The Post-Quantum Cryptography Standardization Project is an ongoing initiative led by the National Institute of Standards and Technology (NIST) to identify, evaluate, and standardize cryptographic algorithms that can withstand attacks from quantum computers. The project is a response to the looming threat of quantum computing, which has the potential to break many of today’s widely used cryptographic systems, including RSA, Elliptic Curve Cryptography (ECC), and Diffie-Hellman.
This guide provides an overview of the Post-Quantum Cryptography Standardization Project, its goals, the types of cryptographic algorithms under consideration, and its timeline for developing new standards to secure data in a quantum world.
Why Is Post-Quantum Cryptography Important?
Quantum computers leverage the principles of quantum mechanics to perform computations that are infeasible for classical computers. This creates a serious threat to cryptographic systems that rely on the difficulty of mathematical problems such as factoring large numbers (RSA) or solving discrete logarithms (ECC). Quantum algorithms, like Shor’s algorithm, can solve these problems exponentially faster than classical computers, rendering these cryptosystems insecure.
Post-quantum cryptography (PQC) aims to develop algorithms that remain secure against both classical and quantum attacks. These new cryptographic systems will be essential for protecting sensitive data, including online banking transactions, government communications, personal data, and intellectual property, from the threat posed by quantum computers.
Goals of the Post-Quantum Cryptography Standardization Project
The primary goal of NIST’s Post-Quantum Cryptography Standardization Project is to develop and standardize cryptographic algorithms that:
- Are resistant to attacks from quantum computers.
- Provide security and efficiency comparable to current cryptographic systems.
- Can be easily integrated into existing communication and security protocols without significant disruptions.
Phases of the NIST Post-Quantum Cryptography Standardization Project
The standardization project is divided into multiple phases, each focusing on reviewing and evaluating cryptographic algorithm submissions from researchers and cryptographers around the world.
1. Submission and Initial Evaluation (2016–2019)
- NIST called for submissions of post-quantum cryptographic algorithms in late 2016.
- A total of 69 candidate algorithms were submitted, spanning categories such as public-key encryption, digital signatures, and key encapsulation mechanisms (KEMs).
- The initial phase involved evaluating these algorithms for their security, efficiency, and potential to resist quantum attacks.
2. Second Round of Evaluation (2019–2020)
- NIST narrowed the field to 26 candidate algorithms after the initial evaluation. These candidates were further analyzed based on their performance, implementation feasibility, and security properties.
- The second round also included public comments and further cryptanalysis from the global cryptographic community.
3. Final Round of Evaluation (2020–2022)
- In July 2020, NIST announced 15 finalist algorithms and 7 alternate candidates that advanced to the third and final round of the evaluation process. These finalists represented the most promising candidates for future standardization.
- This phase involved deeper cryptanalysis and real-world testing to evaluate the practicality of these algorithms for widespread adoption.
4. Standardization and Finalization (2023 and Beyond)
- Following the final evaluation round, NIST is expected to announce the first set of standardized post-quantum cryptographic algorithms by 2024.
- Draft standards will be published for public review, with final standards expected to be released in subsequent years. These standards will guide the global transition to quantum-resistant cryptography.
Categories of Post-Quantum Cryptographic Algorithms
The NIST standardization process evaluates algorithms in three main categories: Public-Key Encryption, Key Encapsulation Mechanisms (KEMs), and Digital Signatures. The candidate algorithms are based on a variety of hard mathematical problems that are believed to be resistant to quantum attacks.
1. Lattice-Based Cryptography
- Lattice-based cryptographic algorithms are among the leading candidates in the post-quantum space. They rely on the hardness of problems like Learning with Errors (LWE) and Short Integer Solutions (SIS) in high-dimensional lattices, which are believed to be secure against quantum computers.
- Examples: Kyber (KEM), Dilithium (Digital Signatures), NTRUEncrypt.
- Applications: Secure communications, encryption, and digital signatures.
2. Code-Based Cryptography
- Code-based cryptographic algorithms are based on the difficulty of decoding random linear error-correcting codes, which remains hard for both classical and quantum computers.
- Examples: Classic McEliece (KEM), BIKE (KEM), HQC (KEM).
- Applications: Public-key encryption, secure key exchange.
- Multivariate polynomial cryptographic algorithms rely on solving systems of multivariate quadratic equations, a problem that is resistant to quantum attacks.
- Examples: Rainbow (Digital Signatures).
- Applications: Digital signatures and secure communications.
- Hash-based cryptographic algorithms use cryptographic hash functions to build secure digital signatures. These algorithms are known for their simplicity and security against quantum attacks.
- Examples: SPHINCS+ (Digital Signatures).
- Applications: Long-term digital signatures, particularly in scenarios requiring robust post-quantum security.
- Isogeny-based cryptographic algorithms rely on the difficulty of finding isogenies (mappings) between elliptic curves. These algorithms are particularly well-suited for key exchange.
- Examples: SIKE (KEM), CSIDH (Key Exchange).
- Applications: Secure key exchange, particularly in bandwidth-constrained environments.
Key Candidate Algorithms in the Final Round
Several algorithms have advanced to the final round of the NIST process, representing the most promising candidates for post-quantum cryptography standardization:
- Kyber (Lattice-Based KEM)A key encapsulation mechanism based on lattice problems. Known for its efficiency and small ciphertext sizes, Kyber is a leading candidate for secure key exchange.
- Dilithium (Lattice-Based Digital Signatures)A digital signature scheme that provides both security and efficiency, making it suitable for various applications like secure communications and blockchain.
- Classic McEliece (Code-Based KEM)One of the oldest and most well-studied code-based cryptosystems, offering strong security with relatively large key sizes. It is highly resistant to quantum attacks but requires more bandwidth due to its key size.
- SPHINCS+ (Hash-Based Digital Signatures)A stateless hash-based signature scheme offering robust security against quantum attacks. SPHINCS+ is particularly useful for applications where signature size is less of a concern.
Evaluation Criteria for Post-Quantum Algorithms
NIST evaluates post-quantum cryptographic algorithms based on several key factors:
- SecurityThe algorithm must withstand both classical and quantum attacks. Researchers evaluate its resistance to known and potential cryptanalytic techniques.
- EfficiencyThe algorithm must perform well in terms of speed, computational resource usage, and bandwidth requirements. Efficiency is especially important for real-time applications like secure communications.
- Key and Ciphertext SizesThe algorithm should have reasonable key and ciphertext sizes to ensure practical implementation across various platforms, including constrained environments like IoT devices.
- Implementation FeasibilityThe algorithm should be easy to implement and integrate into existing systems, such as TLS (Transport Layer Security), VPNs, and cloud services, without significant disruption to infrastructure.
Timeline for Post-Quantum Cryptography Standards
- 2024NIST is expected to release the first draft standards for post-quantum cryptography algorithms.
- 2025–2026Finalized standards for post-quantum cryptography will be published, providing a roadmap for transitioning to quantum-resistant systems.
- 2027 and BeyondWidespread adoption of post-quantum cryptography across industries, including financial services, government agencies, healthcare, and cloud services.
Preparing for Post-Quantum Cryptography
Organizations need to begin preparing for the transition to post-quantum cryptographic systems. Steps to take include:
- Assessing Current Cryptographic Systems:
- Review the cryptographic algorithms currently in use, such as RSA and ECC, and identify systems that are vulnerable to quantum attacks.
- Experimenting with Post-Quantum Algorithms:
- Begin testing candidate post-quantum algorithms, such as Kyber or Dilithium, in non-critical systems to assess their performance and compatibility.
- Adopting Hybrid Cryptography:
- Consider implementing hybrid cryptographic systems that combine classical encryption with post-quantum algorithms to ensure both immediate and long-term security.
- Monitoring NIST Developments:
- Stay informed about updates from NIST’s Post-Quantum Cryptography Standardization Project, especially as new standards are finalized and become available for adoption.
Conclusion
The Post-Quantum Cryptography Standardization Project is a critical initiative to ensure the future security of cryptographic systems in the face of advancing quantum computing technology. By developing and standardizing quantum-resistant algorithms, NIST is helping to protect data and communications for industries worldwide. Organizations must begin preparing now to ensure a smooth transition to post-quantum cryptography, safeguarding their systems against both classical and quantum threats.
For more information on how SolveForce can help implement post-quantum cryptographic solutions for your organization, contact us at 888-765-8301.
Key terms in plain language
Open a term for a concise explanation of language used on this page.
Bandwidth
The amount of data a connection can carry in a given time, usually measured in Mbps or Gbps. More bandwidth supports more users, devices, and simultaneous applications.
VPN
A virtual private network creates an encrypted connection across another network, commonly allowing remote users or offices to access private resources securely.
Cloud Computing
Computing resources—such as applications, servers, storage, or databases—delivered from remote infrastructure and scaled as requirements change.
Infrastructure as a Service (IaaS)
Cloud-based servers, storage, and networking that customers configure and manage without owning the underlying data-center hardware.
Software as a Service (SaaS)
Software accessed as an online service instead of being installed and maintained entirely on the customer’s own computers or servers.
Disaster Recovery (DRaaS)
A plan and service for restoring applications, data, and operations after an outage or disruption. DRaaS provides recovery infrastructure through a managed cloud service.