Showing posts with label quantum threat. Show all posts
Showing posts with label quantum threat. Show all posts

Tuesday, June 30, 2026

Government Sets New Deadline for Quantum-Safe Encryption

A student in one of my summer courses asked the question I get every time encryption comes up in discussion: why does this matter now? RSA (Rivest-Shamir-Adleman) and ECC (elliptic curve cryptography) have protected data for decades. The quantum computer that breaks them does not exist yet. 

My usual answer leans on Q-Day estimates: Google's Gidney put the threshold at roughly one million physical qubits to break RSA-2048, and an IonQ fidelity result last October pushed the realistic window to somewhere between 2029 and 2033. Most expert estimates before that sat closer to 2035. On June 22, the federal government answered the student's question for me. President Trump signed 

an executive order setting hard deadlines for federal post-quantum cryptography migration (PQC): agencies must move high value assets to post-quantum key establishment by December 31, 2030, and post-quantum digital signatures by December 31, 2031. Federal contractors get the same 2030 deadline for FIPS (Federal Information Processing Standards) compliance.

That replaces the prior government baseline. Under the Biden administration's National Security Memorandum 10, agencies were planning around 2035. The new order compresses that by four to five years and adds teeth: agencies must name a PQC migration lead within 30 days, the Commerce Department must run a migration pilot by the end of 2027, and contractors face FIPS enforcement through procurement rules. 

Coverage from Cybersecurity Dive notes the order also pushes CISA (the Cybersecurity and Infrastructure Security Agency) to publish guidance on cryptographic bills of materials, the inventory work agencies need before they can migrate anything.

How the Industry Responded

Two days after the signing, STMicroelectronics introduced the ST54M, the first mobile chip with a dedicated hardware accelerator for post-quantum algorithms. It runs ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) and ML-DSA (Module-Lattice-Based Digital Signature Algorithm), the NIST (National Institute of Standards and Technology) standards finalized in 2024, on a single die alongside NFC (near-field communication), secure element, and eSIM (embedded SIM) functions. Commercial sampling is available now, with certification targeted for July 2026. That is the hardware path the federal order is pushing the rest of industry toward on the same compressed timeline.

I tell students today: nobody knows the exact day a cryptographically relevant quantum computer arrives, but the government just stopped waiting to find out. And.... I would not be surprised at all to see the deadline moved forward again.... soon.

Wednesday, April 1, 2026

The Quantum Security Race: Software vs. Hardware

I wrote about quantum computing's threat to encryption back in December. This post goes deeper on the two primary paths to Post-Quantum Cryptography (PQC): software and hardware.

Encryption protects everything: your bank transactions, your medical records, your company’s intellectual property, and the communications infrastructure that governments and militaries depend on. All of it rests on mathematical problems that classical computers cannot solve in any practical timeframe. Quantum computers change that equation. They do not simply run faster than classical machines; they operate on fundamentally different principles that make certain hard math problems trivial. The encryption standards that have secured the internet for decades, RSA and ECC, will not survive contact with a sufficiently powerful quantum computer. The question is not whether this happens, but when. Most experts put that date around 2035. The problem is that replacing encryption is not like patching software or upgrading a server. It requires identifying every system, device, protocol, and data store that relies on vulnerable cryptography, and migrating all of it to new standards. That process takes a decade or more even when organizations start immediately. Most have not started. The window to act in an orderly, cost-effective way is open now, but it will not stay open.

Quantum computing will break widely used encryption. Experts put the timeline at around 2035, when quantum machines will likely have the power to crack RSA and ECC. The threat does not wait until then. Harvest Now, Decrypt Later (HNDL) attacks are happening now: adversaries intercept and store encrypted data today, betting they can decrypt it once quantum hardware matures.

To understand the stakes, it helps to know what RSA and ECC actually are. RSA (Rivest-Shamir-Adleman, named for its three MIT inventors in 1977) is the encryption standard that secures most of the internet today, including HTTPS, email, and VPNs. Its security rests on a simple fact: factoring the product of two very large prime numbers is computationally impractical for classical computers. A quantum computer running Shor’s algorithm eliminates that protection entirely. ECC, Elliptic Curve Cryptography, is a more efficient alternative that provides equivalent security to RSA with much smaller key sizes. It is widely used in mobile devices, payment systems, and digital certificates precisely because it is lightweight. Its security depends on the difficulty of the elliptic curve discrete logarithm problem, which Shor’s algorithm also breaks. Both are public-key cryptography systems, meaning they underpin the key exchange that makes encrypted communication possible in the first place. When quantum computers can crack them, the foundation of modern digital security fails.

Organizations need to move to Post-Quantum Cryptography (PQC). Two paths exist: software and hardware.

Software-based PQC means implementing NIST-selected algorithms, like CRYSTALS-Kyber (now standardized as ML-KEM under FIPS 203), at the application or OS layer. These algorithms rely on math that is computationally infeasible for classical and quantum machines alike. Among the top 1,000 websites, PQC support averages just 21.9%, dropping to 8.4% for the top 100,000, and only 3% of banking websites currently support it. The practical management approach is “crypto agility”, a modular architecture that lets you swap algorithms as standards evolve without rebuilding from scratch.

Software has limits. It can be too power-hungry for constrained environments, which is where hardware-based PQC comes in. Embedding cryptographic algorithms directly into silicon is faster and more energy-efficient. It matters most for the roughly 20 billion IoT devices deployed worldwide, many of which cannot run complex PQC algorithms in software. SEALSQ launched the QS7001 in late 2025, the first chip to embed NIST-standardized PQC algorithms directly at the hardware level. Samsung developed the S3SSE2A, its own hardware PQC security chip targeting IoT devices and industrial sensors. (Click table below to enlarge)

The transition math is there but major cryptographic migrations typically take more than a decade. The Data Encryption Standard (DES), adopted by the US government in 1977, was the dominant symmetric encryption algorithm for two decades. By the late 1990s it was demonstrably breakable, and NIST ran a competition to replace it. The winner, the Advanced Encryption Standard (AES), was standardized in 2001. Despite DES being publicly compromised, the full industry migration from DES to AES took roughly 16 years. The same pattern held for cryptographic hash functions: retiring the MD family in favor of the more secure SHA family took about 10 years even with clear technical justification. PQC is a more complex transition than either of those, touching more layers of the stack, more device types, and more legacy infrastructure.

The White House estimates the federal government will spend $7.1 billion on PQC migration between 2025 and 2035. Software and hardware solutions are not competing; they address different constraints in the same stack.