MENU

PQC Center of Excellence Releases Post-Quantum Cryptography FAQ, Detailing NIST Standards and U.S. Federal Migration Mandates

PQC Center of Excellence USA
Overview
The PQC Center of Excellence has released an FAQ outlining post-quantum cryptography (PQC) and new mathematical algorithms designed to protect current networks, applications, cloud systems, and devices from quantum threats. NIST finalized three key PQC federal information processing standards (ML-KEM, ML-DSA, SLH-DSA) in August 2024. U.S. federal agencies are mandated to inventory quantum-vulnerable cryptographic systems and plan for PQC migration, with NSA CNSA 2.0 providing quantum-resistant guidelines for national security systems, and leading tech providers actively pursuing PQC transitions.
In Depth

Key Findings

The PQC Center of Excellence has published a comprehensive FAQ dedicated to Post-Quantum Cryptography (PQC), explaining how these new mathematical algorithms are engineered to protect contemporary networks, applications, cloud systems, and devices from the impending threat of quantum computers. The FAQ highlights the critical step taken by the U.S. National Institute of Standards and Technology (NIST) in August 2024, when it finalized three key PQC Federal Information Processing Standards: ML-KEM, ML-DSA, and SLH-DSA. Within the U.S. public sector, federal agencies are now obligated to survey their quantum-vulnerable cryptographic systems and develop concrete plans for PQC migration. Furthermore, the National Security Agency’s (NSA) CNSA 2.0 provides quantum-resistant cryptographic guidelines for national security systems, and major technology providers are actively advancing their PQC transition efforts.

Technical and Policy Details

PQC algorithms are designed to resist attacks from both classical and quantum computers, unlike current public-key cryptography relying on problems like integer factorization (RSA) or elliptic curve discrete logarithm (ECC), which are vulnerable to quantum algorithms. The NIST-finalized algorithms include ML-KEM for key exchange, ML-DSA for digital signatures, and SLH-DSA for stateless hash-based signatures. The U.S. federal government’s push, underscored by Executive Order 14412 and OMB Memorandum M-26-15, mandates the completion of PQC migration for high-priority systems by December 31, 2030. This is a crucial step for governmental bodies to safeguard sensitive data long-term and encourages broader supply chain security enhancements.

Background and Context

The advent of ‘Q-Day,’ when quantum computers become capable of breaking current cryptographic schemes, poses a severe threat to the entire digital society. Specifically, the ‘Harvest Now, Decrypt Later (HNDL)’ threat signifies the risk that currently encrypted data, even if secured today, could be harvested and decrypted by future quantum computers. In this context, NIST has led an international effort to standardize quantum-resistant cryptographic algorithms. Government regulatory moves are powerful drivers for PQC migration among private enterprises, particularly in critical sectors like finance, healthcare, and infrastructure. Leading technology providers and cloud service operators are also proactively transitioning to PQC-compatible products and services to ensure customer data security.

Strategic Significance and Outlook

Resources like the PQC Center of Excellence are vital for organizations to comprehend the complexities of PQC migration and formulate effective strategies. Moving forward, PQC is expected to be adopted as a standard security foundation across diverse fields, including IoT devices, automotive systems, cloud services, and blockchain technologies. The migration process will involve numerous technical challenges, such as integration into existing IT infrastructures, performance implications, and ensuring compatibility. However, through industry-wide collaboration and knowledge sharing, these challenges are expected to be overcome. The widespread adoption of PQC is an indispensable element for ensuring the sustained trustworthiness and security of the digital economy.

Source: https://quantum-infinite.com/faqs/

Get our weekly technology intelligence — free

Receive an infographic that lets you judge at a glance whether each field’s analysis report is worth reading.

Subscribe Free — Weekly Tech Intelligence

By subscribing, you’ll receive Troy-Technical’s weekly technology intelligence newsletter.

  • Your email and selected fields are used only to deliver the newsletter.
  • We never share your information with third parties.
  • You can unsubscribe anytime via the link in each email.

See our Privacy Policy for details.

Takes about a minute · Unsubscribe anytime

Let's share this post !

Author of this article

Comments

To comment

TOC