
OMB M-23-02 (2023)
NIST PQC Standards (2024)
Today (2026)
PQC Migration Period
NSA CNSA 2.0 Target (2035)
Q-Day (Unknown)
Could arrive at any point

Harvest Now, Decrypt Later

An attacker can collect encrypted information today and store it. If quantum computers later become capable of breaking the cryptography used, the attacker may be able to decrypt the stored data. This is known as Harvest Now, Decrypt Later, or HNDL.

Examples include government information, intellectual property, financial information, health records, strategic business information, long-lived credentials, and sensitive communications.

HNDL Attack Model
Encrypted Data Today → Intercepted and Stored → Future Quantum Computer → Data Decrypted

What Is Post-Quantum Cryptography?

Post-quantum cryptography is cryptography designed to remain secure against both classical computers and known quantum attacks. PQC algorithms run on conventional computers. You do not need a quantum computer to use them.

PQC replaces vulnerable mathematical foundations with problems that are believed to remain difficult even for quantum computers. It is primarily focused on replacing vulnerable forms of public-key cryptography, including key establishment and digital signatures.

PQC vs. Quantum Cryptography

Post-quantum cryptography uses mathematical algorithms running on normal computers. Quantum cryptography uses properties of quantum physics as part of the communication system. PQC can be deployed through software and existing computing infrastructure.

PQC Algorithm Families

There is no single mathematical approach to post-quantum cryptography. Researchers have developed cryptographic systems based on several different families of hard mathematical problems.

Lattice-Based

Based on difficult problems involving high-dimensional lattices. Uses concepts like Learning With Errors (LWE) where small amounts of mathematical noise make hidden values extremely hard to recover. ML-KEM and ML-DSA are lattice-based standards.

Hash-Based

Builds digital signatures using cryptographic hash functions. Hash functions have been studied for decades with well-understood security properties. One tradeoff is that signatures can be relatively large. SLH-DSA is a hash-based standard.

Code-Based

Uses difficult mathematical problems related to error-correcting codes. Turns the difficulty of decoding specially constructed problems into a security mechanism. HQC is a code-based KEM selected for standardization.

Multivariate

Based on solving systems of multivariate polynomial equations. Numerous proposed schemes have been broken during cryptanalysis, demonstrating the importance of extensive public review before trusting new constructions.

Lattice-Based Cryptography Target Point Start Point Highlighted Path

PQC Standards

NIST has led a multi-year process to evaluate and standardize post-quantum algorithms. The first three finalized standards are ML-KEM, ML-DSA, and SLH-DSA.

ML-KEM

FIPS 203 | Lattice-Based KEM

Helps two parties establish shared secret keying material over an insecure network. Based on CRYSTALS-Kyber.

ML-DSA

FIPS 204 | Lattice-Based Signatures

Proves that information was signed by the holder of a private key and detects unauthorized changes. Based on CRYSTALS-Dilithium.

SLH-DSA

FIPS 205 | Hash-Based Signatures

Does not depend on lattice problems. Based on SPHINCS+. Provides mathematical diversity alongside lattice-based standards.

ML-KEM | Key Encapsulation | Establishing Shared Secrets

Generate Keys → Encapsulate with Public Key → Ciphertext → Decapsulate with Private Key → Shared Secret (Both Sides)

ML-DSA | Digital Signatures | Proving Authenticity

Generate Keys → Sign with Private Key → Signature → Verify with Public Key → Valid / Invalid

FN-DSA (derived from FALCON) is being developed as an additional lattice-based digital signature standard. HQC, a code-based key-encapsulation mechanism, has also been selected for standardization.

Where Cryptography Lives

Cryptography is rarely located in one neat part of an organization's infrastructure. PQC migration requires organizations to understand where cryptography exists before they can replace it.

TLS

HTTPS

VPNs

SSH

PKI

Digital Certificates

APIs

Databases

Cloud Services

Identity Systems

Software Signing

Hardware Modules

Email

Payment Systems

Blockchains

IoT Devices

Cryptographic Inventory

You cannot migrate what you cannot find.

A cryptographic inventory is a record of the cryptography used across an organization. It should connect cryptography to the systems, data, dependencies, and business functions that rely on it. Building this inventory is one of the first practical steps in PQC migration.

  • What cryptographic algorithms are we using, and where?
  • What keys and certificates exist?
  • Which applications and protocols depend on them?
  • How long must protected information remain secure?
  • Which systems are exposed to quantum risk?
  • Which vendors or third parties are involved?
Building a Cryptographic Inventory
Discover Assets→ Cryptographic Inventory→ Classify→ Prioritize

Cryptographic Agility

Cryptographic agility is the ability to change cryptographic algorithms, protocols, keys, or parameters without rebuilding an entire system. A cryptographically agile system separates applications from specific cryptographic implementations wherever practical.

PQC migration should aim to solve both today's quantum problem and tomorrow's cryptographic change problem.

Cryptographic Agility | Modular Algorithm Replacement RSA / ECC ML-KEM / ML-DSA Application Shell

PQC Migration

Moving to Post-Quantum Security

PQC migration is not a single software update. It is a process of discovering cryptographic dependencies, understanding risk, introducing new standards, testing systems, and moving production infrastructure without breaking compatibility or security.

01
Discover
02
Assess
03
Prioritize
04
Design
05
Test
06
Deploy
07
Monitor

Discover

Identify where cryptography exists: algorithms, keys, certificates, libraries, protocols, applications, devices, services, and third-party dependencies.

Assess

Understand which systems are vulnerable. Consider algorithm type, data sensitivity, required confidentiality period, system lifetime, external exposure, and regulatory requirements.

Prioritize

Focus on systems with long-lived sensitive data, long deployment cycles, critical infrastructure roles, and significant external exposure.

Design

Choose how PQC will be introduced: selecting algorithms, updating protocols, designing hybrid approaches, updating PKI, modifying APIs, and improving cryptographic agility.

Test

Test compatibility, latency, bandwidth, memory, storage, certificate sizes, hardware performance, interoperability, and security.

Deploy and Monitor

Introduce PQC into production. Track standards, algorithm updates, vulnerabilities, vendor support, new systems, and quantum computing developments.

Hybrid Cryptography

Hybrid cryptography combines classical and post-quantum cryptographic techniques. The resulting security does not depend entirely on one component alone. Hybrid approaches help organizations introduce PQC while maintaining compatibility and confidence during a transition period.

Hybrid Cryptography Model
Classical Crypto + Post-Quantum Crypto → Combined Security → Protected Connection
Security depends on both components. If either holds, the connection remains protected.

PQC Migration Challenges

PQC algorithms behave differently from many of the systems they replace. Migration creates engineering challenges as well as cryptographic ones.

Larger Keys

Some PQC algorithms use larger keys than current elliptic-curve systems, affecting storage, certificates, hardware, and protocols.

Larger Signatures

Post-quantum signatures or KEM ciphertexts can be significantly larger, affecting network traffic, blockchains, and embedded devices.

Performance

Different costs for key generation, signing, verification, encapsulation, and decapsulation. Test real workloads.

Network Constraints

Larger cryptographic objects may increase bandwidth requirements or change protocol behavior in constrained environments.

Legacy Systems

Older systems may not support new algorithms, larger keys, or updated certificate formats. Some may require substantial redesign.

Third-Party Dependencies

An organization may be ready while suppliers, vendors, or infrastructure providers are not. Coordination across ecosystems is required.

PQC Across Industries

Quantum migration affects every sector that depends on public-key cryptography.

Enterprise environments use cryptography throughout the technology stack: web servers, TLS, VPNs, identity platforms, PKI, cloud services, databases, APIs, internal applications, software signing, device management, and backups.

Employee Device→Identity→Application→API→Cloud→Database

Government systems often protect information that must remain confidential for many years, making HNDL particularly important. Migration plans may need to account for systems with very long deployment and replacement cycles.

Device→Secure Network→Identity→Application→Sensitive Data

Financial infrastructure depends heavily on cryptography for trust. PQC migration requires coordination across networks rather than simply replacing algorithms inside one organization.

Customer→Authentication→Transaction→Financial Network→Records

Blockchains rely heavily on public-key cryptography. Public keys and signatures may be visible permanently. Protocols may be difficult to change. Assets may remain associated with cryptographic keys for many years.

Wallet→Signed Transaction→Network→Validator→Smart Contract

The PQC Technology Stack

Changing cryptography at one layer can affect many systems above it. PQC migration may begin at a cryptographic library but create changes across every layer above.

L5Users and Services
L4Applications
L3Protocols
L2Cryptographic Libraries
L1Hardware

PQC changes enter at the cryptographic libraries layer and propagate upward through the stack.

Building a PQC Migration Program

A strong PQC program combines technical migration with organizational planning.

Ownership

Define which team or individual is responsible for cryptographic migration.

Inventory

Maintain a current view of cryptographic assets and dependencies.

Risk

Identify systems and data with the greatest quantum-related exposure.

Architecture

Build cryptographic agility into new systems.

Testing

Create environments where PQC can be tested safely.

Vendors

Understand supplier and platform migration plans.

Policies

Update internal cryptographic standards and security requirements.

Training

Ensure security, engineering, architecture, compliance, and leadership teams understand the transition.

Monitoring

Track changes in standards, implementation guidance, technology, and threats.

From Learning to Implementation

Understanding the concepts is the first step. Tectonic's five-day PQ Training program provides structured training across the foundations, algorithms, migration challenges, implementation, and practical application of post-quantum cryptography.

Day 1
Understand
Build foundations in cryptography, quantum computing, quantum risk, and PQC.
Day 2
Analyze
Study PQC algorithms, security assumptions, standards, and technical tradeoffs.
Day 3
Implement
Explore how PQC is implemented across real cryptographic systems.
Day 4
Validate
Apply knowledge through practical labs and complete the certification examination.
Day 5
Teach
Learn how to communicate PQC concepts and transfer knowledge across an organization.

Ready to Get PQ Certified?

Participants move from understanding the quantum threat to applying PQC concepts through advanced instruction and hands-on labs.

Become PQ Certified

Glossary

Algorithm
A defined set of instructions used to solve a problem or perform a calculation.
Asymmetric Cryptography
Cryptography that uses related public and private keys. Also known as public-key cryptography.
Authentication
The process of confirming the identity of a person, device, service, or system.
Certificate
A digital document that connects an identity or system to a public key.
Ciphertext
Data transformed by encryption so it cannot be understood without the required key.
Code-Based Cryptography
Cryptography based on difficult problems involving error-correcting codes.
CRQC
Cryptographically Relevant Quantum Computer. Powerful enough to threaten current cryptographic systems.
Cryptographic Agility
The ability to replace or update cryptographic components without redesigning an entire system.
ECC
Elliptic Curve Cryptography. Public-key techniques based on elliptic curve problems.
Encryption
Transforming readable information into ciphertext to protect confidentiality.
Entanglement
A quantum phenomenon where multiple systems share a combined state that cannot be described independently.
FN-DSA
FFT over NTRU-Lattice-Based Digital Signature Algorithm. Derived from FALCON, selected by NIST.
Grover's Algorithm
A quantum algorithm providing quadratic speedup for certain search problems.
Hash Function
Converts input data into a fixed-size output where small changes produce very different results.
HNDL
Harvest Now, Decrypt Later. Collecting encrypted data today to decrypt with future quantum computers.
HQC
A code-based key encapsulation mechanism selected by NIST for standardization.
Hybrid Cryptography
Combining classical and post-quantum cryptographic mechanisms within the same security process.
KEM
Key Encapsulation Mechanism. A public-key mechanism for establishing shared secret keying material.
Lattice-Based Cryptography
Cryptography based on hard problems involving high-dimensional lattices. ML-KEM and ML-DSA are examples.
ML-DSA
Module-Lattice-Based Digital Signature Algorithm. NIST FIPS 204.
ML-KEM
Module-Lattice-Based Key-Encapsulation Mechanism. NIST FIPS 203.
NIST
U.S. National Institute of Standards and Technology. Led the PQC standardization process.
PKI
Public Key Infrastructure. A system for managing public-key cryptography.
PQC
Post-Quantum Cryptography. Designed to resist attacks from both classical and quantum computers.
Q-Day
The point at which quantum computing can practically threaten important cryptographic systems.
Qubit
Quantum bit. The basic unit of quantum information.
RSA
A public-key system based on integer factorization. Threatened by Shor's algorithm.
Shor's Algorithm
A quantum algorithm that efficiently solves integer factorization and discrete logarithm problems.
SLH-DSA
Stateless Hash-Based Digital Signature Algorithm. NIST FIPS 205.
Superposition
A quantum property allowing a system to exist in a combination of basis states before measurement.
Symmetric Cryptography
Cryptography using shared secret keying material. AES is a common example.
TLS
Transport Layer Security. A protocol widely used to secure network communications.