Primer
Post-quantum cryptography
Encryption and digital-signature methods designed to resist attack by future large quantum computers.
- Today's public-key systems, RSA and elliptic curves, rely on maths problems that Shor's quantum algorithm would solve efficiently.
- Replacements use problems with no known quantum shortcut, mostly based on lattices; the US standards body NIST published the first ones in August 2024.
- The threat is already live for long-lived secrets: adversaries can store encrypted traffic now and decrypt it later.
- Keys and signatures grow from tens of bytes to one or several kilobytes, which strains blockchains, small devices and network protocols.